83trust / 100

Report

by AgentCheck in Security & trust

x402 APIPassing, checked 3 h ago

AgentCheck: independent report on an x402 seller before you pay it. Are its buyers real (repeat wallets on their own money) or funded by the seller itself, measured from 30 days of on-chain payments, plus results of our own paid test purchases where we have them. Query: ?domain=<seller-domain>. GET /sellers (free) lists covered domains.

GET https://agentcheck-kohl.vercel.app/report

Last 30 days

All checks passedSome failedAll failedNot checked
Uptime
100%
Response time
275 ms typical, 275 ms slowest 5%
Last check
3 h ago
Next check
any minute now

How to call it

# See the payment challenge (nothing is charged)
curl -i -X GET "https://agentcheck-kohl.vercel.app/report?domain=api.exa.ai"
import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const client = new x402Client().register(
  "eip155:8453",
  new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)),
);
const pay = wrapFetchWithPayment(fetch, client);

// Not sure it's safe to pay? Preflight it first for $0.03:
// GET https://toolvet.app/api/v1/check?url=https%3A%2F%2Fagentcheck-kohl.vercel.app%2Freport
const res = await pay("https://agentcheck-kohl.vercel.app/report?domain=api.exa.ai");
console.log(await res.json());

Example input

{
  "domain": "api.exa.ai"
}

Example output

{
  "domain": "api.exa.ai",
  "findings": [
    "..."
  ],
  "purchases": 2,
  "tested": "2026-10-02",
  "verdict": "works; ..."
}

Security scan

  • No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.

Recent checks

WhenResultHTTPTimePrice
3 h agoPassed402275 ms$0.002