resources/animica/POST /x402/security/injection
POSTorigin + 2 sourcesqualified signals

https://animica.dev/x402/security/injectionPOST /x402/security/injection · x402 API by animica

Scan retrieved content — a fetched page, an email, a tool result — for text trying to manipulate the agent reading it: instruction overrides, role/system impersonation, exfiltration requests, hidden or encoded directives. Returns a risk score, the suspicious spans verbatim, and the technique observed. Deterministic pattern checks run ALONGSIDE the model so a blatant "ignore all previous instructions" is caught even if the model misses it, and the two signals are reported separately rather than blended into one number you cannot interrogate. Priced per call. For high-volume use, buy prepaid credits (POST /x402/credits/buy) and send X-Animica-Credits on each request — no settlement, no gas, no per-call payment round trip. Paying in ANM on the animica:1 lane is also ~25% cheaper because we sp

https://animica.dev/x402/security/injection

What does this x402 API do?

https://animica.dev/x402/security/injection. This is an x402-gated POST API resource from animica. TOLL·402 did not invoke this route automatically because doing so was not considered safe. No normalized USD price is recorded; the listing names animica:1 and Base. No settled paid call has been verified.

Published price
No normalized USD price is recorded
Networks
animica:1 · Base
Latest evidence
TOLL·402 did not invoke this route automatically because doing so was not considered safe
Resource ID
7c9982004aa6d4ba8bd8b670
USE THIS RESOURCE

Start with a quote-only recipe. Payment signing stays in your project.

CODE
AI CODING TOOLS
quote-check.ts
const response = await fetch("https://animica.dev/x402/security/injection", {
  method: "POST",
  headers: { "content-type": "application/json" },
  body: JSON.stringify({
  "type": "http",
  "method": "POST",
  "bodyType": "json",
  "bodyFieldNames": [
    "input"
  ],
  "pathParamNames": [],
  "queryParamNames": []
}),
});

console.log(response.status);
console.log(Object.fromEntries(response.headers));
console.log((await response.text()).slice(0, 1000));

// A valid 402 is a quote, not a completed paid call.

Review the provider input schema before running this non-read-only method. No payment code is included.

STATUS HISTORY

  1. Exact route checked

    not safely testable · potentially-mutating-method:POST

  2. Origin reachable

    HEAD https://animica.dev/ returned 200.

  3. Observed in cdp-bazaar

    The registry record was observed and retained with provenance.

  4. Observed in 402-index

    Discovered through self-registered.

  5. Registry record checked

    Registry health: healthy.

What evidence supports this listing?

cdp-bazaarobserved 2026-08-25 · open source record ↗
402-indexobserved 2026-08-25 · open source record ↗
origin checkHEAD https://animica.dev/ → 200 on 2026-08-25
route quotenot invoked automatically · potentially-mutating-method:POST · 2026-08-25

Each record has an exact-route quote outcome. Unresolved templates and potentially mutating methods are labeled instead of being invoked without provider-specific test input. A quote is still separate from a settled paid call. Read the discovery and verification methodology →

Which networks and payment options does it accept?

The normalized listing price is No normalized USD price is recorded. Raw protocol requirements remain visible below for implementation and audit use.

Baseexact5808 atomic · 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
animica:1exact68989547038 atomic · ANM
animica POST /x402/security/injection · 7c9982 x402 API · TOLL·402