{"uid":"cap_G3IDowJnehjX1w2VXrRn0","slug":"connskill-exposure-check-domain-breach-infostealer-intelligence-4c04e275","name":"CONNSKILL Exposure Check — Domain Breach & Infostealer Intelligence","description":"Market data and real-world actions for AI agents: keyword and SERP research by location, SMS verification, receive-only inboxes, social marketing, EU-hosted LLMs. Paid per call in USDC on Base. No account, no API key, no minimum.","url":"https://agent.connskill.com/v1/exposure-check","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"domain":{"type":"string","minLength":4,"description":"Domain to check, e.g. example.com (no e-mail addresses, no paths)"}}},"responseSchema":{"type":"json","example":{"leaks":{"found":62,"sources":[{"date":null,"name":"Stealer Logs"}]},"domain":"adobe.com","status":"delivered","verdict":{"level":"high","reasons":["1561 employee device(s) seen in infostealer logs"]},"breaches":[{"date":"2013-10-04","name":"Adobe","accounts":152445165}],"infostealer":{"users":2365419,"employees":1561,"thirdParties":518,"stealerFamilies":[{"count":900000,"family":"Lumma"}],"lastEmployeeCompromised":"2026-08-22T00:25:20.000Z"},"sourcesFailed":[]}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.03","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.03/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_2G4qo3oWnaYXi8V6fQDJb","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.03","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks a domain for known data breaches and infostealer log exposure, returning employee and user compromise counts, stealer families, and a risk verdict.","exampleAgentPrompt":"Can you check if shopify.com has been exposed in any data breaches or infostealer logs — I need to know how many employees or users are compromised and what the overall risk level is?","exampleUseCases":[{"title":"Pre-partnership vendor security vetting","prompt":"Before we sign with this vendor, can you run an exposure check on their domain acmecorp.com and tell me if any of their employee devices have shown up in infostealer logs, and what the risk verdict is?"},{"title":"Responding to a credential stuffing alert","prompt":"We're seeing suspicious login attempts — can you check if databricks.com has had any recent employee compromises in infostealer logs, and how many accounts from their domain have leaked?"},{"title":"Routine corporate security audit","prompt":"Run a breach and infostealer exposure check on our company domain techstartup.io — I want to know about any known breaches, how many of our users or employees are in stealer logs, and what families of malware were involved."}],"resultDescription":"Returns a JSON object with: total leak count and sources (e.g. Stealer Logs), list of named data breaches with dates and account counts, infostealer statistics (total users, employees, and third parties compromised, malware families and their counts, date of last employee compromise), and a risk verdict with a severity level (e.g. 'high') and human-readable reasons explaining the assessment.","failureModes":["Domain too short or invalid format — minimum 4 characters required, no email addresses or URL paths accepted","Domain not found in any breach or stealer database — returns empty breaches and zero infostealer counts","Upstream data source failure — partial results with failed sources listed in 'sourcesFailed' array","Payment not processed — x402 payment required before response is delivered","Rate limiting or network timeout from underlying threat intelligence provider"],"whenToPreferThis":"Choose this endpoint when you need a combined view of both traditional data breaches AND infostealer/stealer log exposure for a domain in a single call, without needing an API key or account. Ideal for on-demand security checks in agent workflows where pay-per-use pricing is preferred over subscription threat intelligence platforms. Particularly useful when employee-level compromise detail (device counts, stealer family breakdown, recency of compromise) matters alongside historical breach data.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T00:32:26.910Z","isFirstParty":false}