x402 census · api.agentstools.dev · b310afdd715e · JSON
POST /mcp/scan
method-gated
Static security scan of an MCP manifest or tool list. Detects tool poisoning, hidden unicode instructions, prompt injection, data-exfiltration directives, dangerous capabilities, tool shadowing and post-approval rug-pull drift. Returns a 0-100 risk score, category, per-tool findings and content hashes. Security indicators, not a guarantee.
Verdict: not verified by an unpaid GET. 405/400: the 402 sits behind the declared method. This says nothing about whether the route works when called as declared.
Facts from the catalogs
| Field | Value |
|---|---|
| URL | https://api.agentstools.dev/mcp/scan |
| Method | POST |
| Price | $0.01 USDC = 10000 atomic units of 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 |
| Network | eip155:8453 (base) |
| payTo | 0xF22e558a00D91Ee12A1F50C52186FecB8dDFf493 |
| Seller | api.agentstools.dev |
| Catalogs | cdp (row updated 2026-09-28) |
| Listed since (lower bound) | 2026-09-28 (earliest catalog timestamp; catalogs report last-update times only) |
| Last catalog update | 2026-09-28 |
| CDP quality counters | 2 calls and 2 unique payers in 30 days, last call 2026-09-28 (catalog-reported, not verified on chain) |
| Category (keyword rule) | crypto-data |
| Templated path | no |
| x402Version in catalog | 2 |
| Service name / tags | mcp-scan · mcp, security, tool-poisoning, prompt-injection, scanner |
Unpaid probe (census of 2026-09-30)
| Field | Value |
|---|---|
| Probed at | 2026-09-30T23:59:55.465Z |
| HEAD | 405 |
| GET | 405 |
| Verdict | method-gated 405/400: the 402 sits behind the declared method |
| 402 carried in | n/a |
| x402Version in the 402 | n/a |
| accepts[0] | none |
| Live amount equals catalog price | not comparable |
| Live payTo equals catalog payTo | not comparable |
| extensions.bazaar in the 402 | no |
| PAYMENT-REQUIRED header | no |
| WWW-Authenticate offer | none |
| Content type / server / CORS | application/json / uvicorn / none |
| Latency | 2,576 ms |
| Error | none |
No hourly re-probe has reached this resource yet; the cron covers a rotating slice of 150 per hour.
On-chain facts for the payTo (public address)
| Field | Value |
|---|---|
| Distinct payers | 45 |
| Payments | 314 |
| USDC volume | $2.00 |
| Median payment | $0.003 |
| First / last payment | 2026-07-07 / 2026-09-30 |
| Sampler-shaped share of payments | 98.4% |
| Payers that are not samplers | 1 |
| Source | forensics-2026-09-30 |
| Address | 0xF22e558a00D91Ee12A1F50C52186FecB8dDFf493 |
Declared input and output (extensions.bazaar)
{
"input": {
"body": {
"manifest": {
"tools": [
{
"description": "Get the weather for a city.",
"inputSchema": {
"properties": {
"city": {
"type": "string"
}
},
"type": "object"
},
"name": "get_weather"
}
]
}
},
"bodyType": "json",
"method": "POST",
"type": "http"
},
"output": {
"type": "json",
"example": {
"coverage": {
"dimensions_flagged": [],
"dimensions_total": 8,
"tools_scanned": 1
},
"disclaimer": "Automated security indicators, not a guarantee.",
"findings": [],
"manifest_hash": "sha256:…",
"object": "manifest",
"per_tool": {
"get_weather": {
"category": "clean",
"findings": [],
"score": 0,
"tool_hash": "sha256:…"
}
},
"reasons": [],
"risk_category": "clean",
"risk_score": 0,
"tool_count": 1
}
}
}
Try it (unpaid: shows the 402)
curl -si -X POST 'https://api.agentstools.dev/mcp/scan' -H 'accept: application/json' -H 'content-type: application/json' --data '{}'
The catalog declares POST. A 402 answer carries the payment requirements in the JSON body and, for x402 v2, base64 in the PAYMENT-REQUIRED header. This page never sends a payment.
Paid checks (x402, USDC on Base)
GET https://bazaar.agentexchange.work/r/b310afdd715e/probe.json re-runs this probe right now for $0.01 and writes the result here. POST https://bazaar.agentexchange.work/featured with {"id":"b310afdd715e"} places this resource at the top of the report and search pages for 30 days for $1.00, labelled. Unpaid requests answer 402 with the terms. Pricing.
Catalog references: agentic.market (CDP Bazaar front end) · this record as JSON · all resources on api.agentstools.dev.