{"uid":"cap_9L0t9C7S-gxmyPlvQIxBf","slug":"delx-commerce-csp-policy-audit-0c7f0365","name":"Delx Commerce CSP Policy Audit","description":"Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.","url":"https://commerce.delx.ai/api/v1/x402/csp-policy-audit?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"policy":{"type":"string","maxLength":100000}}},"responseSchema":{"type":"json","example":{"risk":"low","schema":"delx/csp-policy-audit/v1","findings":[],"directives":["default-src","script-src"],"directive_count":2}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.002","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.002/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_F65TTgtGtllRUroHvuwNY","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.002","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Audits a Content Security Policy (CSP) header string and returns a risk rating, detected directives, and security findings.","exampleAgentPrompt":"Can you audit this CSP policy for security risks and tell me which directives it has and whether there are any findings: \"default-src 'self'; script-src 'self' 'unsafe-inline' https://cdn.example.com; img-src *\"?","exampleUseCases":[{"title":"Pre-deployment CSP security check","prompt":"Before I deploy my new site, can you audit this Content Security Policy header and tell me the risk level and any findings: \"default-src 'none'; script-src 'self'; connect-src 'self'; img-src 'self' data:; style-src 'self' 'unsafe-inline'\"?"},{"title":"Detecting unsafe CSP in CI pipeline","prompt":"I'm running a security check on my app's CSP — can you analyze this policy string \"script-src * 'unsafe-eval' 'unsafe-inline'; object-src *\" and flag any high-risk directives or misconfigurations?"},{"title":"Comparing CSP strictness after refactor","prompt":"My team just updated our Content Security Policy. Can you audit this new version and tell me the risk rating and full list of directives it sets: \"default-src 'self'; script-src 'self' https://apis.google.com; frame-ancestors 'none'\"?"}],"resultDescription":"Returns a JSON object with a risk level ('low', 'medium', 'high'), a schema identifier, a list of findings (security issues or warnings), a list of directive names parsed from the policy, and a count of those directives.","failureModes":["Policy string exceeds 100,000 character limit — request rejected","Malformed or empty policy string — may return empty directives and no findings","Payment failure via x402 — 402 response, call not processed","Network timeout — no result returned"],"whenToPreferThis":"Choose this endpoint when you need a fast, pay-per-call, no-signup CSP audit that returns structured JSON including risk rating, parsed directives, and findings — especially in agent workflows where you want verifiable, per-call pricing in USDC rather than a subscription-based security scanner.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-01T00:54:05.708Z","isFirstParty":false,"canonicalSlug":"delx-commerce-csp-policy-audit-0c7f0365"}