Agent Exchange x402 census and directory

x402 census · x402-api-catalog.onrender.com · 09ebf959fc8c · JSON

GET /api/mcp-audit

unprobed

MCP server safety audit: completes a real initialize+tools/list handshake, then statically scans every tool's name/description/schema for hidden unicode (tool-poisoning), prompt-injection-style phrasing, and tools that quietly combine multiple high-privilege capabilities (network+filesystem+exec+credential access). If a GitHub repo is supplied, folds in a real software-supply-chain signal too.

Verdict: not verified by an unpaid GET. not probed yet. This says nothing about whether the route works when called as declared.

Facts from the catalogs

FieldValue
URLhttps://x402-api-catalog.onrender.com/api/mcp-audit
MethodGET
Price$0.06 USDC = 60000 atomic units of 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Networkeip155:8453 (base)
payTo0x9041f8a43D0B43209B9227DE2c7fb25c9FE3847E
Sellerx402-api-catalog.onrender.com
Catalogscdp (row updated 2026-09-07)
Listed since (lower bound)2026-09-07 (earliest catalog timestamp; catalogs report last-update times only)
Last catalog update2026-09-07
CDP quality counters2 calls and 1 unique payers in 30 days, last call 2026-09-07 (catalog-reported, not verified on chain)
Category (keyword rule)trading-signals
Templated pathno
x402Version in catalog2
Service name / tagsPreFlight Checker · mcp, security, audit, tool-poisoning, prompt-injection

Unpaid probe (census of )

FieldValue
Probenot probed in this build

No hourly re-probe has reached this resource yet; the cron covers a rotating slice of 150 per hour.

On-chain facts for the payTo (public address)

FieldValue
Distinct payers2
Payments23
USDC volume$3.61
Median paymentn/a
First / last payment2026-09-07 / 2026-09-29
Sampler-shaped share of paymentsn/a
Payers that are not samplersn/a
Sourceblockscout-sample — newest page of inbound ERC-20 transfers only (<=50); counts are a floor, not a total
Address0x9041f8a43D0B43209B9227DE2c7fb25c9FE3847E

Declared input and output (extensions.bazaar)

{
 "input": {
  "method": "GET",
  "queryParams": {
   "repo": "example-org/example-mcp-server",
   "url": "https://mcp.example.com/mcp"
  },
  "type": "http"
 },
 "output": {
  "type": "json",
  "example": {
   "findings": [],
   "score": 90,
   "tools_found": 3,
   "url": "https://mcp.example.com/mcp",
   "verdict": "healthy: no red flags found"
  }
 }
}

Try it (unpaid: shows the 402)

curl -si -X GET 'https://x402-api-catalog.onrender.com/api/mcp-audit' -H 'accept: application/json'

The catalog declares GET. A 402 answer carries the payment requirements in the JSON body and, for x402 v2, base64 in the PAYMENT-REQUIRED header. This page never sends a payment.

Paid checks (x402, USDC on Base)

GET https://bazaar.agentexchange.work/r/09ebf959fc8c/probe.json re-runs this probe right now for $0.01 and writes the result here. POST https://bazaar.agentexchange.work/featured with {"id":"09ebf959fc8c"} places this resource at the top of the report and search pages for 30 days for $1.00, labelled. Unpaid requests answer 402 with the terms. Pricing.

Catalog references: agentic.market (CDP Bazaar front end) · this record as JSON · all resources on x402-api-catalog.onrender.com.