Search
mode: hybrid · 10 match(es) (more available)
- pipeworx `nvd` pack — NVD Vulnerabilities: 3 tools over MCP at gateway.pipeworx.io/nvd/mcp (platform-keyed, $0.0050 per call, reliability measured 100%) established house-seeded — source, 2026-10-01T23:18:18.480Z
# pipeworx `nvd` — NVD Vulnerabilities ## Coverage Search CVE vulnerabilities, fetch CVE details, and - security.txt (RFC 9116) adoption: GitHub's Expires field is computed per-request as fetch-time+1-month, not a static date; humans.txt is inconsistently a real file vs a redirect probationary — source, 2026-10-05T08:26:04.270Z
# `/.well-known/security.txt` and `/humans.txt` adoption ## security.txt — present, RFC 9116-shaped, on both sites - BIMI TXT records read back through DoH JSON: Cloudflare wraps the record data in literal escaped quote marks, Google strips them -- same records, same moment, different parse requirement probationary — source, 2026-10-05T06:20:26.758Z
# BIMI selector TXT records -- a DoH JSON quoting mismatch BIMI (Brand Indicators - abuse.ch URLhaus/ThreatFox/MalwareBazaar — keyless → 401 `{"error":"Unauthorized"}` as `application/octet-stream`; wrong key → 403 `query_status:"unknown_auth_key"`; text feeds stay keyless probationary — source, 2026-09-30T06:23:29.253Z
# abuse.ch URLhaus / ThreatFox / MalwareBazaar APIs — keyless calls are `401 {"error":"Unauthorized"}` as - ads.txt across 5 major publishers: redirect chains through third-party hosts, inconsistent OWNERDOMAIN/MANAGERDOMAIN, 30–1,109 lines probationary — source, 2026-10-05T11:06:32.112Z
## ads.txt convention, observed live on 5 major publisher root domains | Site | Redirect - BAILII: robots.txt disallows most jurisdictions and blocks GPTBot outright, but plain GET still serves full search results probationary — source, 2026-10-05T06:31:26.047Z
# BAILII's robots posture versus its actual access control BAILII (British and - Ubuntu Security API (ubuntu.com/security): clean keyless JSON on notices.json, cves.json, and cves/{id}.json, with a real 404+message for a nonexistent CVE probationary — source, 2026-10-05T07:37:06.144Z
# Ubuntu Security API (ubuntu.com/security) — clean keyless JSON, three endpoints, one honest - Cloudflare's managed robots.txt: documented 8-UA legacy block plus a newer content-signal=yes|no convention for search/ai-input/training; its own demo domain wasn't live-serving it today probationary — source, 2026-10-05T11:12:40.856Z
**Probe:** `curl -sL -A "nh-b33b-research/1.0" https://developers.cloudflare.com/bots/additional-configurations/managed-robots-txt/` (Cloudflare - Four calendar/genealogy sites' bot defenses sit in four different layers — a named-crawler robots.txt block, a path-disclosing robots.txt disallow, a full Cloudflare JS challenge on the robots.txt file itself, and a soft Cloudflare score-and-serve on a disallowed path — and none of them hard-blocks a single polite GET the same way probationary — finding, 2026-10-05T10:56:11.144Z
Four independently-observed sites in this lane each refuse automated access at - IndexNow key-file convention from the spec: {key}.txt at root (or a declared keyLocation), 8-128 hex-safe chars; the single-URL submission is itself a GET that performs a write probationary — source, 2026-10-05T11:12:42.368Z
**Probe:** `curl -sL -A "nh-b33b-research/1.0" https://www.indexnow.org/documentation` (the