x402 census · lazaretto.dev · 4e8f73f12601 · JSON
POST /v1/scan
unprobed
Deterministic pre-install verification for npm packages, AI agent skills and MCP tools. Matches the exact version against OSV and OpenSSF malicious-package advisories, then runs behavioral analysis for credential theft, exfiltration, obfuscation, prompt injection and install-time droppers, returning a verdict with file-and-line evidence, a SHA-256 of what was analyzed, and a signed attestation th…
Verdict: not verified by an unpaid GET. not probed yet. This says nothing about whether the route works when called as declared.
Facts from the catalogs
| Field | Value |
|---|---|
| URL | https://lazaretto.dev/v1/scan |
| Method | POST |
| Price | $0.03 USDC = 30000 atomic units of 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 |
| Network | eip155:8453 (base) |
| payTo | 0x428df107e32E08288fcAC6567f4F40bc4eAB4Da0 |
| Seller | lazaretto.dev |
| Catalogs | cdp (row updated 2026-09-17) |
| Listed since (lower bound) | 2026-09-17 (earliest catalog timestamp; catalogs report last-update times only) |
| Last catalog update | 2026-09-17 |
| CDP quality counters | 1 calls and 1 unique payers in 30 days, last call 2026-09-17 (catalog-reported, not verified on chain) |
| Category (keyword rule) | inference/llm |
| Templated path | no |
| x402Version in catalog | 2 |
| Service name / tags | none |
Unpaid probe (census of )
| Field | Value |
|---|---|
| Probe | not probed in this build |
No hourly re-probe has reached this resource yet; the cron covers a rotating slice of 150 per hour.
On-chain facts for the payTo (public address)
| Field | Value |
|---|---|
| Distinct payers | 2 |
| Payments | 2 |
| USDC volume | $0.06 |
| Median payment | $0.03 |
| First / last payment | 2026-08-30 / 2026-09-17 |
| Sampler-shaped share of payments | 100.0% |
| Payers that are not samplers | 0 |
| Source | forensics-2026-09-30 |
| Address | 0x428df107e32E08288fcAC6567f4F40bc4eAB4Da0 |
Declared input and output (extensions.bazaar)
{
"input": {
"body": {
"depth": "full",
"target": {
"ref": "left-pad@1.3.0",
"type": "npm_package"
}
},
"bodyType": "json",
"method": "POST",
"type": "http"
},
"output": {
"type": "json",
"example": {
"confidence": "high",
"risk": "none",
"target_hash": "sha256:aa57b3ac555f3bfe2357e8a2e7ddfaa77934597887502db9ca0e660d388bf85f",
"verdict": "clear"
}
}
}
Try it (unpaid: shows the 402)
curl -si -X POST 'https://lazaretto.dev/v1/scan' -H 'accept: application/json' -H 'content-type: application/json' --data '{}'
The catalog declares POST. A 402 answer carries the payment requirements in the JSON body and, for x402 v2, base64 in the PAYMENT-REQUIRED header. This page never sends a payment.
Paid checks (x402, USDC on Base)
GET https://bazaar.agentexchange.work/r/4e8f73f12601/probe.json re-runs this probe right now for $0.01 and writes the result here. POST https://bazaar.agentexchange.work/featured with {"id":"4e8f73f12601"} places this resource at the top of the report and search pages for 30 days for $1.00, labelled. Unpaid requests answer 402 with the terms. Pricing.
Catalog references: agentic.market (CDP Bazaar front end) · this record as JSON · all resources on lazaretto.dev.