generated: '2026-08-11' method: searched source: >- Live probes of https://rugspull.com (2026-08-11) reconciled against openapi/_original/rugspull-read-api-openapi.json, the published /.well-known/ documents, and https://github.com/pqchase/rugspull/blob/main/docs/INTEGRATION.md summary: >- For a nine-endpoint hobby-scale read API, the standards posture is strong on DISCOVERY and weak on RUNTIME SEMANTICS. Rugspull conforms to OpenAPI 3.1, APIs.json 0.21, RFC 9116, RFC 9727 and RFC 8288 — a combination most large providers do not achieve — while missing RFC 9457 error semantics, RFC 9331 rate-limit signalling, and RFC 8594 deprecation signalling entirely. No third-party certification, audit, or compliance program of any kind is claimed; the provider states the opposite, that an independent audit is pending. standards: - id: openapi-3.1 conforms: true evidence: >- https://rugspull.com/openapi.json is a valid OpenAPI 3.1.0 document with nine paths, unique operationIds on every operation, tags declared and applied, summaries on all nine, reusable components.parameters/responses/schemas, and a declared servers[] host. Advertised via Link rel="service-desc" with media type application/vnd.oai.openapi+json;version=3.1. - id: apis-json-0.21 conforms: true evidence: >- https://rugspull.com/.well-known/apis.json is a valid APIs.json 0.21 index with aid, type Index, visibility, maintainers, and nine typed properties on the API entry. - id: rfc9727-api-catalog conforms: true evidence: >- https://rugspull.com/.well-known/api-catalog returns application/linkset+json with the RFC 9727 profile parameter and service-desc / service-doc / service-meta / status relations. - id: rfc9116-security-txt conforms: true evidence: >- https://rugspull.com/.well-known/security.txt returns text/plain with Contact, Expires (2027-07-19, unexpired), Canonical, Preferred-Languages, and Policy fields. No PGP key or Acknowledgments field. - id: rfc8288-web-linking conforms: true evidence: >- Every /api/* response carries a Link header with api-catalog, service-desc and service-doc relations, and access-control-expose-headers: link makes it readable cross-origin. Runtime discovery, not just static files. - id: llms-txt conforms: true evidence: >- https://rugspull.com/llms.txt returns text/plain in llms.txt format — H1, blockquote summary, and H2 link sections covering canonical facts, resources, and channels. - id: postman-collection-2.1 conforms: true evidence: >- https://rugspull.com/rugspull-read.postman_collection.json is a Collection v2.1.0 document with nine requests matching the nine OpenAPI operations. - id: rfc9110-safe-idempotent-methods conforms: true evidence: >- All nine published operations are GET; the API declares no unsafe method. Every call is safe and idempotent by HTTP semantics and may be retried freely. - id: cors conforms: true evidence: >- access-control-allow-origin *, allow-methods GET/POST/OPTIONS, max-age 86400, expose-headers link. Browser-callable without a proxy. - id: rfc9457-problem-details conforms: false evidence: >- Errors return application/json with a flat {"error": string} body. No application/problem+json media type, no type URI, no title/detail/instance. Confirmed live: {"error":"Rug not indexed"} on a 404. - id: rfc9331-ratelimit-headers conforms: false evidence: >- No RateLimit-* or X-RateLimit-* headers and no 429 anywhere in the contract; the provider states no numeric rate limit is offered. - id: rfc8594-sunset-deprecation conforms: false evidence: >- No Sunset or Deprecation header observed, no deprecation policy published, and no operation flagged deprecated in the spec. - id: oauth2 conforms: false evidence: >- No securitySchemes in the OpenAPI; /.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource both return the SPA HTML shell, not RFC 8414 or RFC 9728 metadata. The API is anonymous by design. - id: oidc conforms: false evidence: /.well-known/openid-configuration returns the SPA HTML shell, not OIDC metadata. - id: mcp conforms: false evidence: >- No hosted MCP server. /mcp and /.well-known/mcp.json both return the SPA HTML shell. See mcp/rugspull-read-api-mcp.yml for a derived candidate tool surface. - id: a2a conforms: false evidence: >- /.well-known/agent-card.json and the legacy /.well-known/agent.json both return the SPA HTML shell (200 text/html, 2458 bytes) rather than an AgentCard object. No a2a/ artifact was written. - id: asyncapi conforms: false not_applicable: true evidence: >- No webhook, SSE or streaming surface exists to describe. The nine domain events are BNB Smart Chain contract events read from the chain or by polling listRugEvents. Not a gap, an absence of the surface. - id: json-schema-2020-12 conforms: true evidence: >- Component schemas use OpenAPI 3.1 / JSON Schema 2020-12 constructs correctly — const, nullable union types (["string","null"]), pattern, maxItems, additionalProperties with a schema value. - id: openapi-examples conforms: false evidence: >- No example or examples keyword anywhere in the document. Real captured responses are held in examples/rugspull-read-api-examples.yml instead. - id: semver conforms: partial evidence: >- info.version 0.4.0 is semver-shaped and tracks the release tag, but the version is absent from the URL path, headers and media types, so it cannot be negotiated or pinned by a client. compliance_programs: certifications: [] audits: - name: Independent smart-contract security audit status: not completed claimed: false source: https://rugspull.com/llms.txt quote: >- An independent audit has not been completed. Exact-match source and project-authored tests are not an audit or safety certification. trust_center: false note: >- No SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR or FedRAMP claim is made anywhere, and no trust center exists. No Compliance pointer is emitted, because there is no compliance program to point at. The provider's discipline about NOT claiming what it has not earned is itself notable: verified source is explicitly distinguished from audited (https://rugspull.com/verified-source-code-does-not-mean-audited). regulatory_posture: note: >- Self-described high-risk parody DeFi protocol on BNB Smart Chain. No licensing, registration, KYC/AML program, or regulatory approval is claimed, and the provider states that none should be inferred from a directory listing. This profile catalogs a public data/discovery API and is not an endorsement of financial infrastructure. cross_links: well_known: well-known/rugspull-read-api-well-known.yml errors: errors/rugspull-read-api-problem-types.yml security: security/rugspull-read-api-vulnerability-disclosure.yml