{
  "name": "Auth Posture",
  "description": "One API call answers two questions about a domain: can it receive email (MX), and can anyone send mail pretending to be it (SPF/DMARC/DKIM posture). Also flags disposable-email domains. This service is a plain REST API and an MCP server over Streamable HTTP - it is NOT an A2A JSON-RPC agent. Docs at the documentationUrl.",
  "supportedInterfaces": [
    {
      "url": "https://auth-posture.rowb.app/mcp",
      "protocolBinding": "MCP",
      "protocolVersion": "1.0"
    },
    {
      "url": "https://auth-posture.rowb.app",
      "protocolBinding": "REST",
      "protocolVersion": "1.0"
    }
  ],
  "provider": {
    "organization": "rowb.app",
    "url": "https://rowb.app"
  },
  "version": "1.0.0",
  "documentationUrl": "https://auth-posture.rowb.app/llms.txt",
  "capabilities": {
    "streaming": false,
    "pushNotifications": false,
    "extendedAgentCard": false
  },
  "defaultInputModes": [
    "application/json",
    "text/plain"
  ],
  "defaultOutputModes": [
    "application/json",
    "text/plain"
  ],
  "skills": [
    {
      "id": "audit-domain",
      "name": "Audit domain email posture",
      "description": "Check whether a domain can receive email and how its SPF/DMARC/DKIM are configured. REST: GET https://auth-posture.rowb.app/api/audit?domain={domain} (anonymous 3/day). MCP tool: audit_domain.",
      "tags": [
        "email",
        "mx",
        "spf",
        "dmarc",
        "dkim",
        "disposable"
      ]
    }
  ],
  "mcpUrl": "https://auth-posture.rowb.app/mcp"
}