81trust / 100
Contract Flags
by Token rug check: contract risk in Onchain & crypto
x402 APIPassing, checked 52 min ago
Smart contract risk check (Base, Arc): can the owner mint, pause, blacklist, change fees or upgrade the code? What can the people behind this contract do to holders? Pass ?chain=base|arc&address=0x... and we read its bytecode on chain (and the code behind a proxy): mint, pause, blacklist, change fees or taxes, cap wallets, switch trading off, upgrade the code. Plus proxy type, who owns it now (renounced or a live wallet or contract) and basic token data.
GET https://apexfaucet.xyz/api/x402/contract-flags
Last 30 days
All checks passedSome failedAll failedNot checked
- Uptime
- 100%
- Response time
- 75 ms typical, 75 ms slowest 5%
- Last check
- 52 min ago
- Next check
- any minute now
How to call it
# See the payment challenge (nothing is charged)
curl -i -X GET "https://apexfaucet.xyz/api/x402/contract-flags?address=0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913&chain=base"import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";
const client = new x402Client().register(
"eip155:8453",
new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)),
);
const pay = wrapFetchWithPayment(fetch, client);
// Not sure it's safe to pay? Preflight it first for $0.005:
// GET https://toolvet.app/api/v1/check?url=https%3A%2F%2Fapexfaucet.xyz%2Fapi%2Fx402%2Fcontract-flags
const res = await pay("https://apexfaucet.xyz/api/x402/contract-flags?address=0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913&chain=base");
console.log(await res.json());Example input
{
"address": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"chain": "base"
}Example output
{
"data": {
"address": "0x833589fCD6eDb6E08f4c7C…",
"bytecodeBytes": 1852,
"chain": "base",
"explorer": "https://basescan.org/add…",
"flags": [],
"how": "bytecode read on chain (…",
"isContract": true,
"ok": true,
"owner": {},
"proxy": {},
"token": {},
"verdict": "PRIVILEGED POWERS IN THE…"
},
"ok": true,
"paid": 0.004
}Security scan
- No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.
Recent checks
| When | Result | HTTP | Time | Price |
|---|---|---|---|---|
| 52 min ago | Passed | 402 | 75 ms | $0.004 |
| 6 h ago | Passed | 402 | 151 ms | $0.004 |