83trust / 100
Report
by AgentCheck in Security & trust
x402 APIPassing, checked 3 h ago
AgentCheck: independent report on an x402 seller before you pay it. Are its buyers real (repeat wallets on their own money) or funded by the seller itself, measured from 30 days of on-chain payments, plus results of our own paid test purchases where we have them. Query: ?domain=<seller-domain>. GET /sellers (free) lists covered domains.
GET https://agentcheck-kohl.vercel.app/report
Last 30 days
All checks passedSome failedAll failedNot checked
- Uptime
- 100%
- Response time
- 275 ms typical, 275 ms slowest 5%
- Last check
- 3 h ago
- Next check
- any minute now
How to call it
# See the payment challenge (nothing is charged)
curl -i -X GET "https://agentcheck-kohl.vercel.app/report?domain=api.exa.ai"import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";
const client = new x402Client().register(
"eip155:8453",
new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)),
);
const pay = wrapFetchWithPayment(fetch, client);
// Not sure it's safe to pay? Preflight it first for $0.03:
// GET https://toolvet.app/api/v1/check?url=https%3A%2F%2Fagentcheck-kohl.vercel.app%2Freport
const res = await pay("https://agentcheck-kohl.vercel.app/report?domain=api.exa.ai");
console.log(await res.json());Example input
{
"domain": "api.exa.ai"
}Example output
{
"domain": "api.exa.ai",
"findings": [
"..."
],
"purchases": 2,
"tested": "2026-10-02",
"verdict": "works; ..."
}Security scan
- No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.
Recent checks
| When | Result | HTTP | Time | Price |
|---|---|---|---|---|
| 3 h ago | Passed | 402 | 275 ms | $0.002 |