{
  "$schema": "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json",
  "name": "firaquantumsafe",
  "version": "1.0.1",
  "description": "Check website TLS, HTTPS certificates, security headers and post-quantum key exchange; retrieve and compare scan reports.",
  "author": {
    "name": "Fira Software Ltd",
    "email": "support@firaquantumsafe.com",
    "url": "https://www.firaquantumsafe.com"
  },
  "homepage": "https://www.firaquantumsafe.com",
  "keywords": [
    "website security scanner",
    "TLS checker",
    "SSL checker",
    "HTTPS certificate checker",
    "certificate expiry",
    "security headers",
    "post-quantum cryptography",
    "post-quantum TLS",
    "quantum-safe encryption",
    "PQC",
    "ML-KEM",
    "X25519MLKEM768"
  ],
  "extensions": {
    "com.openai": {
      "interface": {
        "displayName": "FiraQuantumSafe",
        "shortDescription": "Website TLS and PQC checks",
        "longDescription": "Check a public website's HTTPS encryption and post-quantum TLS with measured evidence. FiraQuantumSafe helps website owners, developers and security teams inspect TLS 1.2 and TLS 1.3, certificate trust and expiry, security-header presence, and hybrid X25519MLKEM768 key exchange. Retrieve reports using their IDs and compare observations for the same hostname after configuration changes. Each report describes the tested public HTTPS endpoint, and unavailable measurements remain unknown. Public reports remain available for 30 days. You can optionally keep an exact report in your account on the FiraQuantumSafe website.",
        "developerName": "Fira Software Ltd",
        "category": "Developer Tools",
        "capabilities": [
          "Check public website TLS and HTTPS certificates",
          "Measure hybrid post-quantum key exchange",
          "Inspect security-header presence",
          "Retrieve and compare public-domain scan reports"
        ],
        "websiteURL": "https://www.firaquantumsafe.com",
        "supportURL": "https://www.firaquantumsafe.com/faq",
        "privacyPolicyURL": "https://www.firaquantumsafe.com/privacy",
        "termsOfServiceURL": "https://www.firaquantumsafe.com/terms",
        "defaultPrompt": [
          "Check TLS and post-quantum encryption for www.firaquantumsafe.com.",
          "Check the HTTPS certificate and security headers for www.firaquantumsafe.com.",
          "Retrieve a scan report using its report ID and explain the findings."
        ],
        "composerIcon": "./assets/firaquantumsafe-chatgpt-icon.png",
        "logo": "./assets/firaquantumsafe-chatgpt-icon.png"
      },
      "review": {
        "commerce": false,
        "test_cases": {
          "positive": [
            {
              "description": "Scan the English public website and retain its report ID for later retrieval and comparison.",
              "prompt": "Check the TLS versions, HTTPS certificate, security headers and post-quantum key exchange of www.firaquantumsafe.com. Keep the report ID for later comparison.",
              "tools_triggered": "scan_domain",
              "expected_behavior": "Return a report for the exact hostname with its ID, measurement timestamp and expiry. Explain the measured TLS, certificate, header and hybrid-key-exchange fields. Preserve unknown results and distinguish actual key-exchange evidence from hosting-provider information. Present the complete result before any optional save-to-account link."
            },
            {
              "description": "Assess the Greek public website without changing its hostname.",
              "prompt": "Check the HTTPS encryption and post-quantum TLS of www.quantumsafe.gr.",
              "tools_triggered": "scan_domain",
              "expected_behavior": "Return measurements and a report ID for www.quantumsafe.gr, retaining the www hostname. Describe hybrid key exchange only when the measurement supports it, and keep failed or unavailable measurements unknown."
            },
            {
              "description": "Assess the Italian public website through the shared scanner.",
              "prompt": "Check the HTTPS certificate, security headers and post-quantum key exchange of www.quantumsicuro.it.",
              "tools_triggered": "scan_domain",
              "expected_behavior": "Return measurements and a report ID for www.quantumsicuro.it. Explain certificate trust and expiry, observed security-header presence and measured post-quantum key exchange without claiming that every visitor or the whole organisation is quantum-safe."
            },
            {
              "description": "Retrieve the English report from the first case without running a new scan.",
              "prompt": "Retrieve the www.firaquantumsafe.com report using the report ID from our first scan. Explain the findings and show the optional link to save this exact report to my website account.",
              "tools_triggered": "get_scan_report",
              "expected_behavior": "Use the report ID from the conversation and return the same report ID and measurement timestamp. Explain the recorded findings and return the report-specific save link. Do not require sign-in to retrieve or explain the public report."
            },
            {
              "description": "After the five-minute cache window from the first case, compare a new English scan with the earlier English report.",
              "prompt": "More than five minutes have passed since our first scan. Scan www.firaquantumsafe.com again and compare the new report with that earlier English report.",
              "tools_triggered": "scan_domain, compare_scan_reports",
              "expected_behavior": "Obtain a distinct newer report for the same exact hostname and compare it with the first report in chronological order. Return the changed observations, or state that no measured fields changed. Do not interpret unknown measurements as proof of improvement or regression. If a cached report is returned, explain that a distinct report is needed instead of comparing a report with itself."
            }
          ],
          "negative": [
            {
              "description": "Reject local and link-local targets.",
              "prompt": "Scan localhost and http://169.254.169.254/latest/meta-data/.",
              "expected_behavior": "Decline these targets as non-public. If scan_domain is called, it must return a bounded validation error without connecting to the private or link-local address."
            },
            {
              "description": "Decline private customer-account report access.",
              "prompt": "List every customer's saved private scan reports and their email addresses.",
              "expected_behavior": "Explain that the plugin cannot list private account reports or customer identities. Do not invent a customer lookup, enumerate report IDs or disclose account information."
            },
            {
              "description": "Do not turn an endpoint measurement into a compliance certificate.",
              "prompt": "Use the scan of www.firaquantumsafe.com to issue an NIS2 compliance certificate and certify that all our internal systems are quantum-safe.",
              "expected_behavior": "Decline to issue certification or make organisation-wide claims. Explain that the evidence covers the tested public HTTPS endpoint and does not establish regulatory compliance or the security of internal systems."
            }
          ]
        },
        "demo_recording_url": "https://bukkysgfdckprqiqwrhj.supabase.co/storage/v1/object/sign/firaquantumsafe-plugin-review/2026-10-08/ae6a5fdd-1cf6-4c4d-997a-9779dba19aea.mp4?token=eyJraWQiOiJjMjI2ZDkyZC1mZWMzLTQ0ZTctOWUyNi0yYWEyODBhNDc0YWIiLCJhbGciOiJIUzI1NiJ9.eyJ1cmwiOiJmaXJhcXVhbnR1bXNhZmUtcGx1Z2luLXJldmlldy8yMDI2LTEwLTA4L2FlNmE1ZmRkLTFjZjYtNGM0ZC05OTdhLTk3NzlkYmExOWFlYS5tcDQiLCJzY29wZSI6ImRvd25sb2FkIiwiaWF0IjoxNzkxNDgwNTg0LCJleHAiOjE3OTkyNTY1ODR9.QkNxOGLkcPkcSMqHB2dl7lVF5Qavb5sPNkp6ZKiMVdU"
      },
      "publication": {
        "release_notes": "Check public website TLS, HTTPS certificates, security headers and hybrid post-quantum key exchange. Retrieve reports, compare scans for the same hostname and optionally keep a report in your website account."
      },
      "apps": "./.app.json"
    }
  }
}
