npm Trust Check

active

Paid API endpoints audit MCP server safety and check EVM token contract risks.

Settled via Coinbase.

Transactions · 30d
25
Volume · 30d
$3.65
Unique buyers · 30d
2
Uptime · 30d
100.0%
Latency p50
131ms
Reported calls · 30d
12

Endpoints (6 live)

  • GET /api/x402-doctor — Audits another x402 service for the exact failure modes that cause aggregators (agent-tools.cloud, x402scan, Bazaar) to mark it 'down' or make its 402 challenge unreadable: missing/invalid /.well-known/x402 descriptor, an unpaid request returning 500/404 instead of a clean 402, a malformed or missing payment-required challenge, and drift between the descriptor's advertised terms and the live challenge. Returns a concrete diagnosis and fix for each failing check, not just pass/fail. (1 USDC on Base)
  • GET /api/contract-check — EVM token contract safety check: honeypot detection, mint/blacklist/pausable/self-destruct capability, ownership renouncement, transfer tax, and a real token-impersonation check (does the symbol claim to be USDC/WETH/DAI/cbBTC at the wrong address — the token equivalent of npm typosquatting). (0.05 USDC on Base)
  • GET /api/repo-health — GitHub repo health check / audit / verify: stars, forks, open issues, last commit age, archived status, license. (0.02 USDC on Base)
  • GET /api/domain-check — Domain liveness check / verify / audit: DNS resolution (A/MX/NS/TXT records), whether mail routing exists, HTTP reachability. (0.02 USDC on Base)
  • GET /api/mcp-audit — MCP server safety audit: completes a real initialize+tools/list handshake, then statically scans every tool's name/description/schema for hidden unicode (tool-poisoning), prompt-injection-style phrasing, and tools that quietly combine multiple high-privilege capabilities (network+filesystem+exec+credential access). If a GitHub repo is supplied, folds in a real software-supply-chain signal too. (0.06 USDC on Base)
  • GET /api/trust-check — npm package trust check / risk score / security audit: registry age, weekly downloads, GitHub org/stars, OSV.dev vulnerabilities, typosquat detection. (0.02 USDC on Base)

First seen · last seen · last active