{"uid":"cap_vCUUc6z8Nz9KU29E7lBom","slug":"delx-xss-signal-scan-32e693be","name":"Delx XSS Signal Scan","description":"Screen untrusted text for common cross-site scripting signals without echoing it. Use it as a bounded preflight or analysis step inside an enterprise agent workflow before data, policy, integration, security, or commercial decisions reach production. Returns deterministic machine-readable JSON for $0.003 USDC via x402 on Base. Execution is first-party, local-only, stateless, memory-only, and has no paid upstream or input retention. Results are advisory; the caller remains responsible for author…","url":"https://api.delx.ai/api/v1/x402/xss-signal-scan","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"text":{"type":"string","description":"Input field: text."}}},"responseSchema":{"type":"json","example":{"risk":"high","schema":"delx/util-xss-signal-scan/v1","advisory":"Heuristic only; use parameterization, contextual encoding, and allowlists.","text_sha256":"5c140d35dcb46a622e2cedf5ef5cc3638cdffd1c118c9331f8c84669f0b74783","signal_count":1,"values_returned":false}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.003","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.003/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_1mia1Xc5EztY7ikhVtuL5","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.003","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Scans untrusted text for cross-site scripting (XSS) signals and returns a deterministic, machine-readable JSON result without echoing or retaining the input.","exampleAgentPrompt":"Before we process this user-submitted comment, scan it for XSS signals: '<script>alert(1)</script> Great product!'","exampleUseCases":[{"title":"Preflight check on user form input","prompt":"Before saving this contact form submission to our database, scan the message field for any XSS signals: 'Hello <img src=x onerror=alert(document.cookie)> I need support.'"},{"title":"Content moderation pipeline gate","prompt":"We're about to publish a user-generated blog comment — screen this text for cross-site scripting patterns before it goes live: '<a href=\"javascript:void(0)\" onclick=\"stealCookies()\">click here</a>'"},{"title":"API integration security audit","prompt":"Our agent is receiving webhook payloads from a third-party — can you scan this payload value for XSS signals before we pass it into our dashboard renderer: '{{userInput: \"<svg onload=fetch('//evil.com')>\"}}' ?"}],"resultDescription":"A deterministic machine-readable JSON object indicating whether XSS signals were detected in the submitted text, along with relevant signal details. The result is advisory and stateless — no input is retained or echoed back. The caller remains responsible for final security decisions.","failureModes":["Empty or missing 'text' field returns a validation error","Oversized input may be rejected with a payload-too-large error","Payment failure via x402 protocol results in a 402 response before scan executes","Network timeout if the endpoint is temporarily unavailable","Ambiguous or edge-case payloads may produce advisory results that require caller-side interpretation"],"whenToPreferThis":"Choose this endpoint when you need a fast, stateless, privacy-preserving preflight XSS signal check inside an agent workflow before data reaches production systems. It is ideal when you cannot afford to echo or retain user input, need deterministic JSON output for downstream logic, and want a lightweight bounded check rather than a full WAF or runtime sanitizer. Prefer it over general-purpose LLM-based security checks when reproducibility and machine-readability of results matter.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T19:01:50.165Z","isFirstParty":false}