81trust / 100

Exposure Check Email

by agent.connskill.com in Email & messaging

x402 APIPassing, checked 3 h ago

Leak and infostealer exposure of one e-mail address: infections that saved it (count, first/last seen, corporate vs user services), leak records and sources - aggregates only, never passwords, logins, devices or IPs; the address is echoed only as SHA-256. For addresses you own or are authorised to check

POST https://agent.connskill.com/v1/exposure-check-email

Last 30 days

All checks passedSome failedAll failedNot checked
Uptime
100%
Response time
213 ms typical, 213 ms slowest 5%
Last check
3 h ago
Next check
any minute now

How to call it

# See the payment challenge (nothing is charged)
curl -i -X POST "https://agent.connskill.com/v1/exposure-check-email" \
  -H "content-type: application/json" \
  -d '{"email":"[email protected]"}'
import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const client = new x402Client().register(
  "eip155:8453",
  new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)),
);
const pay = wrapFetchWithPayment(fetch, client);

// Not sure it's safe to pay? Preflight it first for $0.03:
// GET https://toolvet.app/api/v1/check?url=https%3A%2F%2Fagent.connskill.com%2Fv1%2Fexposure-check-email
const res = await pay("https://agent.connskill.com/v1/exposure-check-email", {
  method: "POST",
  headers: { "content-type": "application/json" },
  body: JSON.stringify({"email":"[email protected]"}),
});
console.log(await res.json());

Example input

{
  "email": "[email protected]"
}

Example output

{
  "domain": "example.com",
  "infostealer": {
    "compromised": true,
    "corporateServices": 16,
    "firstCompromised": "2026-04-12T…",
    "infections": 2,
    "lastCompromised": "2026-05-27T…",
    "userServices": 1262
  },
  "leaks": {
    "fieldTypes": [
      "name",
      "password"
    ],
    "found": 7,
    "sources": [
      {
        "date": "2012-05",
        "name": "LinkedIn.com"
      }
    ]
  },
  "status": "delivered",
  "subject": "sha256:9f86d0…",
  "verdict": {
    "level": "high",
    "reasons": [
      "2 infostealer infection(s) with this address saved, last 2026-05-27"
    ]
  }
}

Security scan

  • No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.

Recent checks

WhenResultHTTPTimePrice
3 h agoPassed402213 ms$0.05