# cicap.es — A+ (92/100) agent-ready

**Agent-readiness (composite):** 92/100 · A+  
**Trust score:** 87/100  
**Access score:** 100/100  
**Scanned:** 2026-08-05T11:11:38.084Z  
**Rubric:** v0.6.2

> The headline is a weighted blend of Trust (50%), Access (30%). The axes are scored separately as components and never cross-contaminate (MCP never feeds Trust).

## Trust categories

| Category | Score |
| --- | ----- |
| Verifiable identity | 67/100 |
| Alignment & values | 100/100 |
| Attestation & provenance | 75/100 |
| Accountability | 100/100 |
| Delegation & auth | 100/100 (1 of 3 applicable) |

## Trust checks

### Verifiable identity

- **Publishes an A2A agent card** — `pass` · `convention`: agent card present with a name and declared capabilities
- **Agent card is cryptographically verifiable (signed / DID / VC)** — `pass` · `standard`: agent card carries a cryptographic signature / proof / DID binding
- **Publishes an MCP server card (if it runs MCP)** — `fail` · `convention`: no MCP server card published

### Alignment & values

- **Publishes an alignment / values card** — `pass` · `convention`: alignment card declares values plus scope/refusals
- **Declared capabilities are present and coherent** — `pass` · `convention`: agent card enumerates concrete capabilities/skills

### Attestation & provenance

- **Publishes signed attestations / verifiable credentials** — `pass` · `standard`: publishes signed attestations / verifiable credentials
- **Build / behaviour provenance (Sigstore / SLSA)** — `partial` · `standard`: provenance statement present but not signed/enveloped

### Accountability

- **Serves security.txt** — `pass` · `standard`: security.txt served with Contact and Expires
- **Publishes a dated, signed re-verification status** — `pass` · `convention`: publishes a dated, machine-readable verification status
- **Publishes advisories / a STIX IoC feed** — `pass` · `standard`: STIX bundle published (0 objects)

### Delegation & auth

- **OAuth protected-resource metadata** — `na` · `standard`: not applicable — service declares no delegated/OAuth authorization
- **OAuth authorization-server metadata** — `na` · `standard`: not applicable — service declares no delegated/OAuth authorization
- **Documents agent authentication** — `pass` · `convention`: publishes a substantive agent authentication guide

## Access categories

| Category | Score |
| --- | ----- |
| Crawl discoverability | 100/100 |
| Agent content access | 100/100 |
| AI access policy | 100/100 |
| Capability discovery | 100/100 |
| Authorization discovery | N/A |
| Protocol hygiene | N/A |
| Discoverability | N/A |
| Breadth of publishing | N/A |

## Access checks

### Crawl discoverability

- **Serves a parseable robots.txt** — `pass` · `standard`: serves a parseable robots.txt
- **Publishes a sitemap** — `pass` · `standard`: serves a sitemap (valid XML / sitemap index)
- **Emits HTTP Link relations** — `pass` · `standard`: emits 3 HTTP Link relation(s)

### Agent content access

- **Serves markdown via content negotiation** — `fail` · `convention`: Accept: text/markdown returns HTML, not markdown
- **Publishes an llms.txt index** — `pass` · `convention`: publishes /llms.txt with an H1 title
- **Embeds structured data (JSON-LD / OpenGraph)** — `pass` · `standard`: embeds schema.org JSON-LD (LocalBusiness, Organization, WebSite)

### AI access policy

- **Declares explicit AI-bot rules** — `pass` · `standard`: declares explicit rules for 11 known AI crawler(s): amazonbot, bytespider, ccbot, chatgpt-user, claude-web, claudebot, diffbot, facebookbot, google-extended, gptbot, perplexitybot
- **Publishes Content Signals** — `pass` · `convention`: publishes Content Signals (ai-train / ai-input / search)

### Capability discovery

- **Publishes an API catalog** — `pass` · `standard`: publishes an RFC 9727 API catalog (linkset+json) with ≥1 link
- **Publishes an OpenAPI document** — `pass` · `standard`: publishes a discoverable OpenAPI document (v3.1.0) at https://cicap.es/openapi.json
- **Publishes an MCP server card** — `fail` · `convention`: no MCP server card published
- **Foregrounds the primary agent channel (agents.txt → MCP)** — `partial` · `convention`: /agents.txt is served but neither it nor /llms.txt references the MCP endpoint — an arriving agent isn't pointed at the primary channel
- **DNS-AID agent discovery (DNSSEC-validated)** — `fail` · `convention`: no DNS-AID ServiceMode SVCB/HTTPS record (_index._agents, _a2a._agents, or _mcp._agents)

### Authorization discovery

- **OAuth protected-resource metadata** — `na` · `standard`: not applicable — service declares no delegated/OAuth authorization
- **OAuth authorization-server metadata** — `na` · `standard`: not applicable — service declares no delegated/OAuth authorization

### Protocol hygiene


### Discoverability


### Breadth of publishing


**Is this your domain?** [Claim it on mnemom.ai →](https://www.mnemom.ai/domains?domain=cicap.es)

---

Signed with Ed25519 (key `94502b2b7235c986`). Verify against https://api.isittrustready.ai/jwk.

[View on isittrustready.ai](https://api.isittrustready.ai/r/cicap.es)
