x402 census · safe.cyberwarex.com · 7023c5595b49 · JSON
GET /check
unprobed
Score a URL for phishing risk before an agent opens or trusts it. Keyless, deterministic heuristics - typosquat / homoglyph of a known brand, punycode / mixed-script hosts, credentials-in-URL, raw-IP hosts, suspicious TLDs, over-deep subdomains - plus a best-effort domain-age check (young domains are a top phishing signal). Returns a 0-100 risk score, a SAFE / SUSPICIOUS / DANGEROUS verdict, and …
Verdict: not verified by an unpaid GET. not probed yet. This says nothing about whether the route works when called as declared.
Facts from the catalogs
| Field | Value |
|---|---|
| URL | https://safe.cyberwarex.com/check |
| Method | GET |
| Price | $0.003 USDC = 3000 atomic units of 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 |
| Network | eip155:8453 (base) |
| payTo | 0x058D0Cc5CC97e61e8A9f38D6d6365bce525921B2 |
| Seller | safe.cyberwarex.com |
| Catalogs | cdp (row updated 2026-09-30) |
| Listed since (lower bound) | 2026-09-30 (earliest catalog timestamp; catalogs report last-update times only) |
| Last catalog update | 2026-09-30 |
| CDP quality counters | 29 calls and 2 unique payers in 30 days, last call 2026-09-30 (catalog-reported, not verified on chain) |
| Category (keyword rule) | inference/llm |
| Templated path | no |
| x402Version in catalog | 2 |
| Service name / tags | URL Safety · phishing, url, security, typosquat, safety |
Unpaid probe (census of )
| Field | Value |
|---|---|
| Probe | not probed in this build |
No hourly re-probe has reached this resource yet; the cron covers a rotating slice of 150 per hour.
On-chain facts for the payTo (public address)
| Field | Value |
|---|---|
| Distinct payers | 5 |
| Payments | 18 |
| USDC volume | $0.16 |
| Median payment | $0.003 |
| First / last payment | 2026-08-30 / 2026-09-29 |
| Sampler-shaped share of payments | 94.4% |
| Payers that are not samplers | 1 |
| Source | forensics-2026-09-30 |
| Address | 0x058D0Cc5CC97e61e8A9f38D6d6365bce525921B2 |
Declared input and output (extensions.bazaar)
{
"input": {
"method": "GET",
"queryParams": {
"url": "https://coinbase.com.secure-login.xyz/verify"
},
"type": "http"
},
"output": {
"type": "json",
"example": {
"domain_age_days": 4,
"host": "coinbase.com.secure-login.xyz",
"labels": [
"brand_impersonation",
"suspicious_tld"
],
"reasons": [
"'coinbase' appears in the host but the domain is secure-login.xyz, not coinbase.com"
],
"registrable_domain": "secure-login.xyz",
"risk_score": 80,
"source": "heuristics + RDAP",
"url": "https://coinbase.com.secure-login.xyz/verify",
"verdict": "DANGEROUS"
}
}
}
Try it (unpaid: shows the 402)
curl -si -X GET 'https://safe.cyberwarex.com/check' -H 'accept: application/json'
The catalog declares GET. A 402 answer carries the payment requirements in the JSON body and, for x402 v2, base64 in the PAYMENT-REQUIRED header. This page never sends a payment.
Paid checks (x402, USDC on Base)
GET https://bazaar.agentexchange.work/r/7023c5595b49/probe.json re-runs this probe right now for $0.01 and writes the result here. POST https://bazaar.agentexchange.work/featured with {"id":"7023c5595b49"} places this resource at the top of the report and search pages for 30 days for $1.00, labelled. Unpaid requests answer 402 with the terms. Pricing.
Catalog references: agentic.market (CDP Bazaar front end) · this record as JSON · all resources on safe.cyberwarex.com.