{"uid":"cap_e8VlzzvgPC_gsG8_VD3jK","slug":"concierge-agent-security-headers-checker-a5b4d23e","name":"Concierge Agent — Security Headers Checker","description":"Passive HTTP security header review for an authorized external target (no exploitation; platform hosts blocked)","url":"https://conc-exe.xyz/api/concierge-security-headers","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"target":{"type":"string","description":"Authorized external https origin (never conc-exe.xyz)"},"allowlist":{"type":"array","items":{"type":"string"},"description":"Optional hostname allowlist"},"authorized":{"type":"boolean","description":"Must be true — caller attests permission"}}},"responseSchema":{"type":"json","example":{"ok":true,"kind":"security-headers","checks":[{"id":"x-content-type-options","header":"x-content-type-options","present":true}],"target":{"origin":"https://app.example.com","hostname":"app.example.com"},"summary":{"grade":"moderate","total":6,"present":4},"disclaimer":"Passive header review only."}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_8wGA9qmd-KJt_z2CBERCz","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Passively audits the HTTP security headers of an external HTTPS origin and returns a graded summary of which headers are present or missing.","exampleAgentPrompt":"Can you audit the security headers on https://app.example.com and tell me which headers are present or missing, plus the overall security grade? I have permission to check this site.","exampleUseCases":null,"resultDescription":"Returns a JSON object with a list of individual header checks (each with ID, header name, and presence boolean), the target origin and hostname, an overall grade (e.g. 'moderate'), counts of total vs. present headers, and a disclaimer noting the review is passive only.","failureModes":["Missing or false 'authorized' field causes rejection — caller must attest permission","Target URL pointing to conc-exe.xyz itself is blocked by design","Invalid or non-HTTPS target origin returns an error","Hostname not on allowlist (if allowlist provided) is rejected","Target site unreachable or times out returns an error response"],"whenToPreferThis":"Use this endpoint when you need a quick, passive, pay-per-call security header audit on an external HTTPS origin without setting up a dedicated scanning tool. Ideal for AI agents performing automated security checks on web properties where the caller can attest authorization.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T12:51:57.114Z","isFirstParty":false}