{"uid":"cap_LxXcTooOkpmkaDBCbITcL","slug":"delx-cache-policy-audit-f2fe009e","name":"Delx Cache Policy Audit","description":"Audit cache headers for missing policy and sensitive public-cache exposure. Use it before an autonomous workflow acts on untrusted input, changes an API, retries a request, or evaluates production reliability. Returns bounded machine-readable JSON for $0.002 USDC via x402 on Base. Execution is deterministic, first-party, local-only, stateless, and does not call an upstream provider; structured validation failures are not billed.","url":"https://api.delx.ai/api/v1/x402/cache-policy-audit","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"headers":{"type":"object","additionalProperties":{"type":"string"}}}},"responseSchema":{"type":"json","example":{"risk":"review","schema":"delx/cache-policy-audit/v1","findings":["cache_control_missing"],"etag_present":false,"vary_present":false,"cache_control":null}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.002","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.002/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_cqBdTq8VoW1YNYcz2sBSX","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.002","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Audits HTTP cache headers to detect missing cache policies and sensitive data exposed via public caching","exampleAgentPrompt":"Can you audit these HTTP response headers for missing cache policies or any sensitive data that might be exposed through public caching? Headers: Cache-Control: public, max-age=3600 and no Pragma or Vary set.","exampleUseCases":[{"title":"Pre-deployment cache security check","prompt":"Before I push this API change to production, audit these response headers for any cache misconfigurations or sensitive data that could end up publicly cached: Cache-Control: no-store, Pragma: no-cache, Expires: 0 — are there any gaps?"},{"title":"Autonomous agent preflight validation","prompt":"My agent is about to act on an API response — can you first check these headers to make sure there's a valid cache policy and nothing sensitive is being exposed via public cache? Here are the headers: Cache-Control: public, Authorization: Bearer xyz."},{"title":"CDN reliability audit before retry","prompt":"I'm seeing inconsistent responses from my CDN and want to know if my cache headers are misconfigured. Can you audit these headers and tell me if any are missing a policy or dangerously set to public: Cache-Control: max-age=86400, Vary: Accept-Encoding?"}],"resultDescription":"A bounded machine-readable JSON object identifying missing cache policies, misconfigured directives, and instances of sensitive data exposed via public-cache headers, along with structured validation findings per header field.","failureModes":["Malformed input headers object returns a structured validation error without billing","Missing required 'headers' field returns a validation failure","Unrecognized header names are ignored rather than flagged as errors","Empty headers object may return no findings rather than an error"],"whenToPreferThis":"Choose this endpoint when you need a fast, deterministic, stateless audit of HTTP cache headers specifically for missing policies and public-cache exposure risks — especially as a preflight check in an autonomous agent workflow before acting on untrusted API responses or deploying changes. It is local-only with no upstream provider calls, making it suitable for security-sensitive pipelines. Prefer it over general HTTP header validators when the specific concern is cache policy completeness and sensitive data leakage through caching.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T19:02:18.536Z","isFirstParty":false}