x402 census · audit.152-53-82-29.sslip.io · 2e7deb63c57d · JSON
POST /v1/vulns
unprobed
Known vulnerabilities for a list of dependencies, npm and PyPI, in one call. Send {"npm":["lodash@4.17.20"],"pypi":["django==3.2.0"]} or a package.json or requirements.txt, up to 50 packages. Returns only packages that have advisories: OSV and GHSA ids, CVE aliases, severity, summary, and the first fixed version, plus counts. Unpinned packages are checked at their latest version. Deterministic OS…
Verdict: not verified by an unpaid GET. not probed yet. This says nothing about whether the route works when called as declared.
Facts from the catalogs
| Field | Value |
|---|---|
| URL | https://audit.152-53-82-29.sslip.io/v1/vulns |
| Method | POST |
| Price | $0.005 USDC = 5000 atomic units of 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 |
| Network | eip155:8453 (base); also accepts eip155:137, solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp |
| payTo | 0x9Ea52806dB0b25a8130D2b210D5336eC1DCFBa0e |
| Seller | audit.152-53-82-29.sslip.io |
| Catalogs | cdp (row updated 2026-09-23) |
| Listed since (lower bound) | 2026-09-23 (earliest catalog timestamp; catalogs report last-update times only) |
| Last catalog update | 2026-09-23 |
| CDP quality counters | 2 calls and 1 unique payers in 30 days, last call 2026-09-23 (catalog-reported, not verified on chain) |
| Category (keyword rule) | inference/llm |
| Templated path | no |
| x402Version in catalog | 2 |
| Service name / tags | manifest-audit · vulnerabilities, cve, osv, security, sca |
Unpaid probe (census of )
| Field | Value |
|---|---|
| Probe | not probed in this build |
No hourly re-probe has reached this resource yet; the cron covers a rotating slice of 150 per hour.
On-chain facts for the payTo (public address)
| Field | Value |
|---|---|
| Distinct payers | 5 |
| Payments | 21 |
| USDC volume | $0.19 |
| Median payment | n/a |
| First / last payment | 2026-09-23 / 2026-09-28 |
| Sampler-shaped share of payments | n/a |
| Payers that are not samplers | n/a |
| Source | blockscout-sample — newest page of inbound ERC-20 transfers only (<=50); counts are a floor, not a total |
| Address | 0x9Ea52806dB0b25a8130D2b210D5336eC1DCFBa0e |
Declared input and output (extensions.bazaar)
{
"input": {
"body": {
"npm": [
"lodash@4.17.20"
],
"pypi": [
"django==3.2.0"
]
},
"bodyType": "json",
"method": "POST",
"type": "http"
},
"output": {
"type": "json",
"example_truncated": true,
"chars": 501
}
}
Try it (unpaid: shows the 402)
curl -si -X POST 'https://audit.152-53-82-29.sslip.io/v1/vulns' -H 'accept: application/json' -H 'content-type: application/json' --data '{}'
The catalog declares POST. A 402 answer carries the payment requirements in the JSON body and, for x402 v2, base64 in the PAYMENT-REQUIRED header. This page never sends a payment.
Paid checks (x402, USDC on Base)
GET https://bazaar.agentexchange.work/r/2e7deb63c57d/probe.json re-runs this probe right now for $0.01 and writes the result here. POST https://bazaar.agentexchange.work/featured with {"id":"2e7deb63c57d"} places this resource at the top of the report and search pages for 30 days for $1.00, labelled. Unpaid requests answer 402 with the terms. Pricing.
Catalog references: agentic.market (CDP Bazaar front end) · this record as JSON · all resources on audit.152-53-82-29.sslip.io.