generated: '2026-08-19' method: probed source: live probes of /.well-known/ on every Nekosia host checked: '2026-08-19' summary: >- One real well-known document is served, and it is served consistently on ALL THREE Nekosia hosts: an RFC 9116 security.txt. It is a genuine WellKnown hit and a genuine SecurityTxt hit, so both pointers are earned. Nothing else is served anywhere: no api-catalog, no ai-plugin.json, no OIDC discovery, no OAuth authorization-server metadata, and no A2A agent card on any host. pointer_basis: >- WellKnown + SecurityTxt pointers emitted on the strength of the 200 text/plain security.txt on nekosia.cat, api.nekosia.cat and cdn.nekosia.cat. No AgentCard pointer is emitted — every agent-card path 404s. false_positive_watch: >- nekosia.cat is fronted by Cloudflare and returns HTTP 403 (a "Sorry, you have been blocked" interstitial) to a default curl user-agent on most HTML paths. All statuses recorded here were taken with a browser user-agent, which the site answers normally. A future round that records 403s from a bare curl as "blocked by the provider" would be wrong — the origin serves these paths, the bot challenge is what refuses. hosts: - host: https://nekosia.cat documents: - path: /.well-known/security.txt status: 200 content_type: text/plain; charset=utf-8 file: nekosia-security.txt - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - host: https://api.nekosia.cat documents: - path: /.well-known/security.txt status: 200 content_type: text/plain; charset=utf-8 body: identical to the nekosia.cat document (same Canonical line) - path: /.well-known/openid-configuration status: 404 body: '{"success":false,"status":404,"message":"Not found","docs":"https://nekosia.cat/documentation"}' - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 note: >- The API host returns its own JSON 404 envelope for unknown well-known paths, so these are confirmed absences rather than an SPA catch-all or a gateway refusal. - host: https://cdn.nekosia.cat documents: - path: /.well-known/security.txt status: 200 content_type: text/plain; charset=utf-8 body: identical to the nekosia.cat document - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 security_txt: file: nekosia-security.txt rfc: '9116' url: https://nekosia.cat/.well-known/security.txt fields: canonical: https://nekosia.cat/.well-known/security.txt contact: mailto:support@nekosia.cat expires: '2030-12-10T12:00:00Z' policy: https://nekosia.cat/documentation?page=privacy-policy preferred_languages: [pl, en] conformance_note: >- Contact, Expires and Canonical are present, which satisfies RFC 9116's required fields. The Expires value is 2030-12-10, more than four years out — RFC 9116 recommends a value less than a year in the future, so the document is valid but long-lived. Policy points at the privacy policy rather than a dedicated vulnerability-disclosure page; there is no Encryption, Acknowledgments or Hiring field, and no PGP key. agent_card: found: false note: >- Probed /.well-known/agent-card.json and the legacy /.well-known/agent.json on all three hosts; all seven paths returned 404. No a2a/ artifact is written and no AgentCard pointer is emitted. robots: url: https://nekosia.cat/robots.txt status: 200 disallow: ['/auth/', '/logout', '/acp', '/*/edit'] sitemaps: - https://nekosia.cat/sitemap.xml - https://nekosia.cat/sitemap-images.xml note: >- Crawling of the documentation and API surface is explicitly permitted; only the auth, admin and edit paths are disallowed. llms_txt: url: https://nekosia.cat/llms.txt status: 404 note: The provider publishes no llms.txt. See llms/nekosia-llms.txt (generated by this pipeline).