x402 census · fachada.chelsea-hermes.workers.dev · 95746fe4c559 · JSON
POST /scan/v1/code/scan
unprobed
Static security scan of a code snippet. Finds hardcoded secrets (AWS keys, private keys, API keys, DB connection strings with passwords), eval/exec, command injection, HTTP calls with no timeout, weak hashes (md5/sha1), bare except and unverified JWT. Returns one entry per finding with rule, severity, exact line number, the offending line and a suggested fix. Rule-based and deterministic: no LLM,…
Verdict: not verified by an unpaid GET. not probed yet. This says nothing about whether the route works when called as declared.
Facts from the catalogs
| Field | Value |
|---|---|
| URL | https://fachada.chelsea-hermes.workers.dev/scan/v1/code/scan |
| Method | POST |
| Price | $1.00 USDC = 1000000 atomic units of 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 |
| Network | eip155:8453 (base) |
| payTo | 0x734DD50Abb63ea5Af3D92b8016825475694BD883 |
| Seller | fachada.chelsea-hermes.workers.dev |
| Catalogs | cdp (row updated 2026-09-28) |
| Listed since (lower bound) | 2026-09-28 (earliest catalog timestamp; catalogs report last-update times only) |
| Last catalog update | 2026-09-28 |
| CDP quality counters | 4 calls and 1 unique payers in 30 days, last call 2026-09-28 (catalog-reported, not verified on chain) |
| Category (keyword rule) | inference/llm |
| Templated path | no |
| x402Version in catalog | 2 |
| Service name / tags | Code security scan · security, code, static-analysis, sast, python |
Unpaid probe (census of )
| Field | Value |
|---|---|
| Probe | not probed in this build |
No hourly re-probe has reached this resource yet; the cron covers a rotating slice of 150 per hour.
On-chain facts for the payTo (public address)
| Field | Value |
|---|---|
| Settlement history | unresolved: payTo not seen in the payer forensics (180 wallets' outbound history) or the Blockscout sample |
Declared input and output (extensions.bazaar)
{
"input": {
"body": {
"code": "import hashlib\nAPI_KEY = 'sk-live-9f2b7c41a8de5f60b3c2'\ndef h(p):\n return hashlib.md5(p.encode()).hexdigest()\n",
"language": "python"
},
"bodyType": "json",
"description": "language: python | javascript (how the snippet should be parsed); code: the source code to scan, as plain text",
"method": "POST",
"type": "http"
},
"output": {
"type": "json",
"example_truncated": true,
"chars": 624
}
}
Try it (unpaid: shows the 402)
curl -si -X POST 'https://fachada.chelsea-hermes.workers.dev/scan/v1/code/scan' -H 'accept: application/json' -H 'content-type: application/json' --data '{}'
The catalog declares POST. A 402 answer carries the payment requirements in the JSON body and, for x402 v2, base64 in the PAYMENT-REQUIRED header. This page never sends a payment.
Paid checks (x402, USDC on Base)
GET https://bazaar.agentexchange.work/r/95746fe4c559/probe.json re-runs this probe right now for $0.01 and writes the result here. POST https://bazaar.agentexchange.work/featured with {"id":"95746fe4c559"} places this resource at the top of the report and search pages for 30 days for $1.00, labelled. Unpaid requests answer 402 with the terms. Pricing.
Catalog references: agentic.market (CDP Bazaar front end) · this record as JSON · all resources on fachada.chelsea-hermes.workers.dev.