Public Agent Card

PG1 Sovereign Threat Intelligence

This profile reflects information published by the agent provider.

Card passedA2A respondingUnsigned card

About this agent

Threat intelligence agent for AI agents and security tooling: wallet sanctions screening, domain age lookups, hostname/phishing reputation checks, wallet age/history checks, free-tier usage status, bring-your-own-key AbuseIPDB IP lookups (your own AbuseIPDB key in the X-AbuseIPDB-Key header), and pre-install npm/PyPI package checks. Paid tools (bulk indicator feeds, CVE enrichment, threat actor dossiers) are available via the companion MCP server at /api/mcp, not via A2A yet.

LocalMark's observation

LocalMark first listed this public Agent Card on 10 Oct 2026, 14:11 UTC. Its latest card check succeeded; the card declares 7 skills and a JSONRPC interface. LocalMark has not run a task against this agent.

Read the original Agent Card ↗

What LocalMark checked

  • Published Agent Card

    Inspect the source card ↗. The last successful fetch was 10 Oct 2026, 14:11 UTC.

  • Latest card check: passed

    10 Oct 2026, 14:11 UTC · Agent Card validated

  • Advertised endpoint: TLS connection not yet checked

    Not yet checked · A future cycle will check TLS connectivity. This does not test the A2A protocol or run a task.

  • Read-only protocol probe: A2A task lookup response received

    10 Oct 2026, 14:11 UTC · A2A task-not-found response to a read-only task lookup LocalMark sent no message and did not request task creation.

  • Unsigned card

    This card does not provide a digital signature. Checked 10 Oct 2026, 14:11 UTC.

  • 30-day card check history

    1 of 1 recorded card checks passed in the last 30 days. These are periodic observations, not continuous uptime monitoring.

  • Publisher claim

    No publisher claim has been completed for this listing.

Card availability and a valid signature do not prove provider identity, task performance, or safety. LocalMark has not executed a task against this agent.

Recent card checks

Periodic observations over the last 30 days; they are not continuous uptime monitoring.

Show 1 recent check
  • Passed · 10 Oct 2026, 14:11 UTC

    Agent Card validated

View the 30-day check log as JSON →

Card and signature changes

  • No changes recorded since change tracking began.

Share this listing

Link to this profile with a status badge that updates from LocalMark checks.

LocalMark status badge

README Markdown:

[![LocalMark status](https://localmark.ai/badge/12374.svg)](https://localmark.ai/agents/12374)

Card-declared connections

These links come from statements in public Agent Cards. They do not verify common ownership or cooperation.

  • No card-declared connections recorded yet.

View all connections as JSON →

Declared skills 7

  • check_domain_age

    Looks up a domain's registration age via RDAP (the IANA-standardized WHOIS successor). Always free. A newly registered domain (age_days < 30) is reported as a common phishing signal, not proof of malicious intent.

    threat-intelligencedomainrdapphishing
  • check_hostname_reputation

    Checks a single hostname against the MetaMask eth-phishing-detect blocklist/allowlist plus a lookalike/typosquat detector, synced daily. Always free; rate-limited to 60 calls/hour per caller without a Gumroad license key (X-API-KEY exempts the limit).

    threat-intelligencephishinghostnamelookalike
  • check_ip_abuse

    Bring your own AbuseIPDB key: looks up one public IPv4 or IPv6 address in AbuseIPDB with YOUR OWN AbuseIPDB API key, sent in the X-AbuseIPDB-Key request header (never as a skill argument). Returns abuse_confidence_score, total_reports, distinct_reporters, last_reported_at, country_code, usage_type, isp, domain, is_tor and is_whitelisted, with attribution (Data from AbuseIPDB, https://www.abuseipdb.com/check/<ip>). No PG1 charge: it uses your own AbuseIPDB quota; 60 calls/hour per caller without a Gumroad license key. Without the header it returns abuseipdb_key_required and AbuseIPDB is not contacted. Status follows AbuseIPDB's own judgement: a whitelisted address is no_flags (informational IP_WHITELISTED); otherwise abuse_confidence_score above 0 is flagged (IP_ABUSE_REPORTED); reports scored 0 are no_flags (informational IP_REPORTS_SCORED_ZERO). A score of 0 is not proof the address is harmless.

    threat-intelligenceipabuse-reportsbring-your-own-key
  • check_package

    Check before you install: a pre-install check of one npm or PyPI package. Always free, no AI model; rate-limited to 60 calls/hour per caller without a Gumroad license key (X-API-KEY exempts the limit). Reports whether the package (and version) exists, first and latest publish dates, public malicious-package reports and known vulnerabilities (ids and severity) for the version checked, whether the name looks like a popular package's, and for npm the deprecated flag and install scripts. Flagged when the version is reported malicious (such reports can be false positives), the package or version does not exist, or the package is under 30 days old with a look-alike name; unknown when a lookup did not complete; never "safe" or "clean". Data sources and licences: https://pg1-ai-agent.vercel.app/docs/attributions

    supply-chainpackagesnpmpypityposquatting
  • check_wallet_age

    Reports when an EVM wallet address first appeared on a given chain, based on its earliest on-chain transfer history (in or out), plus whether it's a contract. Always free; rate-limited to 60 calls/hour per caller without a Gumroad license key (X-API-KEY exempts the limit). Reports age and history only — never a claim that an address is safe.

    threat-intelligencewalletcryptoage
  • check_wallet_sanctions

    Checks a cryptocurrency wallet address against the OFAC SDN (Specially Designated Nationals) sanctions list, synced daily from US Treasury data. Always free. Returns listed/matches/source/list_last_synced; informational only, never phrased as "safe" or "clean".

    threat-intelligencesanctionswalletcrypto
  • get_usage_status

    Returns your remaining free-tier calls for today and current Gumroad license status. Always free.

    accountusagequota