{"id":12374,"name":"PG1 Sovereign Threat Intelligence","description":"Threat intelligence agent for AI agents and security tooling: wallet sanctions screening, domain age lookups, hostname/phishing reputation checks, wallet age/history checks, free-tier usage status, bring-your-own-key AbuseIPDB IP lookups (your own AbuseIPDB key in the X-AbuseIPDB-Key header), and pre-install npm/PyPI package checks. Paid tools (bulk indicator feeds, CVE enrichment, threat actor dossiers) are available via the companion MCP server at /api/mcp, not via A2A yet.","card_url":"https://pg1-ai-agent.vercel.app/.well-known/agent-card.json","endpoint":"https://pg1-ai-agent.vercel.app/api/a2a","protocol_version":"1.0","first_seen":"2026-10-10T14:11:01.318669+00:00","last_verified":"2026-10-10T16:57:55.568288+00:00","card":{"url":"https://pg1-ai-agent.vercel.app/api/a2a","name":"PG1 Sovereign Threat Intelligence","skills":[{"id":"check_wallet_sanctions","name":"check_wallet_sanctions","tags":["threat-intelligence","sanctions","wallet","crypto"],"examples":["Is wallet 0x1234...abcd on the OFAC sanctions list?"],"inputModes":["application/json"],"description":"Checks a cryptocurrency wallet address against the OFAC SDN (Specially Designated Nationals) sanctions list, synced daily from US Treasury data. Always free. Returns listed/matches/source/list_last_synced; informational only, never phrased as \"safe\" or \"clean\".","outputModes":["application/json"]},{"id":"check_domain_age","name":"check_domain_age","tags":["threat-intelligence","domain","rdap","phishing"],"examples":["How old is the domain example.com?"],"inputModes":["application/json"],"description":"Looks up a domain's registration age via RDAP (the IANA-standardized WHOIS successor). Always free. A newly registered domain (age_days < 30) is reported as a common phishing signal, not proof of malicious intent.","outputModes":["application/json"]},{"id":"check_hostname_reputation","name":"check_hostname_reputation","tags":["threat-intelligence","phishing","hostname","lookalike"],"examples":["Is metamask-login.com a known phishing or lookalike domain?"],"inputModes":["application/json"],"description":"Checks a single hostname against the MetaMask eth-phishing-detect blocklist/allowlist plus a lookalike/typosquat detector, synced daily. Always free; rate-limited to 60 calls/hour per caller without a Gumroad license key (X-API-KEY exempts the limit).","outputModes":["application/json"]},{"id":"check_wallet_age","name":"check_wallet_age","tags":["threat-intelligence","wallet","crypto","age"],"examples":["When did wallet 0x1234...abcd first appear on Base?"],"inputModes":["application/json"],"description":"Reports when an EVM wallet address first appeared on a given chain, based on its earliest on-chain transfer history (in or out), plus whether it's a contract. Always free; rate-limited to 60 calls/hour per caller without a Gumroad license key (X-API-KEY exempts the limit). Reports age and history only — never a claim that an address is safe.","outputModes":["application/json"]},{"id":"check_ip_abuse","name":"check_ip_abuse","tags":["threat-intelligence","ip","abuse-reports","bring-your-own-key"],"examples":["How many abuse reports does 8.8.8.8 have in AbuseIPDB (with my own key)?"],"security":[{"abuseipdbKey":[]}],"inputModes":["application/json"],"description":"Bring your own AbuseIPDB key: looks up one public IPv4 or IPv6 address in AbuseIPDB with YOUR OWN AbuseIPDB API key, sent in the X-AbuseIPDB-Key request header (never as a skill argument). Returns abuse_confidence_score, total_reports, distinct_reporters, last_reported_at, country_code, usage_type, isp, domain, is_tor and is_whitelisted, with attribution (Data from AbuseIPDB, https://www.abuseipdb.com/check/<ip>). No PG1 charge: it uses your own AbuseIPDB quota; 60 calls/hour per caller without a Gumroad license key. Without the header it returns abuseipdb_key_required and AbuseIPDB is not contacted. Status follows AbuseIPDB's own judgement: a whitelisted address is no_flags (informational IP_WHITELISTED); otherwise abuse_confidence_score above 0 is flagged (IP_ABUSE_REPORTED); reports scored 0 are no_flags (informational IP_REPORTS_SCORED_ZERO). A score of 0 is not proof the address is harmless.","outputModes":["application/json"]},{"id":"check_package","name":"check_package","tags":["supply-chain","packages","npm","pypi","typosquatting"],"examples":["Does the npm package 'expresss' exist, and does its name imitate a popular package?","Check the PyPI package requests version 2.31.0 before I install it."],"inputModes":["application/json"],"description":"Check before you install: a pre-install check of one npm or PyPI package. Always free, no AI model; rate-limited to 60 calls/hour per caller without a Gumroad license key (X-API-KEY exempts the limit). Reports whether the package (and version) exists, first and latest publish dates, public malicious-package reports and known vulnerabilities (ids and severity) for the version checked, whether the name looks like a popular package's, and for npm the deprecated flag and install scripts. Flagged when the version is reported malicious (such reports can be false positives), the package or version does not exist, or the package is under 30 days old with a look-alike name; unknown when a lookup did not complete; never \"safe\" or \"clean\". Data sources and licences: https://pg1-ai-agent.vercel.app/docs/attributions","outputModes":["application/json"]},{"id":"get_usage_status","name":"get_usage_status","tags":["account","usage","quota"],"examples":["How many free-tier calls do I have left today?"],"inputModes":["application/json"],"description":"Returns your remaining free-tier calls for today and current Gumroad license status. Always free.","outputModes":["application/json"]}],"version":"1.17.0","description":"Threat intelligence agent for AI agents and security tooling: wallet sanctions screening, domain age lookups, hostname/phishing reputation checks, wallet age/history checks, free-tier usage status, bring-your-own-key AbuseIPDB IP lookups (your own AbuseIPDB key in the X-AbuseIPDB-Key header), and pre-install npm/PyPI package checks. Paid tools (bulk indicator feeds, CVE enrichment, threat actor dossiers) are available via the companion MCP server at /api/mcp, not via A2A yet.","capabilities":{"streaming":false,"extendedAgentCard":false,"pushNotifications":false},"protocolVersion":"0.3.0","securitySchemes":{"abuseipdbKey":{"in":"header","name":"X-AbuseIPDB-Key","type":"apiKey","description":"Your own AbuseIPDB API key (free or paid), used only by the check_ip_abuse skill and only for your own request. PG1 has no AbuseIPDB key of its own. Never send it as a skill argument."}},"documentationUrl":"https://pg1-ai-agent.vercel.app/docs/crypto-alert-bot","defaultInputModes":["application/json"],"defaultOutputModes":["application/json"],"preferredTransport":"JSONRPC","supportedInterfaces":[{"url":"https://pg1-ai-agent.vercel.app/api/a2a","protocolBinding":"JSONRPC","protocolVersion":"1.0"},{"url":"https://pg1-ai-agent.vercel.app/api/a2a","protocolBinding":"JSONRPC","protocolVersion":"0.3"}]},"signature_status":"unsigned","signature_detail":"No card signature supplied","signature_key_url":null,"signature_checked_at":"2026-10-10T16:57:55.568288+00:00","domain_claimed_at":null,"domain_proof_checked_at":null,"source_name":"GitHub repository README","source_url":"https://github.com/Project-Gifted1/pg1-ai-agent","last_check":{"checked_at":"2026-10-10T16:57:55.568288+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},"also_published_at":[],"history_urls":["https://pg1-ai-agent.vercel.app/.well-known/agent-card.json"],"skills":[{"skill_id":"check_domain_age","name":"check_domain_age","description":"Looks up a domain's registration age via RDAP (the IANA-standardized WHOIS successor). Always free. A newly registered domain (age_days < 30) is reported as a common phishing signal, not proof of malicious intent.","tags":["threat-intelligence","domain","rdap","phishing"],"quality_warning":false},{"skill_id":"check_hostname_reputation","name":"check_hostname_reputation","description":"Checks a single hostname against the MetaMask eth-phishing-detect blocklist/allowlist plus a lookalike/typosquat detector, synced daily. Always free; rate-limited to 60 calls/hour per caller without a Gumroad license key (X-API-KEY exempts the limit).","tags":["threat-intelligence","phishing","hostname","lookalike"],"quality_warning":false},{"skill_id":"check_ip_abuse","name":"check_ip_abuse","description":"Bring your own AbuseIPDB key: looks up one public IPv4 or IPv6 address in AbuseIPDB with YOUR OWN AbuseIPDB API key, sent in the X-AbuseIPDB-Key request header (never as a skill argument). Returns abuse_confidence_score, total_reports, distinct_reporters, last_reported_at, country_code, usage_type, isp, domain, is_tor and is_whitelisted, with attribution (Data from AbuseIPDB, https://www.abuseipdb.com/check/<ip>). No PG1 charge: it uses your own AbuseIPDB quota; 60 calls/hour per caller without a Gumroad license key. Without the header it returns abuseipdb_key_required and AbuseIPDB is not contacted. Status follows AbuseIPDB's own judgement: a whitelisted address is no_flags (informational IP_WHITELISTED); otherwise abuse_confidence_score above 0 is flagged (IP_ABUSE_REPORTED); reports scored 0 are no_flags (informational IP_REPORTS_SCORED_ZERO). A score of 0 is not proof the address is harmless.","tags":["threat-intelligence","ip","abuse-reports","bring-your-own-key"],"quality_warning":false},{"skill_id":"check_package","name":"check_package","description":"Check before you install: a pre-install check of one npm or PyPI package. Always free, no AI model; rate-limited to 60 calls/hour per caller without a Gumroad license key (X-API-KEY exempts the limit). Reports whether the package (and version) exists, first and latest publish dates, public malicious-package reports and known vulnerabilities (ids and severity) for the version checked, whether the name looks like a popular package's, and for npm the deprecated flag and install scripts. Flagged when the version is reported malicious (such reports can be false positives), the package or version does not exist, or the package is under 30 days old with a look-alike name; unknown when a lookup did not complete; never \"safe\" or \"clean\". Data sources and licences: https://pg1-ai-agent.vercel.app/docs/attributions","tags":["supply-chain","packages","npm","pypi","typosquatting"],"quality_warning":false},{"skill_id":"check_wallet_age","name":"check_wallet_age","description":"Reports when an EVM wallet address first appeared on a given chain, based on its earliest on-chain transfer history (in or out), plus whether it's a contract. Always free; rate-limited to 60 calls/hour per caller without a Gumroad license key (X-API-KEY exempts the limit). Reports age and history only — never a claim that an address is safe.","tags":["threat-intelligence","wallet","crypto","age"],"quality_warning":false},{"skill_id":"check_wallet_sanctions","name":"check_wallet_sanctions","description":"Checks a cryptocurrency wallet address against the OFAC SDN (Specially Designated Nationals) sanctions list, synced daily from US Treasury data. Always free. Returns listed/matches/source/list_last_synced; informational only, never phrased as \"safe\" or \"clean\".","tags":["threat-intelligence","sanctions","wallet","crypto"],"quality_warning":false},{"skill_id":"get_usage_status","name":"get_usage_status","description":"Returns your remaining free-tier calls for today and current Gumroad license status. Always free.","tags":["account","usage","quota"],"quality_warning":false}],"quality_flags":[],"check_history":{"checks":2,"passed":2},"recent_checks":[{"card_url":"https://pg1-ai-agent.vercel.app/.well-known/agent-card.json","checked_at":"2026-10-10T16:57:55.568288+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://pg1-ai-agent.vercel.app/.well-known/agent-card.json","checked_at":"2026-10-10T14:11:01.318669+00:00","success":true,"http_status":200,"detail":"Agent Card validated"}],"endpoint_tls_check":{"checked_at":"2026-10-10T16:57:55.568288+00:00","success":true,"detail":"Valid TLS connection to advertised endpoint host; no A2A request sent"},"protocol_check":{"checked_at":"2026-10-10T14:11:01.318669+00:00","state":"a2a_response","http_status":200,"detail":"A2A task-not-found response to a read-only task lookup"},"events":[],"relationships":[],"verification":{"agent_card_url":"https://pg1-ai-agent.vercel.app/.well-known/agent-card.json","last_successful_card_check":"2026-10-10T16:57:55.568288+00:00","latest_card_check":{"checked_at":"2026-10-10T16:57:55.568288+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},"signature_status":"unsigned","signature_checked_at":"2026-10-10T16:57:55.568288+00:00","task_endpoint_tested":true,"task_execution_tested":false,"endpoint_tls_checked_at":"2026-10-10T16:57:55.568288+00:00","endpoint_tls_reachable":true,"protocol_check_state":"a2a_response","protocol_checked_at":"2026-10-10T14:11:01.318669+00:00","provider_identity_verified":false,"domain_claimed_at":null,"domain_proof_checked_at":null}}