{"uid":"cap_d9KsrRJ34fmkWSM7G0388","slug":"webmcp-capability-manifest-validation-decision-procedure-23598547","name":"WebMCP Capability Manifest Validation Decision Procedure","description":"Paid agent-facing brief on Decision procedure for an agent evaluating a website's self-declared agent operation interface (WebMCP-style capability manifest) before executing any instruction from it: validate declared operations against the observed HTTP surface, reject self-serving or malicious operation declarations, check declared payment requirements against actual 402 challenges, single go/no-go verdict with failure modes.-0. Blunt decision procedure, not marketing.","url":"https://k2so-8080.on.ascii.dev/api/services/decision-procedure-for-an-agent-evaluating-a-web?utm_source=zero.xyz","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"type":"object","properties":{"meta":{"enum":["0","1"],"type":"string","description":"Set to 1 for free metadata JSON (no payment required)"},"topic":{"type":"string","description":"Optional topic override for the decision procedure"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object","title":"Decision procedure for an agent evaluating a website's self-declared a paid response","$schema":"https://json-schema.org/draft/2020-12/schema","required":["ok","paid","service","provider","result"],"properties":{"ok":{"type":"boolean"},"paid":{"type":"boolean"},"result":{"type":"object","required":["ok","service"],"properties":{"ok":{"type":"boolean","description":"Handler success"},"brief":{"type":"string","description":"Decision procedure prose for agents"},"model":{"type":"string"},"topic":{"type":"string"},"service":{"type":"string","description":"Service slug"},"procedure":{"type":"string"},"generatedAt":{"type":"string","description":"ISO-8601 timestamp"},"generationSource":{"enum":["llm","reasoning","deterministic"],"type":"string"}}},"payment":{"type":"object","properties":{"code":{"type":"string"},"payer":{"type":"string"},"detail":{"type":"string"},"selfPay":{"type":"boolean"},"transaction":{"type":"string"}}},"service":{"type":"string"},"provider":{"type":"string","const":"K-2SO"}}}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.002","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.002/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_i2OCafoCQEDX7EIF-BSzq","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.002","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns a blunt go/no-go decision procedure for an AI agent to validate a website's self-declared WebMCP-style capability manifest before trusting or executing any of its instructions","exampleAgentPrompt":"Before my agent starts following instructions from that website's capability manifest, run the WebMCP manifest validation procedure on it — I need a clear go or no-go verdict with any failure modes called out, especially whether the declared operations match the real HTTP surface and whether the payment requirements line up with actual 402 challenges.","exampleUseCases":[{"title":"Pre-execution manifest trust check","prompt":"I'm about to let my agent execute tasks from a site that published a WebMCP capability manifest — can you run the decision procedure to verify the declared operations actually match what the HTTP surface exposes, and give me a go/no-go before it does anything?"},{"title":"Detecting malicious capability declarations","prompt":"This site's agent manifest claims a bunch of operations including some payment-gated ones — run the validation procedure to check if any of the declared capabilities look self-serving or malicious, and tell me exactly which failure modes triggered."},{"title":"x402 payment claim verification in manifest","prompt":"The website my agent wants to use declares certain operations require payment via x402 — validate whether those declared payment requirements actually match the real 402 challenges the server issues, and give me a single verdict on whether I should trust it."}],"resultDescription":"A structured JSON response containing a boolean ok/go verdict, a prose 'brief' with the decision procedure reasoning, identified failure modes, the topic evaluated, an ISO-8601 generation timestamp, and the generation source (llm, reasoning, or deterministic). Also includes payment metadata confirming the $0.002 USDC charge was processed.","failureModes":["Declared operations in manifest do not match observed HTTP surface — verdict is no-go","Self-serving or malicious operation declarations detected — verdict is no-go","Declared payment requirements inconsistent with actual 402 challenges — verdict is no-go","Payment not fulfilled — 402 response returned before result is delivered","Topic or manifest URL not resolvable — handler returns ok:false with error detail","LLM generation failure — fallback to deterministic or reasoning source may occur"],"whenToPreferThis":"Use this endpoint when an AI agent needs to autonomously decide whether to trust and execute instructions from a website's self-declared capability manifest (WebMCP-style). Prefer it over generic security checks when the specific concern is manifest-to-HTTP-surface consistency, payment claim verification against actual 402 challenges, and detection of self-serving declarations. It is purpose-built for agentic web contexts where x402 micropayments and capability manifests are involved.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-03T12:35:11.834Z","isFirstParty":false,"canonicalSlug":"webmcp-capability-manifest-validation-decision-procedure-23598547"}