https://api.agentstools.dev/mcp/scanPOST /mcp/scan · x402 API by agentstools
Static security scan of an MCP manifest or tool list. Detects tool poisoning, hidden unicode instructions, prompt injection, data-exfiltration directives, dangerous capabilities, tool shadowing and post-approval rug-pull drift. Returns a 0-100 risk score, category, per-tool findings and content hashes. Security indicators, not a guarantee.
What does this x402 API do?
https://api.agentstools.dev/mcp/scan. This is an x402-gated POST API resource from agentstools. TOLL·402 did not invoke this route automatically because doing so was not considered safe. No normalized USD price is recorded; the listing names eip155:137 and eip155:42161 and eip155:480 and Base and Solana. No settled paid call has been verified.
- Published price
- No normalized USD price is recorded
- Networks
- eip155:137 · eip155:42161 · eip155:480 · Base · Solana
- Latest evidence
- TOLL·402 did not invoke this route automatically because doing so was not considered safe
- Resource ID
- d5e5a9399b2a2a4f17870773
Start with a quote-only recipe. Payment signing stays in your project.
const response = await fetch("https://api.agentstools.dev/mcp/scan", {
method: "POST",
headers: { "content-type": "application/json" },
body: JSON.stringify({
"type": "http",
"method": "POST",
"bodyType": "json",
"bodyFieldNames": [
"manifest"
],
"pathParamNames": [],
"queryParamNames": []
}),
});
console.log(response.status);
console.log(Object.fromEntries(response.headers));
console.log((await response.text()).slice(0, 1000));
// A valid 402 is a quote, not a completed paid call.Review the provider input schema before running this non-read-only method. No payment code is included.
- Exact route checked
not safely testable · potentially-mutating-method:POST
- Origin reachable
OPTIONS https://api.agentstools.dev/ returned 405.
- Observed in cdp-bazaar
The registry record was observed and retained with provenance.
- Observed in 402-index
Discovered through bazaar.
- Registry record checked
Registry health: healthy.
What evidence supports this listing?
Each record has an exact-route quote outcome. Unresolved templates and potentially mutating methods are labeled instead of being invoked without provider-specific test input. A quote is still separate from a settled paid call. Read the discovery and verification methodology →
Which networks and payment options does it accept?
The normalized listing price is No normalized USD price is recorded. Raw protocol requirements remain visible below for implementation and audit use.