81trust / 100

Discovery

by HALOWERK Agent Tools in Security & trust

x402 APIPassing, checked 4 h ago

Prueft die bekannten Konventionspfade einer Domain auf OpenAPI, MCP, x402, GraphQL, Feeds, llms.txt, security.txt und strukturierte Daten und wertet die Verweise der Startseite mit aus. Liefert je Fund Art, URL, Statuscode und eine Kurzfassung des Inhalts sowie eine Kennzahl fuer die Agententauglichkeit.

POST https://tools.halowerk.com/v1/api/discovery

Last 30 days

All checks passedSome failedAll failedNot checked
Uptime
100%
Response time
147 ms typical, 147 ms slowest 5%
Last check
4 h ago
Next check
any minute now

How to call it

# See the payment challenge (nothing is charged)
curl -i -X POST "https://tools.halowerk.com/v1/api/discovery" \
  -H "content-type: application/json" \
  -d '{"domain":"stripe.com"}'
import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const client = new x402Client().register(
  "eip155:8453",
  new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)),
);
const pay = wrapFetchWithPayment(fetch, client);

// Not sure it's safe to pay? Preflight it first for $0.005:
// GET https://toolvet.app/api/v1/check?url=https%3A%2F%2Ftools.halowerk.com%2Fv1%2Fapi%2Fdiscovery
const res = await pay("https://tools.halowerk.com/v1/api/discovery", {
  method: "POST",
  headers: { "content-type": "application/json" },
  body: JSON.stringify({"domain":"stripe.com"}),
});
console.log(await res.json());

Example input

{
  "domain": "stripe.com"
}

Example output

{
  "agent_readiness_score": 47,
  "base_url": "https://stripe.com",
  "capabilities": {
    "feeds": false,
    "graphql": false,
    "llms_txt": true,
    "machine_readable": true,
    "mcp": false,
    "openapi": true,
    "structured_data": true,
    "x402": false
  },
  "domain": "stripe.com",
  "found_count": 4,
  "homepage": {
    "generator": null,
    "json_ld_types": [
      "Organization"
    ],
    "link_header": null,
    "link_rels": [],
    "payment_header": false,
    "status": 200,
    "title": "Stripe"
  },
  "interfaces": [
    {
      "bytes": 1840233,
      "content_type": "application/json",
      "kind": "openapi",
      "status": 200,
      "summary": {
        "auth_schemes": [
          "bearerAuth"
        ],
        "methods": [
          "GET",
          "POST",
          "DELETE"
        ],
        "path_count": 512,
        "paths_sample": [
          "/v1/charges",
          "/v1/customers"
        ],
        "spec_version": "3.0.0",
        "title": "Stripe API",
        "version": "2026-06-30"
      },
      "url": "https://stripe.com/openapi.json"
    },
    {
      "bytes": 812,
      "content_type": "text/plain",
      "kind": "robots_txt",
      "status": 200,
      "summary": {
        "lines": 34,
        "sitemaps": [
          "https://stripe.com/sitemap.xml"
        ],
        "user_agents": [
          "*",
          "GPTBot"
        ]
      },
      "url": "https://stripe.com/robots.txt"
    }
  ],
  "kinds": [
    "openapi",
    "robots_txt",
    "sitemap",
    "llms_txt"
  ],
  "note": "Nur bekannte Konventionspfade und Verweise der Startseite. Nicht dokumentierte Schnittstellen bleiben unsichtbar.",
  "probed": 26
}

Security scan

  • No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.

Recent checks

WhenResultHTTPTimePrice
4 h agoPassed402147 ms$0.005