Agent Exchange x402 census and directory

x402 census · api.agentstools.dev · b310afdd715e · JSON

POST /mcp/scan

method-gated

Static security scan of an MCP manifest or tool list. Detects tool poisoning, hidden unicode instructions, prompt injection, data-exfiltration directives, dangerous capabilities, tool shadowing and post-approval rug-pull drift. Returns a 0-100 risk score, category, per-tool findings and content hashes. Security indicators, not a guarantee.

Verdict: not verified by an unpaid GET. 405/400: the 402 sits behind the declared method. This says nothing about whether the route works when called as declared.

Facts from the catalogs

FieldValue
URLhttps://api.agentstools.dev/mcp/scan
MethodPOST
Price$0.01 USDC = 10000 atomic units of 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Networkeip155:8453 (base)
payTo0xF22e558a00D91Ee12A1F50C52186FecB8dDFf493
Sellerapi.agentstools.dev
Catalogscdp (row updated 2026-09-28)
Listed since (lower bound)2026-09-28 (earliest catalog timestamp; catalogs report last-update times only)
Last catalog update2026-09-28
CDP quality counters2 calls and 2 unique payers in 30 days, last call 2026-09-28 (catalog-reported, not verified on chain)
Category (keyword rule)crypto-data
Templated pathno
x402Version in catalog2
Service name / tagsmcp-scan · mcp, security, tool-poisoning, prompt-injection, scanner

Unpaid probe (census of 2026-09-30)

FieldValue
Probed at2026-09-30T23:59:55.465Z
HEAD405
GET405
Verdictmethod-gated 405/400: the 402 sits behind the declared method
402 carried inn/a
x402Version in the 402n/a
accepts[0]none
Live amount equals catalog pricenot comparable
Live payTo equals catalog payTonot comparable
extensions.bazaar in the 402no
PAYMENT-REQUIRED headerno
WWW-Authenticate offernone
Content type / server / CORSapplication/json / uvicorn / none
Latency2,576 ms
Errornone

No hourly re-probe has reached this resource yet; the cron covers a rotating slice of 150 per hour.

On-chain facts for the payTo (public address)

FieldValue
Distinct payers45
Payments314
USDC volume$2.00
Median payment$0.003
First / last payment2026-07-07 / 2026-09-30
Sampler-shaped share of payments98.4%
Payers that are not samplers1
Sourceforensics-2026-09-30
Address0xF22e558a00D91Ee12A1F50C52186FecB8dDFf493

Declared input and output (extensions.bazaar)

{
 "input": {
  "body": {
   "manifest": {
    "tools": [
     {
      "description": "Get the weather for a city.",
      "inputSchema": {
       "properties": {
        "city": {
         "type": "string"
        }
       },
       "type": "object"
      },
      "name": "get_weather"
     }
    ]
   }
  },
  "bodyType": "json",
  "method": "POST",
  "type": "http"
 },
 "output": {
  "type": "json",
  "example": {
   "coverage": {
    "dimensions_flagged": [],
    "dimensions_total": 8,
    "tools_scanned": 1
   },
   "disclaimer": "Automated security indicators, not a guarantee.",
   "findings": [],
   "manifest_hash": "sha256:…",
   "object": "manifest",
   "per_tool": {
    "get_weather": {
     "category": "clean",
     "findings": [],
     "score": 0,
     "tool_hash": "sha256:…"
    }
   },
   "reasons": [],
   "risk_category": "clean",
   "risk_score": 0,
   "tool_count": 1
  }
 }
}

Try it (unpaid: shows the 402)

curl -si -X POST 'https://api.agentstools.dev/mcp/scan' -H 'accept: application/json' -H 'content-type: application/json' --data '{}'

The catalog declares POST. A 402 answer carries the payment requirements in the JSON body and, for x402 v2, base64 in the PAYMENT-REQUIRED header. This page never sends a payment.

Paid checks (x402, USDC on Base)

GET https://bazaar.agentexchange.work/r/b310afdd715e/probe.json re-runs this probe right now for $0.01 and writes the result here. POST https://bazaar.agentexchange.work/featured with {"id":"b310afdd715e"} places this resource at the top of the report and search pages for 30 days for $1.00, labelled. Unpaid requests answer 402 with the terms. Pricing.

Catalog references: agentic.market (CDP Bazaar front end) · this record as JSON · all resources on api.agentstools.dev.