generated: '2026-09-19' method: searched source: >- Standards claimed in https://theloopbreaker.com/SKILL.md ("Standards Implemented"), the `standards[]` array of https://theloopbreaker.com/.well-known/x402.json, the agent card, and what the contract itself declares (operationIds, tags, live response shapes). Cross-cutting web-API standards are derived from openapi/theloopbreaker-com-openapi.yml and live probes. No SOC 2 / ISO 27001 / PCI / HIPAA or any other certification is published; the /security page states explicitly that no independent human security audit has been completed (see security/theloopbreaker-com-vulnerability-disclosure.yml). standards: # ---- domain standards the contract declares for its own market (agent identity / trust / payments) ---- - id: erc-8004 name: ERC-8004 Trustless Agents (identity, reputation, validation registries) conforms: true domain_standard: true evidence: >- Declared in the contract, not just in prose: operationId getERC8004Adapter (GET /agent/adapter), tag "Agent" description, and agent-card skills agent-identity / validation-registry / erc8004-adapter carry "ERC-8004"; x402.json standards[] lists ERC-8004; SKILL.md states Vaultfire deploys its own IdentityRegistry/ReputationRegistry/ValidationRegistry (Base 0xa7BD20bf..., 0x98afd144..., 0x8D349577...) plus an adapter to the canonical set. llms.txt registration step: POST /api/agent/register -> ERC-8004. location: openapi/theloopbreaker-com-openapi.yml#getERC8004Adapter - id: erc-8128 name: ERC-8128 signed HTTP requests from agent wallets conforms: true domain_standard: true evidence: >- Observed live 2026-09-19: POST /api/agent/route without headers returned 401 {"error":"unsigned","reason":"Request is missing ERC-8128 Signature and/or Signature-Input headers"}; SKILL.md lists ERC-8128 as "request authentication without API keys". The OpenAPI does NOT declare this (securitySchemes is empty) — the conformance is real but the contract under-documents it. - id: x402-v2 name: x402 HTTP 402 payments (v2, exact scheme, USDC) conforms: true domain_standard: true evidence: >- Machine-readable manifest at /.well-known/x402.json (x402Version 2, 77 endpoints, facilitator https://api.cdp.coinbase.com/platform/v2/x402). Observed live: GET /api/x402/bonds/agent-bond-status returned 402 with a PAYMENT-REQUIRED header (base64 JSON: accepts[].scheme exact, network eip155:8453, asset 0x8335...2913 USDC, payTo 0xfA15...813C, maxTimeoutSeconds 60) and CORS exposing PAYMENT-REQUIRED / PAYMENT-RESPONSE, allowing PAYMENT-SIGNATURE. location: well-known/theloopbreaker-com-x402.json - id: erc-5192 name: ERC-5192 minimal soulbound NFTs (Street Cred badges) conforms: true evidence: SKILL.md "Standards Implemented" (VaultfireStreetCred, locked() == true); agent-card description; x402.json standards[]. - id: erc-7702 name: EIP-7702 one-signature onboarding (VaultfireBatchOnboarder delegate) conforms: true evidence: SKILL.md "One-Signature Onboarding" with Base delegate 0x82c6a0dd34F5cF57F8B98Ee118e911B977618890 and a cited mainnet tx; /start page. - id: erc-4626 name: ERC-4626 tokenized vault (view-only VaultfireBIPVault adapter) conforms: true evidence: SKILL.md "Standards Implemented"; agent-card description ("ERC-4626 insurance vault adapter"). - id: erc-721 name: ERC-721 (IdentityRegistry token model) conforms: true evidence: SKILL.md "Standards Implemented" — agentId is the ERC-721 tokenId on Vaultfire's registry. - id: eip-712 name: EIP-712 typed structured signing (bonds, feedback, reputation) conforms: true evidence: SKILL.md "Standards Implemented". - id: xmtp-v3-mls name: XMTP V3 (MLS) encrypted messaging with on-chain group registry conforms: true evidence: SKILL.md "VaultfireForumRegistry — XMTP V3 Group Registry" (same-bytecode contract on 4 chains, selectors listed); llms.txt routing delivers over XMTP. # ---- agent-web discovery standards ---- - id: a2a-agent-card name: A2A Agent Card at /.well-known/agent-card.json conforms: true evidence: Served, graded conformant against the hard checks (protocolVersion 0.3.0, capabilities object, 18-skill array) in a2a/theloopbreaker-com-a2a.yml; no callable JSON-RPC endpoint behind card.url. - id: mcp name: Model Context Protocol server conforms: partial evidence: Official stdio server @vaultfire/mcp-server (npm, 9 tools); the advertised remote endpoint https://theloopbreaker.com/api/mcp returns 404 (mcp/theloopbreaker-com-mcp.yml). - id: llms-txt name: llms.txt conforms: true evidence: https://theloopbreaker.com/llms.txt (200, text/plain, 12,322 bytes) — saved in llms/. - id: openai-plugin-manifest name: /.well-known/ai-plugin.json (schema_version v1) conforms: true evidence: 200 application/json; api.type openapi -> /api/openapi.json (well-known/theloopbreaker-com-ai-plugin.json). - id: rfc9116-security-txt name: RFC 9116 security.txt conforms: true evidence: /.well-known/security.txt 200 with Contact, Expires (2027-08-27), Preferred-Languages, Canonical, Policy. - id: openapi-3.1 name: OpenAPI 3.1.0 contract conforms: true evidence: https://theloopbreaker.com/api/openapi.json — openapi 3.1.0, 34 operations, every operation has an operationId and tags; no components.schemas, no securitySchemes, only 2xx responses declared. # ---- cross-cutting web-API standards (derived) ---- - id: oauth2 conforms: false evidence: No oauth2 securityScheme; /.well-known/oauth-authorization-server and /oauth-protected-resource 404 on every host. Authentication is wallet-based (ERC-8128 signatures) and payment-based (x402). - id: oidc conforms: false evidence: /.well-known/openid-configuration 404. - id: rfc9457-problem-details conforms: false evidence: >- Live errors are a flat {"error": "..."} (400), {"error","reason"} (401) or {"error","code"} (503) with content-type application/json, never application/problem+json (errors/theloopbreaker-com-problem-types.yml). - id: rfc9421-http-message-signatures conforms: partial evidence: The 401 names the Signature and Signature-Input headers, which are RFC 9421's header pair as profiled by ERC-8128; the spec does not document them. - id: pagination conforms: unknown evidence: llms.txt calls GET /agent/discover "paginated" but the OpenAPI declares no page/cursor parameters and no response schema. - id: idempotency-key conforms: partial evidence: >- x402 endpoints' CORS allow-list names Idempotency-Key (access-control-allow-headers observed on the 402 response), so the header is accepted there; no document states its semantics, scope or retention, and the free /api/* operations neither accept nor document it. Recorded as partial evidence, not as a contract — see conventions/theloopbreaker-com-conventions.yml (coverage: none). - id: rate-limit-headers conforms: partial evidence: llms.txt documents X-RateLimit-Limit/Remaining/Reset and Retry-After (120/min); none was present on live 200 responses from /api/health, /api/hub/stats, /api/agent/status on 2026-09-19. certifications: [] compliance_program: none published