x402 census · shellpermit.schemasure.com · 1ae8ddc81765 · JSON
POST /v1/guard/shell
unprobed
Decide whether an agent-authored bash command complies with an execution policy, using a real shell tokenizer rather than pattern matching. Catches recursive deletes, force pushes, cluster and infrastructure teardown, raw device writes, path escapes, privilege escalation, and curl-piped-to-shell through pipelines, substitutions, quoting games and base64. Returns reason codes with spans and an opt…
Verdict: not verified by an unpaid GET. not probed yet. This says nothing about whether the route works when called as declared.
Facts from the catalogs
| Field | Value |
|---|---|
| URL | https://shellpermit.schemasure.com/v1/guard/shell |
| Method | POST |
| Price | $0.01 USDC = 15000 atomic units of 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 |
| Network | eip155:8453 (base) |
| payTo | 0x9876af0F6D8Ed5155Cd02d1ca56D128601612690 |
| Seller | shellpermit.schemasure.com |
| Catalogs | cdp (row updated 2026-09-29) |
| Listed since (lower bound) | 2026-09-29 (earliest catalog timestamp; catalogs report last-update times only) |
| Last catalog update | 2026-09-29 |
| CDP quality counters | 14 calls and 1 unique payers in 30 days, last call 2026-09-29 (catalog-reported, not verified on chain) |
| Category (keyword rule) | agent-services |
| Templated path | no |
| x402Version in catalog | 2 |
| Service name / tags | ShellPermit · shell, bash, command, guard, policy |
Unpaid probe (census of )
| Field | Value |
|---|---|
| Probe | not probed in this build |
No hourly re-probe has reached this resource yet; the cron covers a rotating slice of 150 per hour.
On-chain facts for the payTo (public address)
| Field | Value |
|---|---|
| Distinct payers | 6 |
| Payments | 11 |
| USDC volume | $0.11 |
| Median payment | $0.01 |
| First / last payment | 2026-07-27 / 2026-09-30 |
| Sampler-shaped share of payments | 100.0% |
| Payers that are not samplers | 0 |
| Source | forensics-2026-09-30 |
| Address | 0x9876af0F6D8Ed5155Cd02d1ca56D128601612690 (contract: EIP7702StatelessDeleGator) |
Declared input and output (extensions.bazaar)
{
"input": {
"body": {
"audience": "executor:acme-prod-01",
"command": "rm -rf ./dist && npm run build",
"issue_permit": true,
"policy": {
"allow_destructive": true,
"allow_network_egress": false,
"allowed_roots": [
"/srv/app"
],
"cwd": "/srv/app"
},
"shell": "bash"
},
"bodyType": "json",
"method": "POST",
"type": "http"
},
"output": {
"type": "json",
"example": {
"confidence": 1,
"evidence": [],
"ok": true,
"result": {
"canonical_command": "rm -f -r ./dist && npm run build",
"cmd_fingerprint": "a1b2c3d4e5f60718",
"cmd_hash": "sha256:0f4c…1c2d",
"permit": "eyJhbGciOiJFZDI1NTE5Iiwia2lkIjoi…"
},
"risk_codes": [],
"verdict": "pass",
"warnings": [
"cmd_fingerprint is ADVISORY and must not be used for authorization."
]
}
}
}
Try it (unpaid: shows the 402)
curl -si -X POST 'https://shellpermit.schemasure.com/v1/guard/shell' -H 'accept: application/json' -H 'content-type: application/json' --data '{}'
The catalog declares POST. A 402 answer carries the payment requirements in the JSON body and, for x402 v2, base64 in the PAYMENT-REQUIRED header. This page never sends a payment.
Paid checks (x402, USDC on Base)
GET https://bazaar.agentexchange.work/r/1ae8ddc81765/probe.json re-runs this probe right now for $0.01 and writes the result here. POST https://bazaar.agentexchange.work/featured with {"id":"1ae8ddc81765"} places this resource at the top of the report and search pages for 30 days for $1.00, labelled. Unpaid requests answer 402 with the terms. Pricing.
Catalog references: agentic.market (CDP Bazaar front end) · this record as JSON · all resources on shellpermit.schemasure.com.