Agent Exchange x402 census and directory

x402 census · toolcall.click · ff0fbda5f6a5 · JSON

GET /t/package/check

unprobed

Is this dependency safe to use? Pass a package name (npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet) and optional version: returns known vulnerabilities (OSV/CVE with CVSS and fixed-in version), deprecation status, license, latest version, repo health (stars, OpenSSF Scorecard) and an overall ok/caution/avoid verdict. JSON response. $0.01 USDC per call, pay via x402, no API key.

Verdict: not verified by an unpaid GET. not probed yet. This says nothing about whether the route works when called as declared.

Facts from the catalogs

FieldValue
URLhttps://toolcall.click/t/package/check
MethodGET
Price$0.01 USDC = 10000 atomic units of 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Networkeip155:8453 (base)
payTo0x84FA7Ea8303d4f503267e2e998A3F7D980e814a5
Sellertoolcall.click
Catalogscdp (row updated 2026-09-29)
Listed since (lower bound)2026-09-29 (earliest catalog timestamp; catalogs report last-update times only)
Last catalog update2026-09-29
CDP quality counters2 calls and 2 unique payers in 30 days, last call 2026-09-29 (catalog-reported, not verified on chain)
Category (keyword rule)trading-signals
Templated pathno
x402Version in catalog2
Service name / tagsToolsmith · dependency security, npm, pypi, cve, vulnerabilities

Unpaid probe (census of )

FieldValue
Probenot probed in this build

No hourly re-probe has reached this resource yet; the cron covers a rotating slice of 150 per hour.

On-chain facts for the payTo (public address)

FieldValue
Distinct payers10
Payments21
USDC volume$0.13
Median payment$0.002
First / last payment2026-07-26 / 2026-09-28
Sampler-shaped share of payments100.0%
Payers that are not samplers0
Sourceforensics-2026-09-30
Address0x84FA7Ea8303d4f503267e2e998A3F7D980e814a5

Declared input and output (extensions.bazaar)

{
 "input": {
  "method": "GET",
  "queryParams": {
   "eco": "npm",
   "name": "express",
   "version": "4.16.0"
  },
  "type": "http"
 },
 "output": {
  "type": "json",
  "example": {
   "latestVersion": "5.2.1",
   "package": "express",
   "project": {
    "scorecard": 6.8,
    "stars": 65000
   },
   "verdict": "caution",
   "version": "4.16.0",
   "vulnerabilities": [
    {
     "cve": "CVE-2024-...",
     "cvss": 6.1,
     "fixedIn": "4.19.2",
     "id": "GHSA-..."
    }
   ]
  }
 }
}

Try it (unpaid: shows the 402)

curl -si -X GET 'https://toolcall.click/t/package/check' -H 'accept: application/json'

The catalog declares GET. A 402 answer carries the payment requirements in the JSON body and, for x402 v2, base64 in the PAYMENT-REQUIRED header. This page never sends a payment.

Paid checks (x402, USDC on Base)

GET https://bazaar.agentexchange.work/r/ff0fbda5f6a5/probe.json re-runs this probe right now for $0.01 and writes the result here. POST https://bazaar.agentexchange.work/featured with {"id":"ff0fbda5f6a5"} places this resource at the top of the report and search pages for 30 days for $1.00, labelled. Unpaid requests answer 402 with the terms. Pricing.

Catalog references: agentic.market (CDP Bazaar front end) · this record as JSON · all resources on toolcall.click.