Auditor Agent ANS-registered agent at auditor.webmesh.ai (A2A 1.0, 0.3-compatible, + MCP at one origin). ANS name: ans://v1.0.1.auditor.webmesh.ai Discoverable endpoints: GET /.well-known/agent-card.json (A2A 1.0 AgentCard, signed) GET /.well-known/agent.json (legacy A2A SDK alias) GET /.well-known/ans/trust-card.json (ANS Trust Card, hybrid) GET /.well-known/did.json (W3C DID document, did:web) GET /.well-known/http-message-signatures-directory (Web Bot Auth key directory, RFC 9421 signed) GET /.well-known/signature-agent-card (Web Bot Auth Signature Agent Card) GET /.well-known/mcp.json (MCP server discovery) GET /.well-known/ai-catalog.json (AI Catalog, Level 3) GET /agentfacts.json (Project NANDA AgentFacts) POST /mcp/ (MCP streamable-HTTP) POST / (A2A 1.0 JSON-RPC, 0.3-compatible) GET /health Independently verifies any transaction from public evidence and produces a signed verdict. Walks the identity chain (ANS -> cert -> SCITT), verifies mandate signature and DPoP binding, checks scope/amount/time window, confirms SCITT receipt is anchored. No privileged access -- reads only public evidence.