pulsefeed-x402
Verify x402 payment endpoints before an AI agent pays: scam scan, on-chain checks, trust scores.
Should I use this
Quality & Safety
Findings (2)
- HIGHin x402_ecosystem_stats
- HIGH
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"pulsefeed-x402": {
"command": "npx",
"args": [
"pulsefeed-x402-mcp"
]
}
}
}Runnable packages
1.1.0stdioRemote endpoints
https://pulsefeed.dev/mcp-serverstreamable-httpWhat it can do
Tool inventory
Tools (11)
🟢check_x402_endpoint(url)
Before paying an unknown x402 endpoint, check whether it is safe: liveness, trust score (0-100), anomaly flags (receiver address changed between observations, catalog price vs. challenge price, invalid receiver, testnet listed as production, scheme outside the x402 spec), receiver stability and observation-count-qualified uptime — with a pay/avoid verdict. Reads the challenge from both the response body and the v2 PAYMENT-REQUIRED header. Free.
Input Schema
{
"type": "object",
"properties": {
"url": {
"type": "string",
"description": "The x402 endpoint URL to verify"
}
},
"required": [
"url"
],
"additionalProperties": false
}🟢mcp_check_server(package)
Before installing an MCP server or npm package, audit it: does it run an INSTALL SCRIPT (arbitrary code execution at `npm i`), is it abandoned, does it ship a repository and license, weekly downloads, provenance — with a safe/caution/avoid verdict. ~11% of audited MCP servers run install scripts. Free.
Input Schema
{
"type": "object",
"properties": {
"package": {
"type": "string",
"description": "npm package name of the MCP server, e.g. @scope/name"
}
},
"required": [
"package"
],
"additionalProperties": false
}🟢mcp_drift_check(packages, days)
The rug pull check. `mcp_check_server` answers whether a package is safe TODAY; this answers what CHANGED after it was adopted: an install script added in a later version (arbitrary code on `npm i` that was not there at review time), package ownership swapped, repository removed, package unpublished, build provenance lost. Pass your own dependency list to check it in one call. Derived from a daily external re-audit of the whole MCP package population — an event exists only because a snapshot from before it exists. Free.
Input Schema
{
"type": "object",
"properties": {
"packages": {
"type": "array",
"items": {
"type": "string"
},
"maxItems": 200,
"description": "npm package names to check, e.g. your installed MCP servers. Omit for the whole ecosystem feed."
},
"days": {
"type": "integer",
"minimum": 1,
"maximum": 365,
"description": "Window in days (default 30)"
}
},
"additionalProperties": false
}🟢mcp_security_report
State of MCP Security: how many audited MCP servers run an arbitrary install script, are abandoned, ship no repository or license — with day-over-day deltas and a sample of currently-flagged servers. From a daily audit of the MCP server catalog. Free.
Input Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}🟢pulsefeed_products
List PulseFeed's products. All data endpoints are FREE since 2026-09-02 (trust checks, track records, datasets, drift history); only on-chain token signals are x402 pay-per-call. Formerly: deep trust check, endpoint track record, bulk trust dataset, and the cross-domain Data API. Includes the client-side spend-cap gotcha for x402-fetch.
Input Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}🟢x402_changes(days)
What changed in the x402 ecosystem recently: services that stopped returning a valid challenge, receiver (payTo) changes, price changes, recoveries, newly-seen services. Derived from compounding time-series that cannot be reconstructed after the fact. Free.
Input Schema
{
"type": "object",
"properties": {
"days": {
"type": "integer",
"minimum": 1,
"maximum": 365,
"description": "Window in days (default 7)"
}
},
"additionalProperties": false
}🟢x402_data_sample
FREE sample of the PulseFeed Data API: top-10 live x402 services as FULL records (compounding payTo/price history, anomaly flags, on-chain receiver profile), top-10 MCP servers with full audit profile, and 3 live incidents.
Input Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}🟢x402_ecosystem_stats
Live health of the whole x402 agent-payment ecosystem: tracked/alive/dead counts, catalog-accuracy audit (what share of listings called 'healthy' actually work), risk-level distribution, receiver stability and on-chain receiver profiles. Free.
Input Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}🟢x402_incidents(days)
Anomalies observed in live x402 endpoints by continuous independent measurement: receiver-address changes between observations, catalog price vs. challenge price mismatches, invalid receivers, testnet endpoints listed as production, payment schemes outside the x402 spec — EACH WITH AN ON-CHAIN REFERENCE on Base. Measurements, not accusations of intent. Check before paying anything. Free.
Input Schema
{
"type": "object",
"properties": {
"days": {
"type": "integer",
"minimum": 1,
"maximum": 365,
"description": "Look-back window in days (default 30)"
}
},
"additionalProperties": false
}🟢x402_leaderboard
Top x402 services ranked by the open PulseFeed Trust Score (0-100), with price and network — the most reliable live agent-payment endpoints right now. Free.
Input Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}🟢x402_working_services
List x402 agent-payment services that are currently ALIVE and return a valid x402 challenge, ranked by PulseFeed Trust Score, plus ecosystem risk map. Use this to pick a service with a track record instead of paying an endpoint you have not checked. Free.
Input Schema
{
"type": "object",
"properties": {},
"additionalProperties": false
}Community
Evidence