skill-audit

active

Detect malicious patterns in AI agent skills/plugins. x402 v2 micropayments on Base.

Transactions · 30d
0
Volume · 30d
$0.00
Unique buyers · 30d
0
Uptime · 30d
100.0%
Latency p50
17ms
Reported calls · 30d
27

Endpoints (43 live)

  • POST /audit/registry — Scan the newest servers in the official MCP registry for supply-chain risk — no input required (0.005 USDC on Base)
  • POST /read — Fetch a URL and return its main content as clean Markdown (boilerplate stripped) (0.005 USDC on Base)
  • POST /crawl — Crawl a site from a start URL (same-domain, breadth-first) and return each page as clean Markdown (0.02 USDC on Base)
  • POST /read/batch — Fetch up to 10 URLs concurrently and return each as clean Markdown (bulk rate) (0.02 USDC on Base)
  • POST /trust — Vet an x402 server or any URL for scam/phishing/trust in ONE call: transport, content-safety, domain, metadata + x402-compliance sub-scores, each with transparent evidence (0.02 USDC on Base)
  • POST /audit/url — Fetch a URL and audit its content. Requires `url`. No URL to hand? POST /audit/registry runs the same scanner over the newest servers in the official MCP registry: no input required, $0.005. (0.005 USDC on Base)
  • POST /rss — Parse an RSS/Atom feed into structured items (title, link, published, summary) — or auto-discover the feed from a site URL (0.005 USDC on Base)
  • POST /audit/repo — Scan an entire public GitHub repo for malicious AI-skill/supply-chain patterns. Requires `repo`. No repo in mind? POST /audit/registry runs this same scanner over the newest servers in the official MCP registry: no input required, $0.005. (0.005 USDC on Base)
  • POST /sitemap — Enumerate a site's URLs from robots.txt + sitemap.xml (sitemap-index aware) — map a domain before crawling it (0.005 USDC on Base)
  • POST /extract — Extract structured metadata from a page: title, description, OpenGraph, JSON-LD, headings, links (0.008 USDC on Base)
  • POST /pdf — Fetch a PDF by URL and return its text as Markdown-ish plain text, page by page (0.01 USDC on Base)
  • POST /audit — Audit text for malicious AI-skill patterns. Requires `content`. Nothing to audit — crawling, or discovering this endpoint cold? POST /audit/registry runs the same scanner over the newest servers in the official MCP registry: no input required, $0.005. (0.005 USDC on Base)
  • POST /dns — Resolve a domain's DNS records (A/AAAA/MX/NS/TXT/CNAME) and flag basic email/security posture (0.006 USDC on Base)
  • POST /headers — Fetch a URL and grade its HTTP security headers (HSTS, CSP, X-Frame-Options, etc.) (0.005 USDC on Base)
  • POST /llm/chat — Run a chat completion against an open-weight 20B-class model — plain prompt in, text out, with automatic failover across independent inference backends so a single call still answers when any one provider is down or rate-limiting (0.02 USDC on Base)
  • POST /okx/read (free)
  • POST /world/earthquakes — Which earthquakes have just happened? Recent USGS events worldwide or within a radius of a named place, with magnitude, depth, tsunami flag and felt reports (0.01 USDC on Base)
  • POST /world/elevation — How high above sea level is this point? Ground elevation in metres for a place name or a coordinate pair (0.01 USDC on Base)
  • POST /world/airquality — How breathable is the air in this place right now? Current PM2.5, PM10, ozone, NO2, SO2, CO and dust plus both the US and European AQI, and the US AQI band ('Good', 'Unhealthy') so the number is directly actionable. Takes a place name, not coordinates (0.01 USDC on Base)
  • POST /world/indicators — What are this country's headline economics? World Bank time series for GDP, GDP per capita, population, inflation, unemployment, life expectancy, CO2 per capita or internet penetration, by plain-English alias or raw indicator code (0.01 USDC on Base)

+23 more endpoints.

MCP tools (11)

skill-audit https://eltociear-skill-audit.hf.space/mcp

  • air_quality — Current air quality for a place: PM2.5, PM10, ozone, NO2, SO2, CO and dust, plus the US and European AQI and the US AQI band ('Good', 'Unhealthy'). Takes a place name — no coordinates needed. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
  • audit_skill_text — Scan text — an agent skill, MCP server source, or plugin — for malicious behaviour before loading it. 17 attack patterns / 65 regex signatures across 4 severity levels — credential exfiltration, download-and-execute, prompt injection, command execution, seed-phrase harvesting and more.
  • audit_skill_url — Fetch a URL and scan what it serves for malicious behaviour. 17 attack patterns / 65 regex signatures across 4 severity levels — credential exfiltration, download-and-execute, prompt injection, command execution, seed-phrase harvesting and more.
  • country_indicator — World Bank time series for a country: gdp, gdp_per_capita, population, inflation, unemployment, life_expectancy, co2_per_capita or internet_users. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
  • earthquakes — Recent earthquakes from the USGS feed — worldwide, or within a radius of a named place. Returns magnitude, depth, tsunami flag and felt reports. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
  • elevation — Ground elevation in metres for a place name. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
  • geocode — Resolve a place name to coordinates, country, admin region, timezone, elevation and population. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
  • paid_catalogue — List the paid API routes this same server offers, with prices and which ones need no input. The MCP tools here are free and general-purpose; the paid routes are specialised (on-chain token safety, live DEX prices, wallet intel, supply-chain scans). Payment is x402 over USDC on Base — no account or API key. Takes no arguments.
  • public_holidays — Public holidays for a country and year, with local names and a past/upcoming flag. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
  • read_url — Fetch a URL and return its main content as clean Markdown, boilerplate stripped. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)
  • web_search — Search the live web and return ranked title/url/snippet results, through an automatic multi-engine failover chain. (Free. This server also sells a paid API — call `paid_catalogue` for the routes and prices; x402 over USDC on Base, no signup.)

First seen · last seen