{"uid":"cap_bFngr8Q3dWPaYPt0XDLO4","slug":"skill-audit-api-ai-agent-plugin-trust-scorer-1d1810e0","name":"skill-audit API – AI Agent Plugin Trust Scorer","description":"Vet an x402 server or any URL for scam/phishing/trust in ONE call: transport, content-safety, domain, metadata + x402-compliance sub-scores, each with transparent evidence","url":"https://eltociear-skill-audit.hf.space/trust","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"url":{"type":"string","format":"uri","description":"x402 server or URL to vet before trusting/paying it"},"check_x402":{"type":"boolean","description":"Probe for a valid x402 402 challenge (default true)"}}},"responseSchema":{"type":"json","example":{"url":"https://some-x402-api.example.com","x402":{"asset":"USDC","pay_to":"0x…","is_x402":true,"network":"eip155:8453","valid_challenge":true},"is_scam":false,"verdict":"Reachable HTTPS endpoint with strong headers, valid x402 challenge, no malicious patterns.","evidence":{"spf":true,"dmarc":true,"latency_ms":210,"missing_headers":["content-security-policy"],"malicious_findings":0},"risk_level":"low","sub_scores":{"x402":100,"domain":70,"metadata":80,"transport":90,"content_safety":100},"trust_score":82}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_VJcUHE00uQZkbgms4ce4H","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Analyzes a given AI agent skill or plugin URL for malicious patterns, x402 payment validity, domain health, and content safety, returning a composite trust score and verdict.","exampleAgentPrompt":"Can you audit this AI plugin URL for me — https://some-tool.example.com — and tell me if it's safe to use, what its trust score is, and whether it has any malicious patterns?","exampleUseCases":[{"title":"Vetting a new agent skill before install","prompt":"Before I add this plugin at https://new-skill.example.com to my AI agent, can you run a trust audit on it and tell me the risk level and any red flags?"},{"title":"Checking an x402 API for payment scams","prompt":"I found this x402 API at https://micropay-api.example.com that wants me to pay in USDC — can you verify it's legit, check if the payment challenge is valid, and give me a trust score?"},{"title":"Comparing safety of two agent tools","prompt":"I'm deciding between two agent plugins. Can you audit https://plugin-a.example.com and tell me its trust score, sub-scores, and whether it has any malicious findings so I can decide if it's worth trusting?"}],"resultDescription":"Returns a JSON object containing: a boolean is_scam flag, a human-readable verdict string, an overall trust_score (0–100), a risk_level (low/medium/high), sub-scores for x402 validity, domain, metadata, transport, and content safety, plus evidence details including SPF/DMARC status, latency in ms, missing security headers, and malicious findings count.","failureModes":["Unreachable target URL returns error or timeout","Invalid URL format causes 400 Bad Request","Target endpoint blocks audit probe requests, skewing scores","x402 challenge validation fails if endpoint uses non-standard implementation","Hugging Face Space may be cold-started, adding initial latency","Payment via x402 required — missing USDC on Base wallet causes auth failure"],"whenToPreferThis":"Use this endpoint when you need a quick, multi-dimensional safety audit of an AI agent skill or x402-enabled API before allowing an agent to call it. It uniquely combines x402 payment challenge verification, domain reputation signals (SPF, DMARC), transport security, and content safety into a single trust score — making it ideal for agent orchestration pipelines that need to vet tools at runtime. Prefer this over generic URL scanners when the target is specifically an AI plugin or x402 micropayment API.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T12:39:37.242Z","isFirstParty":false}