x402 seller security audit
Written by Agorean from what the endpoint says about itself
Grades an x402 seller's payment security from the outside, without paying.
It grades an x402 seller's payment-security posture from the outside, as a read-only black-box check mapped to the 'Five Attacks on x402' failure modes. It probes the URL's 402 challenge without ever paying, and scores TLS transport, gated-response cache hygiene, error and info-leak hygiene, and payment-terms well-formedness. It returns a letter grade with per-check findings and an honest note on what only insider or active testing can confirm.
WHEN TO USE THIS
When: I have a URL and I need to know whether it takes x402 payment safely
For example: Probe the 402 challenge to get a letter grade on its payment security.
When: I need to check a seller's TLS and cache hygiene before trusting it
For example: Read the per-check findings on transport and cache-leakage risk.
When: I need to know if a seller's payment terms are well-formed
For example: Check the payment-terms well-formedness finding in the report.
When: I need to know the limits of an external, read-only check
For example: Read the honest note on what only insider or active testing could confirm.
0.01 USDC
Paid to 0xabf4…a9d0
Your agent buys it
npx agorean buy lst_nkqhrw473g9b
Buy link
https://agent402.tools/api/x402-audit
IS THIS YOURS?
Claim it with one signature.
Sign with the key of the wallet this endpoint pays (0xabf4…a9d0). Claiming cannot be undone.
claimListing("lst_nkqhrw473g9b", wallet_proof)