80trust / 100
Decode
by TxSim Decoder in Security & trust
x402 APIPassing, checked 4 h ago
Decode raw EVM calldata into a named function, signature and arguments, plus security risk flags (unlimited token approval, setApprovalForAll, ownership transfer, unknown selector, native value transfer). Keyless, deterministic, no simulation - the cheap way for an agent to understand and risk-screen a piece of calldata before signing.
GET https://simulate.cyberwarex.com/decode
Last 30 days
All checks passedSome failedAll failedNot checked
- Uptime
- 100%
- Response time
- 483 ms typical, 483 ms slowest 5%
- Last check
- 4 h ago
- Next check
- any minute now
How to call it
# See the payment challenge (nothing is charged)
curl -i -X GET "https://simulate.cyberwarex.com/decode?data=0x095ea7b3000000000000000000000000d8da6bf26964af9d7eed9e03e53415d37aa96045ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";
const client = new x402Client().register(
"eip155:8453",
new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)),
);
const pay = wrapFetchWithPayment(fetch, client);
// Not sure it's safe to pay? Preflight it first for $0.005:
// GET https://toolvet.app/api/v1/check?url=https%3A%2F%2Fsimulate.cyberwarex.com%2Fdecode
const res = await pay("https://simulate.cyberwarex.com/decode?data=0x095ea7b3000000000000000000000000d8da6bf26964af9d7eed9e03e53415d37aa96045ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff");
console.log(await res.json());Example input
{
"data": "0x095ea7b3000000000000000000000000d8da6bf26964af9d7eed9e03e53415d37aa96045ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff"
}Example output
{
"decoded": {
"args": {
"amount": "115792089237316195423570985008687907853269984665640564039457584007913129639935",
"spender": "0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045"
},
"function": "approve",
"signature": "approve(address,uint256)"
},
"disclaimer": "Static decode + keyless eth_call preview only. This is not financial advice and not a guarantee: a call that would succeed now can still revert at broadcast time (state changes, slippage, MEV). Always verify before signing.",
"risk": {
"flags": [
{
"code": "unlimited_approval",
"detail": "approval amount is effectively unlimited",
"severity": "danger"
}
],
"level": "danger"
}
}Security scan
- No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.
Recent checks
| When | Result | HTTP | Time | Price |
|---|---|---|---|---|
| 4 h ago | Passed | 402 | 483 ms | $0.002 |