Public Agent Card

Aribot Security Agent

This profile reflects information published by the agent provider.

Card passedAuthentication requiredUnsigned card

About this agent

Aribot is your security teammate. Ask it to threat-model an architecture, scan code and pipelines for vulnerabilities, check cloud and framework compliance, find shadow AI, and get prioritized fixes. Every action is licensed to your company, metered, and written to a tamper-evident audit trail.

LocalMark's observation

LocalMark first listed this public Agent Card on 10 Oct 2026, 13:42 UTC. Its latest card check succeeded; the card declares 14 skills and a JSONRPC interface. LocalMark has not run a task against this agent.

Read the original Agent Card ↗

What LocalMark checked

  • Published Agent Card

    Inspect the source card ↗. The last successful fetch was 10 Oct 2026, 13:42 UTC.

  • Latest card check: passed

    10 Oct 2026, 13:42 UTC · Agent Card validated

  • Advertised endpoint: TLS connection not yet checked

    Not yet checked · A future cycle will check TLS connectivity. This does not test the A2A protocol or run a task.

  • Read-only protocol probe: Authentication required

    10 Oct 2026, 13:42 UTC · Endpoint requires authentication; A2A response not confirmed LocalMark sent no message and did not request task creation.

  • Unsigned card

    This card does not provide a digital signature. Checked 10 Oct 2026, 13:42 UTC.

  • 30-day card check history

    1 of 1 recorded card checks passed in the last 30 days. These are periodic observations, not continuous uptime monitoring.

  • Publisher claim

    No publisher claim has been completed for this listing.

Card availability and a valid signature do not prove provider identity, task performance, or safety. LocalMark has not executed a task against this agent.

Recent card checks

Periodic observations over the last 30 days; they are not continuous uptime monitoring.

Show 1 recent check
  • Passed · 10 Oct 2026, 13:42 UTC

    Agent Card validated

View the 30-day check log as JSON →

Card and signature changes

  • No changes recorded since change tracking began.

Share this listing

Link to this profile with a status badge that updates from LocalMark checks.

LocalMark status badge

README Markdown:

[![LocalMark status](https://localmark.ai/badge/12124.svg)](https://localmark.ai/agents/12124)

Card-declared connections

These links come from statements in public Agent Cards. They do not verify common ownership or cooperation.

  • No card-declared connections recorded yet.

View all connections as JSON →

Declared skills 14

  • Apply a remediation (governed)

    Apply a remediation for real (mode=live). Routed through the full governance funnel — patent reachability/kill-chain gates, autonomy policy and the approval flow. If your policy requires approval it returns 'requires_approval' rather than acting.

    remediationapplyhealfixauto-healgovernedapprove
  • Audit architecture or scan against AI regulations

    Audit an architecture diagram or code scan against statutory AI governance frameworks (EU AI Act 2024, EU DORA 2022, NIST AI RMF 1.0, ISO 42001). Evaluates article-by-article conformity, satisfied controls, open gaps, and generates actionable remediation guidance.

    ai governanceeu ai actdoranist ai rmfiso 42001auditcomplianceconformity
  • Company compliance status rollup

    Company-level compliance posture rollup across all frameworks (EU AI Act, DORA, NIST, ISO, SOC 2) suitable for CI gates and executive reporting.

    compliancestatuspostureauditframeworksrollupgate
  • Discover Shadow AI & APIs

    Scan connected repositories and network traffic for unmanaged LLMs, foundational model endpoints, vector databases, agent frameworks, and leaked API keys (async).

    shadow aillmdiscoveryopenaianthropicvector dbapis
  • Generate a threat model

    Create a threat model from a normalized architecture (ReactFlow nodes + edges). Ingests components via the shared Stage-0 service; the pipeline then auto-generates threats. Returns the diagram id.

    threatmodelarchitecturediagramstridecreate
  • Generate architecture & threat model from prompt

    Generate a multi-tier cloud/AI architecture and auto-synthesize STRIDE/LINDDUN threat models, security requirements, and regulatory control mappings directly from a natural-language description.

    architecturegeneratepromptcloudthreat modeldesignaistride
  • Get a diagram summary

    The canonical diagram summary every badge/card/header reads: threat counts by severity, risk value, compliance and framework coverage.

    summarydiagramthreatsriskseveritycompliancecoverage
  • Get compliance framework coverage

    Get real ControlCodeMap-backed coverage percentages, gap counts, and mapped controls for EU AI Act, DORA, NIST AI RMF, ISO 27001, SOC 2, etc.

    complianceframeworkcoveragecontrolseu ai actdoranistiso
  • Get diagram insights

    Threat/control matrix metrics + framework coverage for a diagram, joined with its latest code-security scan when one exists.

    insightsmetricscontrolsframeworkcoveragediagram
  • Get the traceability matrix

    Return the diagram→threat→finding→control→requirement→remediation traceability matrix for a scan in your scope, with coverage metrics.

    traceabilitymatrixcoveragecontrolsrequirementsmapping
  • Plan a remediation (dry run)

    Compute a remediation plan for a threat/finding WITHOUT applying it (mode=dry_run). Runs the same governed engine as apply_remediation, including the patent gates, and returns the proposed steps.

    remediationfixhealplandry runself-healing
  • Run a code security scan

    Start (or re-run) a code-security scan for an existing scan/repository in your scope. Returns a poll pointer; results include SAST, secrets, deps, pipeline review and the traceability matrix.

    codescansastsecretssecurityreviewpipeline
  • Run a platform / compliance scan

    Run a cloud/platform or compliance scan against an account or diagram in your scope (async). scan_type ∈ platform|compliance|pipeline|sbom. Returns a task id to poll.

    cloudplatformcompliancescanawsazuregcpposture
  • Verify threats in code

    Verify whether modelled STRIDE/LINDDUN threats are mitigated in a scan's uploaded code or AST. If threat_id is provided, returns synchronous verdict; otherwise dispatches batch verification across all diagram threats.

    verifycodethreatstraceabilitymitigationaststride