Agent Exchange x402 census and directory

x402 census · safe.cyberwarex.com · 7023c5595b49 · JSON

GET /check

unprobed

Score a URL for phishing risk before an agent opens or trusts it. Keyless, deterministic heuristics - typosquat / homoglyph of a known brand, punycode / mixed-script hosts, credentials-in-URL, raw-IP hosts, suspicious TLDs, over-deep subdomains - plus a best-effort domain-age check (young domains are a top phishing signal). Returns a 0-100 risk score, a SAFE / SUSPICIOUS / DANGEROUS verdict, and …

Verdict: not verified by an unpaid GET. not probed yet. This says nothing about whether the route works when called as declared.

Facts from the catalogs

FieldValue
URLhttps://safe.cyberwarex.com/check
MethodGET
Price$0.003 USDC = 3000 atomic units of 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Networkeip155:8453 (base)
payTo0x058D0Cc5CC97e61e8A9f38D6d6365bce525921B2
Sellersafe.cyberwarex.com
Catalogscdp (row updated 2026-09-30)
Listed since (lower bound)2026-09-30 (earliest catalog timestamp; catalogs report last-update times only)
Last catalog update2026-09-30
CDP quality counters29 calls and 2 unique payers in 30 days, last call 2026-09-30 (catalog-reported, not verified on chain)
Category (keyword rule)inference/llm
Templated pathno
x402Version in catalog2
Service name / tagsURL Safety · phishing, url, security, typosquat, safety

Unpaid probe (census of )

FieldValue
Probenot probed in this build

No hourly re-probe has reached this resource yet; the cron covers a rotating slice of 150 per hour.

On-chain facts for the payTo (public address)

FieldValue
Distinct payers5
Payments18
USDC volume$0.16
Median payment$0.003
First / last payment2026-08-30 / 2026-09-29
Sampler-shaped share of payments94.4%
Payers that are not samplers1
Sourceforensics-2026-09-30
Address0x058D0Cc5CC97e61e8A9f38D6d6365bce525921B2

Declared input and output (extensions.bazaar)

{
 "input": {
  "method": "GET",
  "queryParams": {
   "url": "https://coinbase.com.secure-login.xyz/verify"
  },
  "type": "http"
 },
 "output": {
  "type": "json",
  "example": {
   "domain_age_days": 4,
   "host": "coinbase.com.secure-login.xyz",
   "labels": [
    "brand_impersonation",
    "suspicious_tld"
   ],
   "reasons": [
    "'coinbase' appears in the host but the domain is secure-login.xyz, not coinbase.com"
   ],
   "registrable_domain": "secure-login.xyz",
   "risk_score": 80,
   "source": "heuristics + RDAP",
   "url": "https://coinbase.com.secure-login.xyz/verify",
   "verdict": "DANGEROUS"
  }
 }
}

Try it (unpaid: shows the 402)

curl -si -X GET 'https://safe.cyberwarex.com/check' -H 'accept: application/json'

The catalog declares GET. A 402 answer carries the payment requirements in the JSON body and, for x402 v2, base64 in the PAYMENT-REQUIRED header. This page never sends a payment.

Paid checks (x402, USDC on Base)

GET https://bazaar.agentexchange.work/r/7023c5595b49/probe.json re-runs this probe right now for $0.01 and writes the result here. POST https://bazaar.agentexchange.work/featured with {"id":"7023c5595b49"} places this resource at the top of the report and search pages for 30 days for $1.00, labelled. Unpaid requests answer 402 with the terms. Pricing.

Catalog references: agentic.market (CDP Bazaar front end) · this record as JSON · all resources on safe.cyberwarex.com.