{"_id":"@agentutility/mcp-prooflayer","_rev":"7-2d7d9cd99533b79fea540ffaffcef253","name":"@agentutility/mcp-prooflayer","dist-tags":{"latest":"0.3.3"},"versions":{"0.1.8":{"name":"@agentutility/mcp-prooflayer","version":"0.1.8","keywords":["mcp","model-context-protocol","x402","agentutility","agent-tools","prooflayer"],"license":"MIT","_id":"@agentutility/mcp-prooflayer@0.1.8","maintainers":[{"name":"agentutility","email":"aroozen+agentutility@gmail.com"}],"homepage":"https://mcp.agentutility.ai/prooflayer/","bugs":{"url":"https://github.com/rooz21/x402/issues"},"bin":{"agentutility-mcp-prooflayer":"dist/index.js"},"dist":{"shasum":"5cbcf12d02b4377ec854d44b894640d11e9994d7","tarball":"https://registry.npmjs.org/@agentutility/mcp-prooflayer/-/mcp-prooflayer-0.1.8.tgz","fileCount":4,"integrity":"sha512-A7C7AZpA49xbTuNqfbfbip39xo7AFgY+SWuZo1ZlTrqvjHiPFFEEYP+i62K0DeHiNKcZqUcSxAHGID/Q2hPmtA==","signatures":[{"sig":"MEUCID7Kb3f9VKTjwrlEFClIhqd0s695QTDcfTcsn/pXavUCAiEAt5JmLTKDDCU7/KpID113yigCVmgD0w+eKqj/WNxTK44=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":26784},"main":"dist/index.js","type":"module","engines":{"node":">=18"},"scripts":{"build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"agentutility","email":"aroozen+agentutility@gmail.com"},"repository":{"url":"git+https://github.com/rooz21/x402.git","type":"git","directory":"packages/mcp-prooflayer"},"_npmVersion":"10.8.2","description":"MCP server for the @agentutility prooflayer cluster — pay-per-call x402 tools, no API keys, USDC on Base.","directories":{},"_nodeVersion":"20.20.0","dependencies":{"viem":"^2.21.0","@x402/evm":"^2.12.0","@x402/fetch":"^2.12.0","@modelcontextprotocol/sdk":"^1.0.4"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.5.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-prooflayer_0.1.8_1779123801459_0.11222438291311665","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@agentutility/mcp-prooflayer","version":"0.2.1","keywords":["mcp","model-context-protocol","x402","agentutility","agent-tools","prooflayer"],"license":"MIT","_id":"@agentutility/mcp-prooflayer@0.2.1","maintainers":[{"name":"agentutility","email":"aroozen+agentutility@gmail.com"}],"homepage":"https://mcp.agentutility.ai/prooflayer/","bugs":{"url":"https://github.com/rooz21/x402/issues"},"bin":{"agentutility-mcp-prooflayer":"dist/index.js"},"dist":{"shasum":"c6bd9903f42fd199cbe15cb01fc59f28808211af","tarball":"https://registry.npmjs.org/@agentutility/mcp-prooflayer/-/mcp-prooflayer-0.2.1.tgz","fileCount":4,"integrity":"sha512-+GQRHnVzxJD7z6y/EdhpbKqymn5M3iIM6i0tr27adV/m/sH3qfUEgSZRMDrdxb+pujA4j4PGIbMJt6+rxkpsHg==","signatures":[{"sig":"MEUCIQDe/IdW9M5KVbpy27SVixjYxFr1fCmx9h9e9TvU1ug2BwIgJA4U1zUzl/AJowgC8nXO/aMHliBgvdPDQpPkEVzu/Eo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":34043},"main":"dist/index.js","type":"module","engines":{"node":">=18"},"scripts":{"build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"agentutility","email":"aroozen+agentutility@gmail.com"},"repository":{"url":"git+https://github.com/rooz21/x402.git","type":"git","directory":"packages/mcp-prooflayer"},"_npmVersion":"10.8.2","description":"MCP server for the @agentutility prooflayer cluster — pay-per-call x402 tools, no API keys, USDC on Base.","directories":{},"_nodeVersion":"20.20.2","dependencies":{"viem":"^2.21.0","@x402/evm":"^2.12.0","@x402/fetch":"^2.12.0","@modelcontextprotocol/sdk":"^1.0.4"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.5.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-prooflayer_0.2.1_1782526548467_0.6528899743799974","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@agentutility/mcp-prooflayer","version":"0.2.0","keywords":["mcp","model-context-protocol","x402","agentutility","agent-tools","prooflayer"],"license":"MIT","_id":"@agentutility/mcp-prooflayer@0.2.0","maintainers":[{"name":"agentutility","email":"aroozen+agentutility@gmail.com"}],"homepage":"https://mcp.agentutility.ai/prooflayer/","bugs":{"url":"https://github.com/rooz21/x402/issues"},"bin":{"agentutility-mcp-prooflayer":"dist/index.js"},"dist":{"shasum":"df7c5d39c6160cc3c38aa82d6b4c94b5f0edf73f","tarball":"https://registry.npmjs.org/@agentutility/mcp-prooflayer/-/mcp-prooflayer-0.2.0.tgz","fileCount":4,"integrity":"sha512-C2rPdwcvZ8iS6OFUk98OcGyapzOGQpVuNxzwUi4Zfh7bMvPU5QNwD+yn+SHz6OOSjMO+vy2X/T4bNZ18D1iYHw==","signatures":[{"sig":"MEQCIDamiJ9eIkmhYtMechuGdjmCP8tN/ODsSjGW6gTZf1qDAiASz6Or6iF9l17m6+0w8bA200DLCRJbkamQDG0yJSK5Pw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":34181},"main":"dist/index.js","type":"module","engines":{"node":">=18"},"gitHead":"7f085d738f6b73053aa1c0a6e4af67112f4376d6","scripts":{"build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"agentutility","email":"aroozen+agentutility@gmail.com"},"repository":{"url":"git+https://github.com/rooz21/x402.git","type":"git","directory":"packages/mcp-prooflayer"},"_npmVersion":"10.8.2","description":"MCP server for the @agentutility prooflayer cluster — pay-per-call x402 tools, no API keys, USDC on Base.","directories":{},"_nodeVersion":"20.20.2","dependencies":{"viem":"^2.21.0","@x402/evm":"^2.12.0","@x402/fetch":"^2.12.0","@modelcontextprotocol/sdk":"^1.0.4"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.5.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-prooflayer_0.2.0_1782704268973_0.3856825068031702","host":"s3://npm-registry-packages-npm-production"}},"0.2.3":{"name":"@agentutility/mcp-prooflayer","version":"0.2.3","keywords":["mcp","model-context-protocol","x402","agentutility","agent-tools","prooflayer"],"license":"MIT","_id":"@agentutility/mcp-prooflayer@0.2.3","maintainers":[{"name":"agentutility","email":"aroozen+agentutility@gmail.com"}],"homepage":"https://mcp.agentutility.ai/prooflayer/","bugs":{"url":"https://github.com/rooz21/x402/issues"},"bin":{"agentutility-mcp-prooflayer":"dist/index.js"},"dist":{"shasum":"5abcb31e29040a58c1b80a55fa709bc63aa810e4","tarball":"https://registry.npmjs.org/@agentutility/mcp-prooflayer/-/mcp-prooflayer-0.2.3.tgz","fileCount":4,"integrity":"sha512-5N5Ayo66R4k0um5J4+SZu9ik8LpTJnyCmnLTGZSXD7sz0ZWEEx8qY2GlNoMLLlTS8KuLHst1IVS92oqv/mRDTQ==","signatures":[{"sig":"MEUCIExTZ0cu1B+XWcqGepUUx2p36qY3aFNMTUgY7IzuSnz/AiEAnc7HuosKm0Dv33Sa9pqv2tMw5uj2gec5ZnYQo/rzfjo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":35387},"main":"dist/index.js","type":"module","engines":{"node":">=18"},"gitHead":"e60d85b06e6a7aad743386a794e13c1dc0af2054","scripts":{"build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"agentutility","email":"aroozen+agentutility@gmail.com"},"repository":{"url":"git+https://github.com/rooz21/x402.git","type":"git","directory":"packages/mcp-prooflayer"},"_npmVersion":"10.8.2","description":"MCP server for the @agentutility prooflayer cluster — pay-per-call x402 tools, no API keys, USDC on Base.","directories":{},"_nodeVersion":"20.20.2","dependencies":{"viem":"^2.21.0","@x402/evm":"^2.12.0","@x402/fetch":"^2.12.0","@modelcontextprotocol/sdk":"^1.0.4"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.5.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-prooflayer_0.2.3_1783053698787_0.6521946546096362","host":"s3://npm-registry-packages-npm-production"}},"0.2.4":{"name":"@agentutility/mcp-prooflayer","version":"0.2.4","keywords":["mcp","model-context-protocol","x402","agentutility","agent-tools","prooflayer"],"license":"MIT","_id":"@agentutility/mcp-prooflayer@0.2.4","maintainers":[{"name":"agentutility","email":"aroozen+agentutility@gmail.com"}],"homepage":"https://mcp.agentutility.ai/prooflayer/","bugs":{"url":"https://github.com/rooz21/x402/issues"},"bin":{"agentutility-mcp-prooflayer":"dist/index.js"},"dist":{"shasum":"4d482f50617333adb062dccd1e84d3d351e5bc31","tarball":"https://registry.npmjs.org/@agentutility/mcp-prooflayer/-/mcp-prooflayer-0.2.4.tgz","fileCount":4,"integrity":"sha512-YQ3tdxkZibm/tSXSkTO05SgMvPEYP9IHiyLzgff0q3mcuU5ynMIut/bQspJ2QwM381UifgBjBHvJrHyLfqsYXw==","signatures":[{"sig":"MEQCICTeQVNfEx7QlH6dAn0x8WCfbi1vKGGm9Cxmbz8YmphAAiAoVNgmVy+07fQqfYJuA8lGjQ8JAFzkDZK0cxcPOQhmlw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":35434},"main":"dist/index.js","type":"module","engines":{"node":">=18"},"gitHead":"bb16253ab9d06c11e824e1f2d1d907a5c815ef11","mcpName":"ai.agentutility/mcp-prooflayer","scripts":{"build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"agentutility","email":"aroozen+agentutility@gmail.com"},"repository":{"url":"git+https://github.com/rooz21/x402.git","type":"git","directory":"packages/mcp-prooflayer"},"_npmVersion":"10.8.2","description":"MCP server for the @agentutility prooflayer cluster — pay-per-call x402 tools, no API keys, USDC on Base.","directories":{},"_nodeVersion":"20.20.2","dependencies":{"viem":"^2.21.0","@x402/evm":"^2.12.0","@x402/fetch":"^2.12.0","@modelcontextprotocol/sdk":"^1.0.4"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.5.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-prooflayer_0.2.4_1783646570646_0.23841797854203506","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@agentutility/mcp-prooflayer","version":"0.3.1","keywords":["mcp","model-context-protocol","x402","agentutility","agent-tools","prooflayer"],"license":"MIT","_id":"@agentutility/mcp-prooflayer@0.3.1","maintainers":[{"name":"agentutility","email":"aroozen+agentutility@gmail.com"}],"homepage":"https://mcp.agentutility.ai/prooflayer/","bugs":{"url":"https://github.com/rooz21/x402/issues"},"bin":{"agentutility-mcp-prooflayer":"dist/index.js"},"dist":{"shasum":"9d23f58b97006652797ec6d548e4fe9d6cc98fbc","tarball":"https://registry.npmjs.org/@agentutility/mcp-prooflayer/-/mcp-prooflayer-0.3.1.tgz","fileCount":4,"integrity":"sha512-ZiVWa6KSkBTC2ZqsZjjDLf25ZUjTgfXxzz7b4irFP4Y/1U8QBN4fbnIYhhJVz4mf+FvJsmHRKGx+8qLVenACow==","signatures":[{"sig":"MEUCIDkSSNeuFdKZLl/9Bzq1BuGP/9ASTypAPf0DUJVYvkPyAiEA10pmiRioj1HaZTOQOpi8sxKhFLGMNoFKWqUYX6iur8E=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":40318},"main":"dist/index.js","type":"module","engines":{"node":">=18"},"gitHead":"4525b787eb30dd30312755c8b74562cecba5f40b","mcpName":"ai.agentutility/mcp-prooflayer","scripts":{"build":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"agentutility","email":"aroozen+agentutility@gmail.com"},"repository":{"url":"git+https://github.com/rooz21/x402.git","type":"git","directory":"packages/mcp-prooflayer"},"_npmVersion":"10.8.2","description":"MCP server for the @agentutility prooflayer cluster — pay-per-call x402 tools, no API keys, USDC on Base.","directories":{},"_nodeVersion":"20.20.2","dependencies":{"viem":"^2.21.0","@x402/evm":"^2.12.0","@x402/fetch":"^2.12.0","@modelcontextprotocol/sdk":"^1.0.4"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.5.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-prooflayer_0.3.1_1784072730376_0.8662825280941211","host":"s3://npm-registry-packages-npm-production"}},"0.3.3":{"name":"@agentutility/mcp-prooflayer","mcpName":"ai.agentutility/mcp-prooflayer","version":"0.3.3","description":"MCP server for the @agentutility prooflayer cluster — pay-per-call x402 tools, no API keys, USDC on Base.","license":"MIT","type":"module","main":"dist/index.js","bin":{"agentutility-mcp-prooflayer":"dist/index.js"},"repository":{"type":"git","url":"git+https://github.com/rooz21/x402.git","directory":"packages/mcp-prooflayer"},"homepage":"https://mcp.agentutility.ai/prooflayer/","scripts":{"build":"tsc","prepublishOnly":"npm run build"},"keywords":["mcp","model-context-protocol","x402","agentutility","agent-tools","prooflayer"],"dependencies":{"@modelcontextprotocol/sdk":"^1.0.4","@x402/fetch":"^2.12.0","@x402/evm":"^2.12.0","viem":"^2.21.0"},"devDependencies":{"@types/node":"^22.0.0","typescript":"^5.5.0"},"engines":{"node":">=18"},"_id":"@agentutility/mcp-prooflayer@0.3.3","bugs":{"url":"https://github.com/rooz21/x402/issues"},"_nodeVersion":"20.20.2","_npmVersion":"10.8.2","dist":{"integrity":"sha512-th+fmsPtoQC67byj5OVzbAy3smqoYslKNM/WY2RN3leI8SCVJAW4kyZDpFwBcy2qmhf0mlIMi3avzDXXhf1HOw==","shasum":"85febd30f4010f7ae3782d5be3ade9f894e57559","tarball":"https://registry.npmjs.org/@agentutility/mcp-prooflayer/-/mcp-prooflayer-0.3.3.tgz","fileCount":4,"unpackedSize":41010,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCm25Dyd/tk7dkyaKEW0RLaCmXEDzUGaFBS6r/3MP327AIgFUzMPZ10HsWfCVUJegneKKWgIn8owP/lUKG/WSC6ot8="}]},"_npmUser":{"name":"agentutility","email":"aroozen+agentutility@gmail.com"},"directories":{},"maintainers":[{"name":"agentutility","email":"aroozen+agentutility@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-prooflayer_0.3.3_1784663429588_0.6110175326343681"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-18T17:03:21.375Z","modified":"2026-07-21T19:50:29.933Z","0.1.8":"2026-05-18T17:03:21.610Z","0.2.1":"2026-06-27T02:15:48.636Z","0.2.0":"2026-06-29T03:37:49.117Z","0.2.3":"2026-07-03T04:41:38.921Z","0.2.4":"2026-07-10T01:22:50.791Z","0.3.1":"2026-07-14T23:45:30.545Z","0.3.3":"2026-07-21T19:50:29.719Z"},"bugs":{"url":"https://github.com/rooz21/x402/issues"},"license":"MIT","homepage":"https://mcp.agentutility.ai/prooflayer/","keywords":["mcp","model-context-protocol","x402","agentutility","agent-tools","prooflayer"],"repository":{"type":"git","url":"git+https://github.com/rooz21/x402.git","directory":"packages/mcp-prooflayer"},"description":"MCP server for the @agentutility prooflayer cluster — pay-per-call x402 tools, no API keys, USDC on Base.","maintainers":[{"name":"agentutility","email":"aroozen+agentutility@gmail.com"}],"readme":"# @agentutility/mcp-prooflayer\n\n> Trust + risk scanners for AI-built apps.\n\nAI builds apps fast. Prooflayer verifies they're safe to ship — secrets, deploys, migrations, dependencies, prompt-injection, supply chain.\n\n**Pricing:** pay-per-call in USDC on Base. No subscriptions, no API keys. See per-tool prices below.\n\n## Install — Claude Desktop\n\nEdit `~/Library/Application Support/Claude/claude_desktop_config.json` (macOS) or `%APPDATA%\\Claude\\claude_desktop_config.json` (Windows):\n\n```json\n{\n  \"mcpServers\": {\n    \"agentutility-prooflayer\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@agentutility/mcp-prooflayer\"],\n      \"env\": { \"X402_PRIVATE_KEY\": \"0xYOUR_PRIVATE_KEY_HEX\" }\n    }\n  }\n}\n```\n\nRestart Claude Desktop. 17 tools appear in the tool palette.\n\n## Install — Cursor\n\nAdd to `.cursor/mcp.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"agentutility-prooflayer\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@agentutility/mcp-prooflayer\"],\n      \"env\": { \"X402_PRIVATE_KEY\": \"0x...\" }\n    }\n  }\n}\n```\n\n## Funding\n\nSend any amount of **USDC on Base mainnet** to the address derived from your `X402_PRIVATE_KEY`. The MCP server uses it to pay for tool calls automatically.\n\nUSDC on Base contract: `0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913`\n\n## Tools (17)\n\n| Tool | Description |\n|---|---|\n| `ai-content-detector` | (0.03 USDC/call) Detect AI-generated writing with a calibrated probability score. Returns a 0-1 likelihood, a verdict, suspicious phrases, and per-axis style signals (em-dash overuse, hedge phrases, formulaic transitions). Works as an AI content detector, GPT detector, or ChatGPT-text checker. |\n| `ai-image-detector` | (0.02 USDC/call) AI-generated image detector: send an image URL and get back a calibrated probability that the image is AI-generated or synthetic, plus the vision signals behind the score — anatomical artifacts (hands, teeth, eyes), garbled pseudo-text, over-smooth texture, lighting/shadow inconsistency, background incoherence, and an over-stylized 'AI look'. This is a vision-model heuristic, not a forensic or watermark-level detector, calibrated to never inflate a verdict just because a caller wants one. Verdict buckets: likely_real below 0.4, uncertain 0.4-0.65, likely_ai at 0.65+. A failed or unparseable vision call returns an error instead of a guess. Use it as an AI image detector, synthetic image checker, AI-generated picture screen, or image slop filter. |\n| `app-store-rejection-explain` | (0.02 USDC/call) Explains App Store and Google Play rejections and turns them into a resubmission plan. Parses rejection text and app metadata, identifies likely policy areas, extracts deadlines, and returns a policy-clean resubmission checklist plus reviewer-note outline. Does not promise approval or recommend platform-policy evasion. Use it for Google Play rejection triage or as a mobile app review policy checklist. |\n| `brand-clearance` | (0.25 USDC/call) Screens a candidate brand name across trademark, domain, and web-presence checks in a single composite signal. Runs four checks in parallel (in-process, no x402 self-billing): USPTO TM name search, domain availability across requested TLDs (default .com .ai .dev .io .co), Wikipedia presence, and a Hacker News mention scan. Returns risk_level (clear|soft|moderate|hard), risk_score 0-100, sub-scores per signal, the raw hits, and a one-line recommendation. Designed for AI agents self-screening project, product, or startup names before committing. Screening tool only, not legal advice. Use it as a brand clearance aggregator, name screening tool, product-name vetting step, or startup-brand pre-flight. |\n| `cve` | (0.005 USDC/call) Looks up a CVE and returns the full NIST NVD vulnerability record. Short alias of cve-lookup: CVSS v3.1 + v2 vectors, severity, CWE class, affected CPE list, references, public-exploit indicator with reference URLs, and a bounded exploitability summary. Federal public data. Use it as a vulnerability lookup, NVD record fetch, CVSS scorer, vuln advisory fetch, exploit-known check, or patch-priority triage for Log4Shell-style records. |\n| `cve-lookup` | (0.005 USDC/call) Looks up a CVE and returns its canonical NIST NVD record: description, CVSS v3.1 and v2 vectors plus numeric scores, severity bucket, CWE class, affected CPE list, NVD references, and a public-exploit-known boolean with reference URLs. Takes a CVE-YYYY-NNNNN identifier and includes a bounded plain-English exploitability summary. Federal public data. Use it as a vulnerability database, NVD record fetcher, CVSS scorer, Log4Shell-style advisory inspector, known-exploit checker, CISA KEV adjacent tool, patch-priority triage aid, or CWE classifier. |\n| `db-migration-risk` | (0.02 USDC/call) Audits database migrations for risky SQL before deploy. Walks migrations/, prisma/migrations/, db/migrate/, supabase/migrations/, and alembic/versions/ and flags destructive DDL, lock-heavy ALTER TABLE, NOT NULL without DEFAULT, plain CREATE INDEX (vs CONCURRENTLY), unbounded TRUNCATE/DELETE, and FK validation without NOT VALID. Returns 0-100 score, per-finding kind/severity/path/line/evidence/recommendation, and a Venice plain-English verdict. Dual input: {repo: 'owner/name'} for public GitHub or {files: [{path, content}, ...]} for private / agent-workspace use. Use it as a SQL migration safety check, DROP COLUMN detector, unsafe ALTER TABLE detector, Postgres CREATE INDEX CONCURRENTLY check, Alembic op.drop_* detector, TRUNCATE/DELETE WHERE detector, foreign key NOT VALID check, or pre-deploy DB gate. |\n| `dep-risk-summary` | (0.03 USDC/call) Scores dependency risk for a whole repo from its manifests and lockfiles. Best-effort scan of package.json, pnpm-lock.yaml, package-lock.json, yarn.lock, bun.lock (JS); requirements.txt, pyproject.toml, poetry.lock (Python); go.mod, go.sum (Go). Samples 10 alphabetically-first direct deps via npm/PyPI registry for deprecation + install-script signals. Returns 0-100 score, per-finding kind/severity/path/evidence/recommendation, and a Venice plain-English verdict. Dual input: {repo: 'owner/name'} or {files: [{path, content}, ...]}. Use it as a package.json + lockfile vetter, unpinned dep detector, transitive dep counter, requirements.txt audit, pyproject dep risk check, deprecated dep detector, install-script dep detector, or Snyk-adjacent repo-level supply-chain risk score. |\n| `deploy-config-risk` | (0.02 USDC/call) Audits deploy configuration files for production risks. Fetches Dockerfile, wrangler.toml, vercel.json, netlify.toml, fly.toml, docker-compose.yml, and serverless.yml and flags open CORS with credentials, exposed admin ports (22/5432/6379/etc), plaintext secrets in inline env, dev/debug mode left enabled, and missing healthchecks. Returns 0-100 score, per-finding kind/severity/path/line/redacted-evidence/recommendation, and a Venice plain-English verdict. Dual input: {repo: 'owner/name'} for public GitHub or {files: [{path, content}, ...]} for private / agent-workspace use. Use it as a Dockerfile lint, vercel.json hardening pass, wrangler.toml review, docker-compose.yml safety check, fly.toml secrets check, netlify deploy gate, open CORS detector, exposed admin port detector, plaintext-secret-in-env detector, or production-readiness deploy gate. |\n| `github-repo-health` | (0.03 USDC/call) Score how healthy and maintained an open-source GitHub repo is. Send a repo (owner/name) and it pulls public GitHub REST API data on commit recency, 30-day commit volume, star count, contributor count, README/tests/CI presence, and license, rolling it into a 0-100 score and a grade (abandoned, stale, okay, healthy, or thriving), plus a short LLM verdict explaining the rating. No auth needed for public repos. Use it as a GitHub repo health checker, open-source maintainability score, repo activity checker, or dependency-vetting tool before you adopt or depend on a library. |\n| `package-risk-npm` | (0.03 USDC/call) Scores supply-chain risk for an npm package before you install it. Pulls registry metadata + download stats for the package (and optional version) and checks maintainer count, weekly downloads, install / postinstall script hooks, dependency tree depth, deprecation flag, package age, last-publish recency, and edit-distance to popular package names (typosquat). Returns a 0-10 score, risk_level bucket, contributing factors, typosquat candidate list, and a Venice plain-English summary. Use it as an npm supply-chain scanner, typosquat detector, postinstall-script flagger, npm install pre-flight audit, package.json + pnpm-lock.yaml vetter, or Snyk-adjacent / Socket.dev-adjacent pre-install safety gate. |\n| `production-readiness-score` | (0.10 USDC/call) Composite: one call runs secrets-exposure-check, deploy-config-risk, db-migration-risk, dep-risk-summary, and prompt-injection-surface in parallel and rolls the results into one production-readiness verdict for a repo. Send either {repo: 'owner/name'} or {files: [{path, content}]}, with optional weights (each component in [0, 0.5], normalized) and max_findings (default 10, cap 50) to tune the output. Returns a composite score 0-100, a production_grade (production-ready, needs-review, risky, or do-not-ship), per-component sub-scores, deduped findings ranked by severity and score_contribution, and a plain-English summary naming the most acute risks. Use it as an AI app deploy gate, one-call repo audit, pre-deploy risk scan, or vibe-coded app safety check before shipping code an LLM wrote. |\n| `prompt-injection-detect` | (0.02 USDC/call) Prompt injection detector for untrusted inbound text — a webpage, an email, a tool result, or a message an agent is about to read. Two layers run on every call: a deterministic pattern layer (pure code) matching known injection shapes — instruction override, system-prompt exfiltration, role hijack / jailbreak phrasing ('act as DAN', 'developer mode'), fake delimiter blocks, tool abuse, and covert manipulation — plus a calibrated LLM judge layer scoring overall injection likelihood 0-1, never inflated to please a caller. Returns which pattern families hit, matched snippets, the judge's reasoning, and a combined verdict. If the LLM leg fails, the deterministic layer alone is still a valid, billable result. Use it as a prompt injection detector, jailbreak detector, untrusted text screen, or LLM input firewall. |\n| `prompt-injection-surface` | (0.03 USDC/call) Scans AI app source code for prompt injection risk at LLM call sites. Walks .ts/.tsx/.js/.jsx/.py/.mjs/.cjs source files, locates LLM SDK call sites (anthropic, openai, @ai-sdk/*, google generative), and flags user input flowing into prompts without sanitization, calls without max_tokens caps, system/user prompt mixing, and LLM output used unvalidated in fetch/exec/eval. Returns 0-100 score, per-finding kind/severity/path/line/evidence/recommendation, and a Venice plain-English verdict. Dual input: {repo: 'owner/name'} (tree-walk, capped 500 files) or {files: [{path, content}, ...]}. Use it as an LLM call-site audit, unsanitized-user-input-in-prompts detector, system-message mixing flag, unbounded completion detector, AI app safety scan, or pre-deploy AI risk gate. |\n| `pypi-package-risk` | (0.01 USDC/call) Scores the supply-chain risk of a PyPI package before you install it. Pulls metadata + release history from pypi.org for a package (and optional version), evaluating age, recent download volume, maintainer count, post-install hook presence, dependency depth, deprecation flags, last-update recency, and string-distance to popular packages (typosquat). Returns a numeric score (0-10), risk_level bucket, contributing factor list, and an AI-written plain-English risk summary from Venice. Use it as a Python supply-chain scanner, pip dependency vetter, typosquat detector, pre-install audit, Python-package safety check, pyproject.toml / requirements.txt vetter, or poetry + uv pre-install gate. |\n| `secrets-exposure-check` | (0.02 USDC/call) Scans project config files for hardcoded secrets before you deploy. Fetches top-level config files (.env*, wrangler.toml, vercel.json, next.config.*, package.json, etc.) and scans for hardcoded AWS/OpenAI/Anthropic/Stripe/GitHub keys, private keys, DB URLs with passwords, JWT secrets, weak values in .env.example, and server-only env vars accidentally exposed via NEXT_PUBLIC_. Returns 0-100 score, per-finding kind/severity/path/line/redacted-evidence/recommendation, and a Venice plain-English verdict. Dual input: {repo: 'owner/name'} for public GitHub or {files: [{path, content}, ...]} for private / agent-workspace use. Use it as a secrets exposure scan, hardcoded API key detector, .env-committed-key audit, Next.js client env leak detector, or pre-deploy secret gate. |\n| `vendor-questionnaire-draft` | (0.08 USDC/call) Drafts vendor security questionnaire answers from evidence you supply. Takes questionnaire text plus evidence snippets and drafts only evidence-supported answers; unsupported questions are marked needs_evidence instead of invented. Useful for founders and agents answering customer security reviews without leaking private repo data or making unsupported compliance claims. Use it as a security questionnaire answerer, SOC 2 evidence answer helper, or vendor due diligence response builder. |\n\n## How it works\n\n1. Agent calls a tool (e.g. `ai-content-detector`).\n2. MCP server POSTs to `https://x402.agentutility.ai/ai-content-detector`.\n3. The endpoint responds **HTTP 402** with payment instructions.\n4. The MCP server signs an EIP-3009 USDC transfer authorization with `X402_PRIVATE_KEY` and retries.\n5. CDP facilitator settles on Base.\n6. The endpoint returns the actual response.\n\nThe agent never sees the payment flow — it just gets the result.\n\n## Links\n\n- Cluster overview: https://agentutility.ai/prooflayer/\n- All MCP packages: https://mcp.agentutility.ai/\n- Source: https://github.com/rooz21/x402/tree/main/packages/mcp-prooflayer\n\n---\n\n**Version:** 0.3.3 · **License:** MIT\n","readmeFilename":"README.md"}