{"id":12124,"name":"Aribot Security Agent","description":"Aribot is your security teammate. Ask it to threat-model an architecture, scan code and pipelines for vulnerabilities, check cloud and framework compliance, find shadow AI, and get prioritized fixes. Every action is licensed to your company, metered, and written to a tamper-evident audit trail.","card_url":"https://api.aribot.ayurak.com/.well-known/agent-card.json","endpoint":"https://api.aribot.ayurak.com/aribot-api/v2/gateway/a2a","protocol_version":"1.0.0","first_seen":"2026-10-10T13:42:05.312917+00:00","last_verified":"2026-10-10T16:39:41.396471+00:00","card":{"url":"https://api.aribot.ayurak.com/aribot-api/v2/gateway/a2a","name":"Aribot Security Agent","skills":[{"id":"generate_threat_model","name":"Generate a threat model","tags":["threat","model","architecture","diagram","stride","create"],"examples":["Threat-model this architecture and tell me what could go wrong."],"inputModes":["application/json","text/plain"],"description":"Create a threat model from a normalized architecture (ReactFlow nodes + edges). Ingests components via the shared Stage-0 service; the pipeline then auto-generates threats. Returns the diagram id.","outputModes":["application/json","text/plain"]},{"id":"code_review_scan","name":"Run a code security scan","tags":["code","scan","sast","secrets","security","review","pipeline"],"examples":["Scan this repository for security vulnerabilities."],"inputModes":["application/json","text/plain"],"description":"Start (or re-run) a code-security scan for an existing scan/repository in your scope. Returns a poll pointer; results include SAST, secrets, deps, pipeline review and the traceability matrix.","outputModes":["application/json","text/plain"]},{"id":"compliance_scan","name":"Run a platform / compliance scan","tags":["cloud","platform","compliance","scan","aws","azure","gcp","posture"],"examples":["Check my cloud accounts against SOC 2 and flag the gaps."],"inputModes":["application/json","text/plain"],"description":"Run a cloud/platform or compliance scan against an account or diagram in your scope (async). scan_type ∈ platform|compliance|pipeline|sbom. Returns a task id to poll.","outputModes":["application/json","text/plain"]},{"id":"get_remediation","name":"Plan a remediation (dry run)","tags":["remediation","fix","heal","plan","dry run","self-healing"],"examples":["How do I fix this finding?"],"inputModes":["application/json","text/plain"],"description":"Compute a remediation plan for a threat/finding WITHOUT applying it (mode=dry_run). Runs the same governed engine as apply_remediation, including the patent gates, and returns the proposed steps.","outputModes":["application/json","text/plain"]},{"id":"apply_remediation","name":"Apply a remediation (governed)","tags":["remediation","apply","heal","fix","auto-heal","governed","approve"],"examples":["Fix the high-severity finding and show me what changed."],"inputModes":["application/json","text/plain"],"description":"Apply a remediation for real (mode=live). Routed through the full governance funnel — patent reachability/kill-chain gates, autonomy policy and the approval flow. If your policy requires approval it returns 'requires_approval' rather than acting.","outputModes":["application/json","text/plain"]},{"id":"get_traceability","name":"Get the traceability matrix","tags":["traceability","matrix","coverage","controls","requirements","mapping"],"examples":["Trace this threat back to the control and the code."],"inputModes":["application/json","text/plain"],"description":"Return the diagram→threat→finding→control→requirement→remediation traceability matrix for a scan in your scope, with coverage metrics.","outputModes":["application/json","text/plain"]},{"id":"get_diagram_summary","name":"Get a diagram summary","tags":["summary","diagram","threats","risk","severity","compliance","coverage"],"examples":["Summarize the security posture of this diagram."],"inputModes":["application/json","text/plain"],"description":"The canonical diagram summary every badge/card/header reads: threat counts by severity, risk value, compliance and framework coverage.","outputModes":["application/json","text/plain"]},{"id":"get_insights","name":"Get diagram insights","tags":["insights","metrics","controls","framework","coverage","diagram"],"examples":["What are my top security risks right now?"],"inputModes":["application/json","text/plain"],"description":"Threat/control matrix metrics + framework coverage for a diagram, joined with its latest code-security scan when one exists.","outputModes":["application/json","text/plain"]},{"id":"verify_threats_in_code","name":"Verify threats in code","tags":["verify","code","threats","traceability","mitigation","ast","stride"],"examples":["Verify this threat actually exists in my code."],"inputModes":["application/json","text/plain"],"description":"Verify whether modelled STRIDE/LINDDUN threats are mitigated in a scan's uploaded code or AST. If threat_id is provided, returns synchronous verdict; otherwise dispatches batch verification across all diagram threats.","outputModes":["application/json","text/plain"]},{"id":"discover_shadow_ai","name":"Discover Shadow AI & APIs","tags":["shadow ai","llm","discovery","openai","anthropic","vector db","apis"],"examples":["Find the unsanctioned AI tools and models used across my code."],"inputModes":["application/json","text/plain"],"description":"Scan connected repositories and network traffic for unmanaged LLMs, foundational model endpoints, vector databases, agent frameworks, and leaked API keys (async).","outputModes":["application/json","text/plain"]},{"id":"get_framework_coverage","name":"Get compliance framework coverage","tags":["compliance","framework","coverage","controls","eu ai act","dora","nist","iso"],"examples":["How well am I covered against OWASP and NIST?"],"inputModes":["application/json","text/plain"],"description":"Get real ControlCodeMap-backed coverage percentages, gap counts, and mapped controls for EU AI Act, DORA, NIST AI RMF, ISO 27001, SOC 2, etc.","outputModes":["application/json","text/plain"]},{"id":"compliance_status","name":"Company compliance status rollup","tags":["compliance","status","posture","audit","frameworks","rollup","gate"],"examples":[],"inputModes":["application/json","text/plain"],"description":"Company-level compliance posture rollup across all frameworks (EU AI Act, DORA, NIST, ISO, SOC 2) suitable for CI gates and executive reporting.","outputModes":["application/json","text/plain"]},{"id":"generate_architecture","name":"Generate architecture & threat model from prompt","tags":["architecture","generate","prompt","cloud","threat model","design","ai","stride"],"examples":[],"inputModes":["application/json","text/plain"],"description":"Generate a multi-tier cloud/AI architecture and auto-synthesize STRIDE/LINDDUN threat models, security requirements, and regulatory control mappings directly from a natural-language description.","outputModes":["application/json","text/plain"]},{"id":"run_ai_governance_audit","name":"Audit architecture or scan against AI regulations","tags":["ai governance","eu ai act","dora","nist ai rmf","iso 42001","audit","compliance","conformity"],"examples":[],"inputModes":["application/json","text/plain"],"description":"Audit an architecture diagram or code scan against statutory AI governance frameworks (EU AI Act 2024, EU DORA 2022, NIST AI RMF 1.0, ISO 42001). Evaluates article-by-article conformity, satisfied controls, open gaps, and generates actionable remediation guidance.","outputModes":["application/json","text/plain"]}],"version":"1.0.0","provider":{"url":"https://ayurak.com","organization":"Aristiun (Ayurak)"},"security":[{"oauth2":["read:insights"]}],"description":"Aribot is your security teammate. Ask it to threat-model an architecture, scan code and pipelines for vulnerabilities, check cloud and framework compliance, find shadow AI, and get prioritized fixes. Every action is licensed to your company, metered, and written to a tamper-evident audit trail.","capabilities":{"streaming":false,"pushNotifications":false,"stateTransitionHistory":true},"protocolVersion":"1.0.0","securitySchemes":{"oauth2":{"type":"oauth2","flows":{"authorizationCode":{"scopes":{"run:scan":"Run platform/cloud scans","read:findings":"Read code-review findings and traceability","read:insights":"Read insights, reports and compliance coverage","offline_access":"Issue refresh tokens for long-lived assistant connections","run:codereview":"Start code-security scans","read:threatmodel":"Read threat models","write:threatmodel":"Create/upload/generate threat models"},"tokenUrl":"https://api.aribot.ayurak.com/o/token/","authorizationUrl":"https://api.aribot.ayurak.com/o/authorize/"}},"description":"Sign in with your Aribot account. An Owner or Security Manager authorizes the agent, then Aribot governs every call."}},"documentationUrl":"https://developer.ayurak.com","defaultInputModes":["application/json","text/plain"],"defaultOutputModes":["application/json","text/plain"],"preferredTransport":"JSONRPC"},"signature_status":"unsigned","signature_detail":"No card signature supplied","signature_key_url":null,"signature_checked_at":"2026-10-10T16:39:41.396471+00:00","domain_claimed_at":null,"domain_proof_checked_at":null,"source_name":"Agent Tools Catalog","source_url":"https://agent-tools.cloud","last_check":{"checked_at":"2026-10-10T16:39:41.396471+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},"also_published_at":[],"history_urls":["https://api.aribot.ayurak.com/.well-known/agent-card.json"],"skills":[{"skill_id":"apply_remediation","name":"Apply a remediation (governed)","description":"Apply a remediation for real (mode=live). Routed through the full governance funnel — patent reachability/kill-chain gates, autonomy policy and the approval flow. If your policy requires approval it returns 'requires_approval' rather than acting.","tags":["remediation","apply","heal","fix","auto-heal","governed","approve"],"quality_warning":false},{"skill_id":"run_ai_governance_audit","name":"Audit architecture or scan against AI regulations","description":"Audit an architecture diagram or code scan against statutory AI governance frameworks (EU AI Act 2024, EU DORA 2022, NIST AI RMF 1.0, ISO 42001). Evaluates article-by-article conformity, satisfied controls, open gaps, and generates actionable remediation guidance.","tags":["ai governance","eu ai act","dora","nist ai rmf","iso 42001","audit","compliance","conformity"],"quality_warning":false},{"skill_id":"compliance_status","name":"Company compliance status rollup","description":"Company-level compliance posture rollup across all frameworks (EU AI Act, DORA, NIST, ISO, SOC 2) suitable for CI gates and executive reporting.","tags":["compliance","status","posture","audit","frameworks","rollup","gate"],"quality_warning":false},{"skill_id":"discover_shadow_ai","name":"Discover Shadow AI & APIs","description":"Scan connected repositories and network traffic for unmanaged LLMs, foundational model endpoints, vector databases, agent frameworks, and leaked API keys (async).","tags":["shadow ai","llm","discovery","openai","anthropic","vector db","apis"],"quality_warning":false},{"skill_id":"generate_threat_model","name":"Generate a threat model","description":"Create a threat model from a normalized architecture (ReactFlow nodes + edges). Ingests components via the shared Stage-0 service; the pipeline then auto-generates threats. Returns the diagram id.","tags":["threat","model","architecture","diagram","stride","create"],"quality_warning":false},{"skill_id":"generate_architecture","name":"Generate architecture & threat model from prompt","description":"Generate a multi-tier cloud/AI architecture and auto-synthesize STRIDE/LINDDUN threat models, security requirements, and regulatory control mappings directly from a natural-language description.","tags":["architecture","generate","prompt","cloud","threat model","design","ai","stride"],"quality_warning":false},{"skill_id":"get_diagram_summary","name":"Get a diagram summary","description":"The canonical diagram summary every badge/card/header reads: threat counts by severity, risk value, compliance and framework coverage.","tags":["summary","diagram","threats","risk","severity","compliance","coverage"],"quality_warning":false},{"skill_id":"get_framework_coverage","name":"Get compliance framework coverage","description":"Get real ControlCodeMap-backed coverage percentages, gap counts, and mapped controls for EU AI Act, DORA, NIST AI RMF, ISO 27001, SOC 2, etc.","tags":["compliance","framework","coverage","controls","eu ai act","dora","nist","iso"],"quality_warning":false},{"skill_id":"get_insights","name":"Get diagram insights","description":"Threat/control matrix metrics + framework coverage for a diagram, joined with its latest code-security scan when one exists.","tags":["insights","metrics","controls","framework","coverage","diagram"],"quality_warning":false},{"skill_id":"get_traceability","name":"Get the traceability matrix","description":"Return the diagram→threat→finding→control→requirement→remediation traceability matrix for a scan in your scope, with coverage metrics.","tags":["traceability","matrix","coverage","controls","requirements","mapping"],"quality_warning":false},{"skill_id":"get_remediation","name":"Plan a remediation (dry run)","description":"Compute a remediation plan for a threat/finding WITHOUT applying it (mode=dry_run). Runs the same governed engine as apply_remediation, including the patent gates, and returns the proposed steps.","tags":["remediation","fix","heal","plan","dry run","self-healing"],"quality_warning":false},{"skill_id":"code_review_scan","name":"Run a code security scan","description":"Start (or re-run) a code-security scan for an existing scan/repository in your scope. Returns a poll pointer; results include SAST, secrets, deps, pipeline review and the traceability matrix.","tags":["code","scan","sast","secrets","security","review","pipeline"],"quality_warning":false},{"skill_id":"compliance_scan","name":"Run a platform / compliance scan","description":"Run a cloud/platform or compliance scan against an account or diagram in your scope (async). scan_type ∈ platform|compliance|pipeline|sbom. Returns a task id to poll.","tags":["cloud","platform","compliance","scan","aws","azure","gcp","posture"],"quality_warning":false},{"skill_id":"verify_threats_in_code","name":"Verify threats in code","description":"Verify whether modelled STRIDE/LINDDUN threats are mitigated in a scan's uploaded code or AST. If threat_id is provided, returns synchronous verdict; otherwise dispatches batch verification across all diagram threats.","tags":["verify","code","threats","traceability","mitigation","ast","stride"],"quality_warning":false}],"quality_flags":[],"check_history":{"checks":2,"passed":2},"recent_checks":[{"card_url":"https://api.aribot.ayurak.com/.well-known/agent-card.json","checked_at":"2026-10-10T16:39:41.396471+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://api.aribot.ayurak.com/.well-known/agent-card.json","checked_at":"2026-10-10T13:42:05.312917+00:00","success":true,"http_status":200,"detail":"Agent Card validated"}],"endpoint_tls_check":{"checked_at":"2026-10-10T16:39:41.396471+00:00","success":true,"detail":"Valid TLS connection to advertised endpoint host; no A2A request sent"},"protocol_check":{"checked_at":"2026-10-10T13:42:05.312917+00:00","state":"auth_required","http_status":401,"detail":"Endpoint requires authentication; A2A response not confirmed"},"events":[],"relationships":[],"verification":{"agent_card_url":"https://api.aribot.ayurak.com/.well-known/agent-card.json","last_successful_card_check":"2026-10-10T16:39:41.396471+00:00","latest_card_check":{"checked_at":"2026-10-10T16:39:41.396471+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},"signature_status":"unsigned","signature_checked_at":"2026-10-10T16:39:41.396471+00:00","task_endpoint_tested":true,"task_execution_tested":false,"endpoint_tls_checked_at":"2026-10-10T16:39:41.396471+00:00","endpoint_tls_reachable":true,"protocol_check_state":"auth_required","protocol_checked_at":"2026-10-10T13:42:05.312917+00:00","provider_identity_verified":false,"domain_claimed_at":null,"domain_proof_checked_at":null}}