{"uid":"cap_Lew7HX4N21ZvTsfN6wthj","slug":"concierge-agent-security-readiness-auditor-b80cfe0e","name":"Concierge Agent — Security Readiness Auditor","description":"Passive agent-readiness audit for an authorized external API — OpenAPI, discovery files, security headers (platform hosts blocked)","url":"https://conc-exe.xyz/api/concierge-security-readiness","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"target":{"type":"string","description":"Authorized external https origin (never conc-exe.xyz)"},"allowlist":{"type":"array","items":{"type":"string"},"description":"Optional hostname allowlist"},"authorized":{"type":"boolean","description":"Must be true — caller attests permission"}}},"responseSchema":{"type":"json","example":{"ok":true,"kind":"security-readiness","scores":{"max":3,"mean":2.1,"dimensions":4},"target":{"origin":"https://api.example.com","hostname":"api.example.com"},"dimensions":[{"id":"spec-presence","name":"OpenAPI spec presence","label":"present","score":2}],"disclaimer":"Passive audit only — no exploitation."}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_EKeB3pJztphQLt-Tytr1Y","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Performs a passive, multi-dimension security readiness audit of an external API origin, scoring it across dimensions like spec presence and returning structured readiness scores.","exampleAgentPrompt":"Can you run a passive security readiness audit on https://api.example.com — I have authorization to scan it — and tell me how it scores across dimensions like OpenAPI spec presence?","exampleUseCases":null,"resultDescription":"A JSON object containing overall scores (max, mean, number of dimensions), the target origin and hostname, a breakdown of individual dimension scores with labels (e.g. spec-presence: 'present', score 2), and a disclaimer confirming this is a passive audit only with no exploitation.","failureModes":["authorized field not set to true — attestation required, request rejected","target origin is not an external HTTPS URL (e.g. conc-exe.xyz itself is not allowed)","unreachable or invalid origin — may return error or degraded scores","missing target field — request body invalid","payment not included or insufficient — 402 response requiring x402 USDC payment"],"whenToPreferThis":"Use this endpoint when you need a structured, passive security readiness assessment of an external HTTPS API origin, especially to check for spec presence and other security hygiene dimensions. Prefer this over manual checks when you need a scored, machine-readable audit report suitable for agent pipelines.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T12:33:34.126Z","isFirstParty":false}