{"uid":"cap_H4DphzQbziqZMIY9D4YjD","slug":"security-txt-8903bf8d","name":"security-txt","description":"security.txt reader (RFC 9116): fetches /.well-known/security.txt (and the legacy /security.txt), parses Contact, Policy, Expires, Encryption, Acknowledgments, Preferred-Languages and Canonical, and flags an expired file. Find the right way to report a vulnerability. $0.01 per domain.","url":"https://intel.rallylive.ca/site/security-txt","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","properties":{}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_3VEPMmYza86R2FzxSSk4D","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches and parses a domain's security.txt file (RFC 9116), extracting vulnerability disclosure contact, policy, expiry, encryption, and other fields, and flags expired files.","exampleAgentPrompt":"Can you look up the security.txt for github.com and tell me the right contact to report a vulnerability, whether their policy link is listed, and if the file is still valid or expired?","exampleUseCases":[{"title":"Finding vulnerability disclosure contact","prompt":"I found a security bug on stripe.com — can you check their security.txt and tell me who to contact to report it and whether there's a preferred method or PGP key I should use?"},{"title":"Auditing responsible disclosure compliance","prompt":"We need to verify that all our vendor domains have a valid, non-expired security.txt file with a contact and policy URL — can you start by checking vendor.example.com?"},{"title":"Security researcher pre-report check","prompt":"Before I submit this vulnerability report, can you fetch the security.txt for mozilla.org and confirm the correct disclosure email, preferred languages, and whether their file is still within its expiry date?"}],"resultDescription":"Returns parsed fields from the domain's security.txt file including Contact (email/URL), Policy URL, Expires timestamp, Encryption key URL, Acknowledgments URL, Preferred-Languages list, and Canonical URL. Also flags whether the file is expired. Returns data from /.well-known/security.txt with fallback to /security.txt.","failureModes":["Domain has no security.txt file at either standard path — returns not found","security.txt file is malformed or missing required fields — partial parse returned","Domain is unreachable or returns non-200 status — network error reported","security.txt file exists but is expired — file returned with expiry flag set to true","Domain input is invalid or malformed — input validation error"],"whenToPreferThis":"Use this endpoint when you need to find the correct channel for reporting security vulnerabilities to a specific domain, verify a site's compliance with RFC 9116, or automate responsible disclosure workflows. Prefer this over manual HTTP fetching when you need structured parsing of all security.txt fields including expiry validation across both standard paths.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T13:12:58.868Z","isFirstParty":false}