generated: '2026-08-13' method: derived source: well-known/goomp-inc-kalendar-ai-ai-plugin.json note: >- Derived from the only machine-readable artifact this provider publishes. There is no OpenAPI, no AsyncAPI, no GraphQL SDL and no compliance or trust-center page on any reachable host, so every assertion below except the two that the plugin manifest itself carries is a recorded absence rather than a negative finding about the product. standards: - id: openai-plugin-manifest-v1 conforms: true evidence: >- https://api.oncockpit.ai/.well-known/ai-plugin.json returns HTTP 200 application/json with schema_version "v1" and the full name_for_human / name_for_model / description_for_model / auth / api / logo_url / contact_email / legal_info_url shape. - id: oauth2 conforms: partial evidence: >- The plugin manifest declares auth.type "oauth" with scope "read write" and an authorization URL, but no OAuth server metadata is served: /.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource both return HTTP 500 on api.oncockpit.ai and HTTP 403 on oncockpit.ai. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns 500 on the API host and 403 on the web host. - id: rfc9116-security-txt conforms: false evidence: No /.well-known/security.txt is served on any host (500 on the API host, 403 on the web host). - id: rfc9457-problem-details conforms: false evidence: >- Error responses on api.oncockpit.ai are a plain-text Rails 500 body ("500 Internal Server Error ..."), not application/problem+json. - id: rfc8594-sunset conforms: false evidence: No Sunset or Deprecation header documentation is published. - id: a2a-agent-card conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json return 500 on api.oncockpit.ai and v1.oncockpit.ai and 403 on oncockpit.ai; no agent card exists. - id: mcp conforms: false evidence: No MCP endpoint was found; /mcp returns 500 on both API hosts. - id: llms-txt conforms: false evidence: >- /llms.txt returns the SPA catch-all shell (text/html) on oncockpit.ai and HTTP 500 on the API hosts — no llms.txt is published. compliance_certifications: []