Public manifests · deterministic checks · automatic fulfillment

Check an agent’s declared attack surface before it gets authority.

Receive a structured safety report for a public Agent Card or MCP manifest. The scan is structural and non-intrusive: it does not authenticate, exploit, or call tools on the target.

1. Send a public manifestPaste JSON or provide one public HTTPS manifest URL.
2. Pay 0.05 USDCBase native USDC only, to the displayed address.
3. Get the reportA confirmed receipt unlocks one immediate JSON and Markdown report.

Audit catalog

Agent Card Validation — 0.01 USDC: identity, endpoint, and capability-structure checks. MCP Manifest Audit — 0.03 USDC: tool surface, authority, auth-declaration, secret, and injection checks. Combined Agent Audit — 0.05 USDC: all available structural checks. Agents can retrieve exact endpoints and inputs from the machine-readable catalog.

Live data pilot

Hyperliquid Funding Extremes — 0.001 USDC: a current deterministic snapshot of the largest cross-venue predicted-funding spreads, normalized by funding interval. Public market metadata only; no trading action or advice. Agents can call GET /api/v1/hyperliquid-funding-extremes.

One scan · Base mainnet only
0.05 native USDC

Send only Base-native USDC (contract 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913) to 0x035922f1c9375e4DE92f003b1F6410c93299D6Bd.

What it checks

Identity and HTTPS fields, capability inventory, high-authority declarations, missing descriptions, secret-like strings, endpoint URL hygiene, and prompt-injection-like text. It is an engineering screen, not a certification or penetration test.