{"uid":"cap_DCaLmRbSnVk3N4Ezg5YlX","slug":"agent-auditor-e94608ed","name":"Agent Auditor","description":"Due-diligence audit of any x402/MPP merchant origin on behalf of a paying agent: probes /api/discovery + service catalog, does an unpaid GET on a paid service to capture its real 402 PAYMENT-REQUIRED challenge (x402 version, resource, price), checks the free meta contract, records security headers, and cross-checks registration on x402scan, PayAI discovery and ScoutScore. SSRF-guarded; only public http(s) origins.","url":"https://k2so.wrong.systems/api/services/agent-auditor","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"type":"object","properties":{"meta":{"enum":["0","1"],"type":"string","description":"Set to 1 for free metadata JSON (no payment required)"},"origin":{"type":"string","description":"Composite input parameter"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object","title":"Agent Auditor paid response","$schema":"https://json-schema.org/draft/2020-12/schema","required":["ok","paid","service","provider","result"],"properties":{"ok":{"type":"boolean"},"paid":{"type":"boolean"},"result":{"type":"object","required":["ok","service"],"properties":{"ok":{"type":"boolean","description":"Handler success"},"score":{"type":"number"},"service":{"type":"string","description":"Service slug"},"summary":{"type":"string"},"evidence":{"type":"object"},"strengths":{"type":"array","items":{"type":"string"}},"confidence":{"type":"string"},"generatedAt":{"type":"string","description":"ISO-8601 timestamp"},"riskFactors":{"type":"array","items":{"type":"string"}}}},"payment":{"type":"object","properties":{"code":{"type":"string"},"payer":{"type":"string"},"detail":{"type":"string"},"selfPay":{"type":"boolean"},"transaction":{"type":"string"}}},"service":{"type":"string"},"provider":{"type":"string","const":"K-2SO"}}}}}}},"responseSchema":{"type":"json","example":{"ok":true,"paid":true,"result":{"ok":true,"service":"agent-auditor"},"service":"agent-auditor","provider":"K-2SO"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_UXMKd5TDGmtZN1_e_jPTV","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Performs a due-diligence audit of an x402/MPP merchant origin, probing its service catalog, capturing real 402 challenge details, checking security headers, and cross-referencing on x402scan, PayAI, and ScoutScore.","exampleAgentPrompt":"Can you run a full due-diligence audit on the x402 merchant at https://example.com using a GET probe and tell me its trust score, any risk factors, and whether it's registered on x402scan and PayAI?","exampleUseCases":[{"title":"Vetting a new x402 merchant before payment","prompt":"Before I route any funds, can you audit the x402 merchant at https://api.someservice.io and give me its score, strengths, and any risk factors I should know about?"},{"title":"Checking 402 challenge legitimacy","prompt":"I want to verify that the 402 PAYMENT-REQUIRED challenge from https://payments.merchantdomain.com is legitimate — can you probe it and show me the real x402 version, resource, and price it's demanding?"},{"title":"Security header and registration cross-check","prompt":"Can you check whether https://marketplace.agentprovider.net is properly registered on x402scan and PayAI discovery, and also report its security headers so I know if it's safe to transact with?"}],"resultDescription":"Returns a structured audit report including: an overall boolean success flag, a numeric score, a natural-language summary, arrays of strengths and risk factors, a confidence rating, a timestamp, and an evidence object containing raw findings from the 402 challenge probe, meta contract check, security header scan, and cross-registration checks on x402scan, PayAI, and ScoutScore.","failureModes":["SSRF guard blocks private/internal IP origins — only public http(s) URLs accepted","Origin unreachable or times out — network error returned","Discovery endpoint (/api/discovery) absent — partial audit with reduced score","402 challenge missing or malformed — evidence recorded but challenge fields empty","x402scan or PayAI lookup failures — partial results with missing cross-check data"],"whenToPreferThis":"Choose this endpoint when an AI agent needs to vet an unknown x402/MPP merchant before authorizing payment — particularly when cross-checking registration across x402scan and PayAI discovery, inspecting real 402 challenge parameters, or assessing security headers is required. Prefer it over manual probing when a structured risk score and evidence bundle are needed for automated payment-gating decisions.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T11:26:43.188Z","isFirstParty":false}