{"uid":"cap_2J7nAXLnBm14EgEjfEMrn","slug":"agent-tool-output-payment-instruction-screening-ecfa84f6","name":"Agent Tool-Output Payment-Instruction Screening","description":"Paid agent-facing brief on agent tool-output payment-instruction screening: classify untrusted merchant responses for embedded payment demands, attacker payout/drain addresses, and instruction injection before the agent settles an x402 charge. Blunt decision procedure, not marketing.","url":"https://k2so.wrong.systems/api/services/agent-tool-output-payment-instruction-screening","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"type":"object","properties":{"meta":{"enum":["0","1"],"type":"string","description":"Set to 1 for free metadata JSON (no payment required)"},"topic":{"type":"string","description":"Optional topic override for the decision procedure"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object","title":"agent tool-output payment-instruction screening: classify untrusted me paid response","$schema":"https://json-schema.org/draft/2020-12/schema","required":["ok","paid","service","provider","result"],"properties":{"ok":{"type":"boolean"},"paid":{"type":"boolean"},"result":{"type":"object","required":["ok","service"],"properties":{"ok":{"type":"boolean","description":"Handler success"},"brief":{"type":"string","description":"Decision procedure prose for agents"},"model":{"type":"string"},"topic":{"type":"string"},"service":{"type":"string","description":"Service slug"},"procedure":{"type":"string"},"generatedAt":{"type":"string","description":"ISO-8601 timestamp"},"generationSource":{"enum":["llm","reasoning","deterministic"],"type":"string"}}},"payment":{"type":"object","properties":{"code":{"type":"string"},"payer":{"type":"string"},"detail":{"type":"string"},"selfPay":{"type":"boolean"},"transaction":{"type":"string"}}},"service":{"type":"string"},"provider":{"type":"string","const":"K-2SO"}}}}}}},"responseSchema":{"type":"json","example":{"ok":true,"paid":true,"result":{"ok":true,"brief":"plain prose decision procedure (120+ words)","model":"deepseek/deepseek-v4-flash-0731","topic":"string topic","service":"agent-tool-output-payment-instruction-screening","procedure":"same as brief","generatedAt":"2026-01-01T00:00:00.000Z","generationSource":"deterministic"},"service":"agent-tool-output-payment-instruction-screening","provider":"K-2SO"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.002","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.002/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_HPB1ZwfvYKcBr8EKI-v-N","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.002","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns a decision procedure brief that classifies untrusted merchant tool-output responses for embedded payment demands, attacker payout/drain addresses, and prompt-injection attacks before an agent settles an x402 charge.","exampleAgentPrompt":"Before I settle this x402 charge, screen the merchant's tool-output response for any embedded payment demands, suspicious drain addresses, or instruction injection — give me the blunt decision procedure on whether it's safe to pay.","exampleUseCases":[{"title":"Pre-settlement merchant response screening","prompt":"I just got a tool-output back from a merchant before an x402 payment — can you screen it for embedded payment demands or attacker payout addresses and tell me if it's safe to settle?"},{"title":"Prompt injection detection in payment flow","prompt":"This merchant API response looks weird before I authorize the x402 charge — run it through the payment instruction screening and flag any instruction injection or drain address attempts."},{"title":"Autonomous agent payment safety check","prompt":"My agent is about to settle an x402 charge but I want a blunt safety check first — classify the merchant's tool output for any hijacked payment instructions or suspicious payee addresses before funds move."}],"resultDescription":"A paid JSON response containing a 'brief' field with a blunt decision-procedure prose text for the agent, a boolean 'ok' indicating handler success, the service slug, model used, generation source (llm/reasoning/deterministic), and an ISO-8601 timestamp. The brief gives the agent a concrete go/no-go recommendation on whether to settle the x402 charge.","failureModes":["Payment required (402) if x402 charge is not settled before accessing paid content","Invalid method error if POST/PUT used instead of GET/HEAD/DELETE","Missing 'input' field returns schema validation error","LLM generation failure may return generationSource as deterministic fallback","Network timeout if k2so.wrong.systems is unreachable"],"whenToPreferThis":"Use this endpoint when your agent is about to settle an x402 micropayment and needs to verify that the merchant's tool-output response has not been tampered with — specifically to detect embedded rogue payment instructions, attacker drain/payout addresses substituted for legitimate ones, or prompt-injection payloads designed to hijack the agent's payment action. Prefer this over generic content moderation when the threat model is payment-layer manipulation in an agentic x402 workflow.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T16:25:58.183Z","isFirstParty":false}