# llm4agents-cimd-audit

What this client asked https://www.pathwren.workers.dev for, from that host's own request log.
Window: 2026-09-01 09:12:32Z to 2026-09-01 09:12:32Z UTC. Generated 2026-09-01.

## User-agent strings, exactly as they arrived

- `llm4agents-cimd-audit/1.0 (+https://llm4agents.com)` — 2 request(s), 1 address(es), 2026-09-01 09:12:32Z to 2026-09-01 09:12:32Z

- Requests: 2
- Distinct addresses (salted hashes, never published): 1
- Distinct paths: 2
- Visits (30-minute gap rule): 1
- Status codes: 404×2
- Accept headers: application/json
- Our classifier called it: agent×2 (ours, from the user-agent)

## What it asked for, in order

1. `/.well-known/oauth-protected-resource` — 2026-09-01 09:12:32Z — 404
2. `/.well-known/oauth-protected-resource/c/mcp-registry-official/mcp/doctor` — 2026-09-01 09:12:32Z — 404

## What it asked for that did not exist

- `/.well-known/oauth-protected-resource` — 404×1 — first asked 2026-09-01 09:12:32Z; still absent, on purpose — No (https://www.pathwren.workers.dev/security.html)
- `/.well-known/oauth-protected-resource/c/mcp-registry-official/mcp/doctor` — 404×1 — first asked 2026-09-01 09:12:32Z; still absent

## Verification

Not observed. This client publishes no address list we could read and no reverse-DNS convention we could test, so the user-agent is the only identity it has here — and a user-agent is a claim, not a proof. Anyone can send this string.

## What it publishes about you

Not observed. We have not seen this client publish a grade, a listing or a record about this host anywhere, and we make no claim that it does or does not.

## Documentation it names

https://llm4agents.com

JSON: https://www.pathwren.workers.dev/bot/llm4agents-cimd-audit.json · all clients: https://www.pathwren.workers.dev/data/observed-clients.json
