{"uid":"cap_iEYU9mctvD_uyt9xideAO","slug":"conc-exe-xyz-unified-passive-security-scan-2b16ef10","name":"conc-exe.xyz Unified Passive Security Scan","description":"Unified passive security breakdown — agent-readiness + HTTP headers + recommendations for an authorized external website (platform hosts blocked)","url":"https://conc-exe.xyz/api/concierge-security-scan","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"target":{"type":"string","description":"Authorized external https URL. For free platform self-audit only, use https://conc-exe.xyz with selfAudit: true; otherwise never conc-exe.xyz."},"allowlist":{"type":"array","items":{"type":"string"},"description":"Hostname allowlist (*.example.com). Optional for selfAudit of conc-exe.xyz."},"selfAudit":{"type":"boolean","description":"When true with target https://conc-exe.xyz (or www), runs free platform self-audit and skips x402 settlement"},"authorized":{"type":"boolean","description":"Must be true — caller attests permission"}}},"responseSchema":{"type":"json","example":{"ok":true,"kind":"security-scan","target":{"origin":"https://api.example.com","hostname":"api.example.com"},"summary":{"headersGrade":"moderate","headersTotal":6,"mcpReachable":false,"overallGrade":"B","readinessMax":3,"discoveryFiles":2,"headersPresent":4,"readinessScore":2.1},"breakdown":{},"disclaimer":"Passive security breakdown only.","recommendations":["Add strict-transport-security — max-age with includeSubDomains on HTTPS"]}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_CWXEqRCivO7uwtaFzEp6W","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.1","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Combines passive agent-readiness audit and HTTP security header review into a single unified security breakdown with recommendations for an authorized external website","exampleAgentPrompt":"Can you run a full passive security scan on https://api.mycompany.com — I'm authorized to test it — and give me the combined agent-readiness audit, HTTP header review, and recommendations? Add api.mycompany.com to the allowlist.","exampleUseCases":null,"resultDescription":"A unified passive security breakdown covering: agent-readiness assessment (OpenAPI discovery, AI-agent discoverability signals, security header compatibility for agents), HTTP security header analysis, and prioritized recommendations — all without active exploitation or intrusive probing.","failureModes":["authorized field is false or missing — request rejected with authorization error","target URL is a conc-exe.xyz hostname — platform hosts are blocked, returns 403 or validation error","target URL is HTTP (not HTTPS) — rejected as invalid","target URL is unreachable or times out — returns connectivity error","target domain not in allowlist if allowlist is specified — returns scope violation error","malformed URL format — returns input validation error"],"whenToPreferThis":"Choose this endpoint when you need both agent-readiness and HTTP header security analysis in a single call rather than calling the two sibling endpoints separately. Ideal when you want a holistic passive security posture report with recommendations for an external site you own or are authorized to test, without active exploitation.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T12:37:58.107Z","isFirstParty":false}