generated: '2026-08-11'
method: probed
source: live probes of /.well-known/ and root discovery paths on https://rugspull.com
summary: >-
Rugspull publishes an unusually complete machine-readable discovery layer for a
single-host, nine-operation read API: an APIs.json 0.21 index, an RFC 9727 API
Catalog linkset, an RFC 9116 security.txt, and an API Onboarding descriptor —
all four returning real documents with correct media types. The site is a
single-page app served from Cloudflare, and its catch-all answers HTTP 200 with
the same 2,458-byte HTML shell for EVERY unrecognised /.well-known/* path. Those
200s are soft-404s, not documents, and are recorded below as misses.
soft_404_warning: >-
Any /.well-known/* path not in the hit list below returns 200 text/html with the
site shell (Content-Length 2458,
Rugspull | Disclosed Rugpull Parody on BNB
Smart Chain). Treat a 200 on this host as evidence only when the response
Content-Type is not text/html AND the body parses as the expected document type.
hosts:
- host: https://rugspull.com
documents:
- path: /.well-known/apis.json
status: 200
content_type: application/json
file: rugspull-read-api-apis.json
real_document: true
note: APIs.json 0.21 index, aid rugspull.com:read-api, nine typed properties.
- path: /.well-known/api-catalog
status: 200
content_type: application/linkset+json; profile="https://www.rfc-editor.org/info/rfc9727"
file: rugspull-read-api-api-catalog.json
real_document: true
note: >-
RFC 9727 linkset with service-desc (OpenAPI 3.1), service-doc (INTEGRATION.md),
service-meta (apis.json, api-onboarding, Postman) and status (/api/health) relations.
Also advertised as a Link header on every /api/* response.
- path: /.well-known/security.txt
status: 200
content_type: text/plain
file: rugspull-read-api-security.txt
real_document: true
note: >-
RFC 9116. Contact mailto:info@rugspull.com, Expires 2027-07-19, Canonical,
Preferred-Languages en/zh, Policy https://rugspull.com/community-safety.
Explicitly states no bounty and no response-time SLA.
- path: /.well-known/api-onboarding
status: 200
content_type: application/json; charset=utf-8
file: rugspull-read-api-api-onboarding.json
real_document: true
note: >-
API Onboarding Descriptor (aod 0.1). Declares maturity self-serve, account
required false, agentPolicy allowed, auth none, scopes model none.
- path: /.well-known/openid-configuration
status: 200
content_type: text/html
real_document: false
note: Soft-404 — SPA shell, not OIDC metadata. No OpenID Connect surface.
- path: /.well-known/oauth-authorization-server
status: 200
content_type: text/html
real_document: false
note: Soft-404 — SPA shell. No RFC 8414 authorization-server metadata.
- path: /.well-known/oauth-protected-resource
status: 200
content_type: text/html
real_document: false
note: Soft-404 — SPA shell. No RFC 9728 protected-resource metadata.
- path: /.well-known/ai-plugin.json
status: 200
content_type: text/html
real_document: false
note: >-
Soft-404 — SPA shell. A prior catalog round recorded this path as "detected
but unconfirmed"; this probe resolves it as an absence.
- path: /.well-known/agent-card.json
status: 200
content_type: text/html
real_document: false
note: Soft-404 — SPA shell. No A2A agent card. Nothing written to a2a/.
- path: /.well-known/agent.json
status: 200
content_type: text/html
real_document: false
note: Soft-404 — SPA shell. Legacy pre-0.3 A2A path also misses.
- path: /.well-known/mcp.json
status: 200
content_type: text/html
real_document: false
note: Soft-404 — SPA shell. No MCP discovery document.
root_discovery:
- path: /openapi.json
status: 200
content_type: application/json
real_document: true
file: openapi/_original/rugspull-read-api-openapi.json
note: OpenAPI 3.1.0, info.version 0.4.0, nine GET operations. Served from the API host root.
- path: /llms.txt
status: 200
content_type: text/plain
real_document: true
file: llms/rugspull-read-api-llms.txt
- path: /integration.json
status: 200
content_type: application/json
real_document: true
file: rugspull-read-api-integration.json
note: >-
Non-standard but substantive first-party integration package (schemaVersion 1):
canonical identity, contract addresses, the nine indexed on-chain events, market
reconstruction arithmetic, and explicit third-party display boundaries.
- path: /rugspull-read.postman_collection.json
status: 200
content_type: application/json
real_document: true
file: collections/rugspull-read-api.postman_collection.json
note: Postman Collection v2.1.0, nine requests.
- path: /sitemap.xml
status: 200
content_type: application/xml
real_document: true
note: 60 URLs. Used to confirm the absence of pricing/terms/privacy/status/blog pages.
- path: /robots.txt
status: 200
content_type: text/plain
real_document: true
note: 'Allow: / with Disallow /ops and /account/. No agent-specific directives, no AIPREF signals.'
- path: /asyncapi.yaml
status: 200
content_type: text/html
real_document: false
note: Soft-404 — SPA shell. No AsyncAPI document.
- path: /openapi.yaml
status: 200
content_type: text/html
real_document: false
note: Soft-404 — SPA shell. JSON is the only serving of the spec.
- path: /mcp
status: 200
content_type: text/html
real_document: false
note: Soft-404 — SPA shell. No hosted MCP endpoint.