Service record

Martin Estate Winery

https://agents.martinestate.com/
activeweb

Estate-grown Napa Valley wine. AI agents can browse and purchase wine with identity verification (KYC, age 21+, US only) via AgentScore.

Implementation fingerprint
unknown no confident attribution
Fingerprint evidence
No implementation-specific public signal observed.
First seen
Aug 25, 2026, 6:43 PM UTC
Last seen
Oct 9, 2026, 6:22 PM UTC
Origin
https://agents.martinestate.com
Tags
winecommercealcoholage-restrictedphysical-goodsnapa-valley

Payment surface

5 MPP endpoints

This count includes endpoints established by catalog, OpenAPI, or valid runtime 402 evidence. It does not count every URL the harmless scanner attempted.

JSON record →
GET
https://agents.martinestate.com/catalog
List purchasable wines
Status: 200TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 1, 06:21 AM UTC
No normalized payment offer observed for this endpoint.
GET
https://agents.martinestate.com/catalog/:slug
Get wine details by slug
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 9, 06:22 PM UTC
No normalized payment offer observed for this endpoint.
GET
https://agents.martinestate.com/orders/:id
Retrieve order details
Status: 401TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 9, 12:22 PM UTC
No normalized payment offer observed for this endpoint.
GET
https://agents.martinestate.com/orders/:id/status
Check payment status
Status: 401TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 1, 06:23 PM UTC
No normalized payment offer observed for this endpoint.
POST
https://agents.martinestate.com/purchase
Purchase wine with identity verification via AgentScore and MPP payment
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
tempochargecatalogamount unknown 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · dynamic
true
Session · amountHint
Variable
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
tempochargeopenapiamount unknown 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
solanachargeopenapiamount unknown EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
stripechargeopenapiamount unknown usd
Recipient
not observed
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.

Probe coverage

22 harmless observations

These are bounded unauthenticated requests and scanner-policy stops. A response without MPP evidence remains a discovery result, not a security failure.

GET https://agents.martinestate.com/catalog/:slug

HTTP 404

60 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:22 PM UTC

GET https://agents.martinestate.com/.well-known/api-catalog

HTTP 404

13 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:21 PM UTC

GET https://agents.martinestate.com/openapi.json

HTTP 200

12,053 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:21 PM UTC

GET https://agents.martinestate.com/orders/:id

HTTP 401

3,102 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:22 PM UTC

GET https://agents.martinestate.com/orders/:id/status

HTTP 401

3,120 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 6:23 PM UTC

GET https://agents.martinestate.com/catalog

HTTP 200

2,609 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 6:21 AM UTC

GET https://agents.martinestate.com/catalog/:slug

HTTP 404

60 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 12:21 AM UTC

GET https://agents.martinestate.com/.well-known/api-catalog

HTTP 404

13 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 12:20 AM UTC

GET https://agents.martinestate.com/openapi.json

HTTP 200

11,756 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 12:19 AM UTC

GET https://agents.martinestate.com/orders/:id

HTTP 401

3,120 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:19 PM UTC

GET https://agents.martinestate.com/orders/:id/status

HTTP 401

3,120 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 22, 2026, 12:24 PM UTC

GET https://agents.martinestate.com/catalog

HTTP 200

2,609 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 22, 2026, 12:24 AM UTC

GET https://agents.martinestate.com/catalog/:slug

HTTP 404

60 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 21, 2026, 6:23 PM UTC

GET https://agents.martinestate.com/.well-known/api-catalog

HTTP 404

13 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 21, 2026, 6:23 PM UTC

GET https://agents.martinestate.com/openapi.json

HTTP 200

11,219 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 21, 2026, 6:20 PM UTC

GET https://agents.martinestate.com/orders/:id

HTTP 401

3,120 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 21, 2026, 6:20 PM UTC

GET https://agents.martinestate.com/orders/:id/status

HTTP 401

3,120 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 13, 2026, 6:24 AM UTC

GET https://agents.martinestate.com/catalog

HTTP 200

2,609 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 13, 2026, 12:23 AM UTC

GET https://agents.martinestate.com/catalog/:slug

HTTP 404

60 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 12, 2026, 6:21 PM UTC

GET https://agents.martinestate.com/.well-known/api-catalog

HTTP 404

13 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 12, 2026, 6:20 PM UTC

GET https://agents.martinestate.com/openapi.json

HTTP 200

11,219 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 12, 2026, 6:19 PM UTC

GET https://agents.martinestate.com/orders/:id

HTTP 401

3,120 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 12, 2026, 6:18 PM UTC

Evidence model

Security properties

Every result names its evidence state. Unknown and not tested never mean secure.

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:22 PM UTC

bounded_response

Tested — pass

60 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:22 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:22 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 6:22 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:22 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:22 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:22 PM UTC

api_catalog_parse

Observed

No RFC 9727 API catalog was available at this URL (HTTP 404); prior advertised links were withdrawn

Basis: RFC 9727 discovery response · Oct 9, 2026, 6:21 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:21 PM UTC

bounded_response

Tested — pass

13 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:21 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 6:21 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:21 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:21 PM UTC

openapi_parse

Tested — pass

3 payment offer(s) accepted

Basis: harmless discovery response · Oct 9, 2026, 6:21 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:22 PM UTC

bounded_response

Tested — pass

3102 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:22 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:22 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:22 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 12:22 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:22 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:22 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:22 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:22 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 1, 2026, 6:23 PM UTC

bounded_response

Tested — pass

3120 bytes within scanner limit

Basis: harmless scanner · Oct 1, 2026, 6:23 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 1, 2026, 6:23 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 1, 2026, 6:23 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 1, 2026, 6:23 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 6:23 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 1, 2026, 6:23 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 1, 2026, 6:23 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 1, 2026, 6:23 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 1, 2026, 6:23 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 1, 2026, 6:23 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 1, 2026, 6:23 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 6:23 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 1, 2026, 6:23 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 1, 2026, 6:21 AM UTC

bounded_response

Tested — pass

2609 bytes within scanner limit

Basis: harmless scanner · Oct 1, 2026, 6:21 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 1, 2026, 6:21 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 1, 2026, 6:21 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 1, 2026, 6:21 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 6:21 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 1, 2026, 6:21 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 1, 2026, 6:21 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 1, 2026, 6:21 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 1, 2026, 6:21 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 1, 2026, 6:21 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 1, 2026, 6:21 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 6:21 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 1, 2026, 6:21 AM UTC

History

Service changes

Showing the latest 50 of 73 changes. Continue in the changes API view.

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"12053 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"13 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— payment-offer-updated

method: unknown → stripe

Evidence: openapi payment metadata

— payment-offer-withdrawn

offer-active: 1 → 0

Evidence: openapi source https://agents.martinestate.com/openapi.json

— payment-offer-updated

method: unknown → tempo

Evidence: openapi payment metadata

— endpoint-updated

description: Purchase wine with identity verification via AgentScore and MPP payment → Purchase wine. Requires identity verification via AgentScore and MPP payment.

Evidence: clock-guarded source update

— payment-offer-updated

currency: USD → usd

Evidence: openapi payment metadata

— payment-offer-updated

method: unknown → solana

Evidence: openapi payment metadata

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"13 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"12053 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:openapi_parse: {"state":"tested-pass","evidence":"4 payment offer(s) accepted","basis":"harmless discovery response"} → {"state":"tested-pass","evidence":"3 payment offer(s) accepted","basis":"harmless discovery response"}

Evidence: Repeated harmless observation changed the modeled property

— payment-offer-updated

currency: USD → EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v

Evidence: openapi payment metadata

— payment-offer-updated

session_json: {"mode":"dynamic","min":"50.00","max":"5000.00","x402":{"scheme":"exact","network":"base","asset":"USDC","client":"agen…

Evidence: openapi payment metadata

— payment-offer-updated

currency: USD → 0x20c000000000000000000000b9537d11c60e8b50

Evidence: openapi payment metadata

— payment-offer-updated

session_json: {"mode":"dynamic","min":"50.00","max":"5000.00","mpp":{"method":"solana","intent":"charge","currency":"EPjFWdd5AufqSSqe…

Evidence: openapi payment metadata

— payment-offer-updated

session_json: {"mode":"dynamic","min":"50.00","max":"5000.00","mpp":{"method":"tempo","intent":"charge","currency":"0x20c000000000000…

Evidence: openapi payment metadata

— endpoint-updated

description: Purchase wine. Requires identity verification via AgentScore and MPP payment. → Purchase wine with identity verification via AgentScore and MPP payment

Evidence: clock-guarded source update

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"3120 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"3102 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"11756 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"13 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— endpoint-updated

description: Purchase wine with identity verification via AgentScore and MPP payment → Purchase wine. Requires identity verification via AgentScore and MPP payment.

Evidence: clock-guarded source update

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"13 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"11756 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— endpoint-updated

description: Purchase wine. Requires identity verification via AgentScore and MPP payment. → Purchase wine with identity verification via AgentScore and MPP payment

Evidence: clock-guarded source update

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"11219 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"13 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— endpoint-updated

description: Purchase wine with identity verification via AgentScore and MPP payment → Purchase wine. Requires identity verification via AgentScore and MPP payment.

Evidence: clock-guarded source update

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"13 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"11219 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— endpoint-updated

description: Purchase wine. Requires identity verification via AgentScore and MPP payment. → Purchase wine with identity verification via AgentScore and MPP payment

Evidence: clock-guarded source update

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"11219 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"13 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property