generated: '2026-08-05' method: probed source: https://ursamajor.com/ note: >- Probed the full /.well-known/ discovery surface on the only host Ursa Major Technologies operates, ursamajor.com. Nothing is published. Ursa Major is an aerospace and defense propulsion hardware manufacturer with no developer-facing API surface, so an empty well-known result is the expected, honest outcome. Note that ursamajor.com is a WordPress site behind a WAF that answers 404 with an HTML body for every unknown path; a control path (/llms-nonsense-9f8a.txt) was probed to confirm the site does not soft-200 unknown paths, so the single 200 below (/llms.txt) is a real document and not a catch-all. hosts: - host: https://ursamajor.com documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/oauth-protected-resource status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - path: /.well-known/mcp.json status: 404 - path: /.well-known/change-password status: 404 - path: /.well-known/dnt-policy.txt status: 404 contract_discovery: note: >- STEP 0b contract discovery run against every host Ursa Major operates. No OpenAPI, Swagger, GraphQL, MCP or A2A surface exists. No agent card was found, so no a2a/ artifact was written (search-only artifact — never generated). probes: - host: https://ursamajor.com paths: /openapi.json: 404 /swagger.json: 404 /api-docs: 404 /docs: 404 /developers: 404 /developer: 404 /api: 404 /graphql: 404 /wp-json/: 403 /wp-json/wp/v2/: 403 /llms.txt: 200 /robots.txt: 200 /sitemap.xml: 200 note: >- The site is WordPress (Yoast SEO). The WordPress REST API at /wp-json/ is reachable but returns 403 application/json — the built-in CMS API is blocked to anonymous callers. It is CMS boilerplate, not a product API, and is not recorded as an Ursa Major API surface. subdomains: note: >- Candidate API/developer subdomains were resolved directly. None has an A record, so there is no hidden API host. checked: api.ursamajor.com: NXDOMAIN developer.ursamajor.com: NXDOMAIN developers.ursamajor.com: NXDOMAIN docs.ursamajor.com: NXDOMAIN portal.ursamajor.com: NXDOMAIN status.ursamajor.com: NXDOMAIN trust.ursamajor.com: NXDOMAIN app.ursamajor.com: NXDOMAIN mcp.ursamajor.com: NXDOMAIN github_org: searched: true result: none note: >- GitHub user/org search for "ursamajor" returns github.com/ursamajor, an unrelated 2014 university schedule-planner project (http://ursamajor.herokuapp.com/). No first-party Ursa Major Technologies organization, SDK, spec or .proto repository exists. registries: note: >- npm search for "ursamajor" returned zero packages; pypi.org/pypi/ursamajor returned 404. No first-party client libraries are published. findings: - id: llms-txt-published detail: >- ursamajor.com/llms.txt returns 200 text/plain. It is auto-generated by Yoast SEO v25.7 and is a marketing-site index, not an API index. Saved verbatim to llms/ursa-major-technologies-published-llms.txt. - id: llms-txt-broken-links detail: >- The published llms.txt emits empty link targets — every Pages and Posts entry is "[Title]()" with no href — so it carries titles and no URLs. Its three Categories links and its sitemap link point at ursamajor20dev.wpenginepowered.com, the WP Engine staging hostname, rather than at ursamajor.com. This is a provider-side generation defect: an agent following the file reaches a staging host or nothing at all.