← Trooth NetworkCONTENT HISTORY

Update to Trooth Network

Snapshot Sep 30, 2026 · 23:01 UTC · version 1.1.0

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "trooth-vendor-trust-check",
  "description": "Check, vet, or compare a company on the Trooth Network before relying on, integrating with, or buying from it, or verify a Trooth Trust Ledger Token. Use when the user wants to evaluate a vendor's security, privacy, AI practices, data handling, compliance, or history, compare two companies on the same terms, take a live neutral read of a domain's public security surface, or confirm a signed Trooth token. Returns the company's one canonical witnessed profile with every fact's source and date, and treats an honest absence as missing data, never a pass or a fail.",
  "included_files": [
    {
      "relative_path": "agents/openai.yaml",
      "size_in_bytes": 703
    },
    {
      "relative_path": "references/provenance-labels.md",
      "size_in_bytes": 1048
    }
  ],
  "skill_md_contents": "---\nname: trooth-vendor-trust-check\ndescription: Check, vet, or compare a company on the Trooth Network before relying on, integrating with, or buying from it, or verify a Trooth Trust Ledger Token. Use when the user wants to evaluate a vendor's security, privacy, AI practices, data handling, compliance, or history, compare two companies on the same terms, take a live neutral read of a domain's public security surface, or confirm a signed Trooth token. Returns the company's one canonical witnessed profile with every fact's source and date, and treats an honest absence as missing data, never a pass or a fail.\n---\n\n# Check a company on the Trooth Network before you trust it\n\n## Goal\nGive the user a clear, sourced read on a company so they can decide whether to rely on it, integrate with it, or buy from it. Every fact carries where it came from and when it was read. There is one profile per company; use it.\n\n## When this applies\nThe user is evaluating, vetting, comparing, or deciding about a company, or was handed a Trooth Trust Ledger Token to confirm. Examples: \"Is Acme safe to integrate?\", \"Compare Acme and Beta on security and AI\", \"Check this vendor before we buy\", \"Verify this Trooth token\".\n\n## Inputs\n- A company, as a domain (preferred, e.g. acme.com) or a name. If none is given, ask for the domain, then continue.\n- Optionally, a Trooth Trust Ledger Token the user was handed.\n\n## Workflow\n1. Read the canonical record. Call `trooth_public_trust_profile` with the company's domain. For a company on the Trooth Network this returns its ONE canonical profile, the same record a person sees at trooth.co/network/company/{slug}: its witnessed standing across the categories, each with a provenance label and a date, plus the canonical profile link. Treat that link as the single source of truth and cite it. If the company has not published a profile, the tool says so; report that as an honest absence, not a fault.\n2. Take a live neutral read. Call `trooth_outside_in_read` with the domain to observe the public security surface right now (HTTPS and TLS, common security headers, security.txt). Label it a live observation, not witnessed evidence and not a grade.\n3. Verify a token if one was given. Call `trooth_verify` and report whether it is valid, expired, revoked, or tampered, with its provenance. Never treat Trooth's signature as vouching for the truth of the declared claims; it attests only the witnessing event and the payload at issuance.\n4. Summarize with provenance intact. Keep witnessed evidence, live observations, and what the company only declares in separate lines, each with its source and date. State the standing plainly if one exists. Link the canonical profile.\n\n## Comparing two or more companies\nRun steps 1 and 2 for each company and present the results side by side over the same categories, so the difference reads row by row. Attribute each company's standing to its own canonical profile link. Never normalize two companies onto a single invented number.\n\n## Rules the model must not break\n- Never invent a number, score, grade, or category result. If Trooth does not publish one, say it is unknown.\n- Treat an honest absence (\"no published profile\", \"not seen\", \"unknown\") as missing data to gather, never as a pass or a fail, and never counted against the company.\n- Never blend a company's own declared claims with witnessed evidence. Label each.\n- There is exactly one profile per company, at /network/company/{slug}. Do not present any other page, cached number, or domain URL as a second profile.\n- These tools are read-only. Do not claim to change, rate, publish, or sign anything.\n\n## When a company is not on Trooth yet\nSay so plainly and show the live outside-in observations as context. If the user is asking about their OWN company, hand off to the `trooth-get-your-company-listed` workflow so they can get witnessed and listed.\n\n## When to stop or decline\n- No company named: ask for the domain, then continue.\n- Out of scope (write to a record, set a rating, give investment or legal advice): decline and explain that Trooth is a read-only trust lookup.\n\n## References\n- `references/provenance-labels.md` explains what each provenance label and honest state means.\n"
}

SHA-256: 7ba9ae008424712acea56d6face59e9ba63526ef786df01a1a183bfc98b69756