Pocket Network
Scan a dependency manifest for known-vulnerable and confirmed-malicious packages. POST /v1/scan with a raw lockfile or a components array and get per-dependency verdicts (malicious, vulnerable, suspicious, clean) from OSV.dev and the OpenSSF Malicious Packages feed, each with a summary and snapshot timestamp. Pay per request in USDC; no account, no API key.
The wallet the 402 directs payment to. Its whole payment record — every payer, every chain — is on the merchant page.
Asset 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
The payTo wallet does not resolve to a registered ERC-8004 agent. That is not a verdict on the service — most of the catalog is unregistered.
Live 402 challenge
Captured by the enrichment pass, not read just now. Prices can change — always read the 402 the endpoint answers with.
{
"accepts": [
{
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"extra": {
"name": "USD Coin",
"version": "2"
},
"payTo": "0xF732ea490c5766071785a2310523f7fA2CEbB829",
"amount": "5000",
"scheme": "exact",
"network": "eip155:8453",
"maxTimeoutSeconds": 60
}
],
"resource": {
"url": "https://agent.pocket.network/v1/taint-check",
"tags": [
"security",
"taint-check",
"rest"
],
"iconUrl": "https://pocket.network/wp-content/uploads/2026/09/Pocket-Icon.png",
"mimeType": "application/json",
"description": "Scan a dependency manifest for known-vulnerable and confirmed-malicious packages. POST /v1/scan with a raw lockfile or a components array and get per-dependency verdicts (malicious, vulnerable, suspicious, clean) from OSV.dev and the OpenSSF Malicious Packages feed, each with a summary and snapshot timestamp. Pay per request in USDC; no account, no API key.",
"serviceName": "Pocket Network"
},
"extensions": {
"bazaar": {
"info": {
"input": {
"body": {},
"type": "http",
"method": "POST",
"bodyType": "json"
},
"output": {
"type": "json",
"example": {
"data": {},
"portal": {
"serviceId": "taint-check",
"provenance": "third-party-supplier",
"schemaCheck": "passed"
}
}
}
},
"schema": {
"type": "object",
"$schema": "https://json-schema.org/draft/2020-12/schema",
"required": [
"input"
],
"properties": {
"input": {
"type": "object",
"required": [
"type",
"method",
"bodyType",
"body"
],
"properties": {
"body": {
"type": "object",
"required": [],
"properties": {
"options": {
"type": "object",
"properties": {
"since": {
"type": "string",
"description": "Only advisories newer than this timestamp (monitor mode)."
},
"heuristics": {
"type": "boolean",
"description": "Add typosquat, install-script and dormancy signals."
}
},
"description": "Scan options."
},
"lockfile": {
"type": "object",
"properties": {
"format": {
"enum": [
"package-lock.json",
"pnpm-lock.yaml",
"yarn.lock",
"requirements.txt",
"poetry.lock",
"uv.lock",
"Pipfile.lock",
"Cargo.lock",
"go.sum"
],
"type": "string",
"description": "Lockfile format."
},
"content": {
"type": "string",
"description": "Raw lockfile content."
}
},
"description": "A raw lockfile."
},
"components": {
"type": "array",
"items": {
"type": "object",
"properties": {
"name": {
"type": "string",
"description": "Package name."
},
"version": {
"type": "string",
"description": "Package version."
},
"ecosystem": {
"type": "string",
"description": "e.g. npm, pypi, go, cargo."
}
}
},
"description": "Pre-parsed dependencies."
}
},
"description": "Provide either a raw lockfile or a pre-parsed components array; body size and component limits come from GET /v1/capabilities."
},
"type": {
"type": "string",
"const": "http"
},
"method": {
"enum": [
"POST",
"PUT",
"PATCH"
],
"type": "string"
},
"bodyType": {
"enum": [
"json",
"form-data",
"text"
],
"type": "string"
}
},
"additionalProperties": false
},
"output": {
"type": "object",
"required": [
"type"
],
"properties": {
"type": {
"type": "string"
},
"example": {
"type": "object",
"required": [
"portal",
"data"
],
"properties": {
"data": {
"type": "object",
"description": "For POST /v1/scan, a JSON object with a `findings` array — each dependency's verdict (malicious, vulnerable, suspicious, clean), a summary, and a data_as_of timestamp. Findings vary by each supplier's snapshot freshness and converge as mirrors sync. The exact shape is the service's own and is not pinned here; errors return a JSON object with an `error` field, and the GET routes return their own small JSON documents."
},
"portal": {
"type": "object",
"required": [
"provenance",
"serviceId",
"schemaCheck"
],
"properties": {
"serviceId": {
"const": "taint-check"
},
"provenance": {
"const": "third-party-supplier"
},
"schemaCheck": {
"enum": [
"passed",
"undeclared",
"unchecked"
]
}
}
}
}
}
}
}
}
}
}
},
"x402Version": 2
}Accepts
The payment requirements as published to the catalog. Read the live 402 before paying — a price here is a claim, not a quote.
Pay 0.005 USDC on Base to 0xF732…bB829. The signed payment is good for 1 minute.
- Paid to
- 0xF732…bB829
- USD Coin contract
- 0x8335…02913
- Payment window
- 1 minute
- As published
- 5000 smallest units
The catalog’s raw entry
[
{
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"extra": {
"name": "USD Coin",
"version": "2"
},
"payTo": "0xF732ea490c5766071785a2310523f7fA2CEbB829",
"amount": "5000",
"scheme": "exact",
"network": "eip155:8453",
"maxTimeoutSeconds": 60
}
]Extensions
{
"bazaar": {
"info": {
"input": {
"body": {
"options": {
"heuristics": false
},
"components": [
{
"name": "minimist",
"version": "1.2.0",
"ecosystem": "npm"
}
]
},
"type": "http",
"method": "POST",
"bodyType": "json"
},
"output": {
"type": "json",
"example": {
"data": {},
"portal": {
"serviceId": "taint-check",
"provenance": "third-party-supplier",
"schemaCheck": "passed"
}
}
}
},
"schema": {
"type": "object",
"$schema": "https://json-schema.org/draft/2020-12/schema",
"required": [
"input"
],
"properties": {
"input": {
"type": "object",
"required": [
"type",
"method",
"bodyType",
"body"
],
"properties": {
"body": {
"type": "object",
"required": [],
"properties": {
"options": {
"type": "object",
"properties": {
"since": {
"type": "string",
"description": "Only advisories newer than this timestamp (monitor mode)."
},
"heuristics": {
"type": "boolean",
"description": "Add typosquat, install-script and dormancy signals."
}
},
"description": "Scan options."
},
"lockfile": {
"type": "object",
"properties": {
"format": {
"enum": [
"package-lock.json",
"pnpm-lock.yaml",
"yarn.lock",
"requirements.txt",
"poetry.lock",
"uv.lock",
"Pipfile.lock",
"Cargo.lock",
"go.sum"
],
"type": "string",
"description": "Lockfile format."
},
"content": {
"type": "string",
"description": "Raw lockfile content."
}
},
"description": "A raw lockfile."
},
"components": {
"type": "array",
"items": {
"type": "object",
"properties": {
"name": {
"type": "string",
"description": "Package name."
},
"version": {
"type": "string",
"description": "Package version."
},
"ecosystem": {
"type": "string",
"description": "e.g. npm, pypi, go, cargo."
}
}
},
"description": "Pre-parsed dependencies."
}
},
"description": "Provide either a raw lockfile or a pre-parsed components array; body size and component limits come from GET /v1/capabilities."
},
"type": {
"type": "string",
"const": "http"
},
"method": {
"enum": [
"POST",
"PUT",
"PATCH"
],
"type": "string"
},
"bodyType": {
"enum": [
"json",
"form-data",
"text"
],
"type": "string"
}
},
"additionalProperties": false
},
"output": {
"type": "object",
"required": [
"type"
],
"properties": {
"type": {
"type": "string"
},
"example": {
"type": "object",
"required": [
"portal",
"data"
],
"properties": {
"data": {
"type": "object",
"description": "For POST /v1/scan, a JSON object with a `findings` array — each dependency's verdict (malicious, vulnerable, suspicious, clean), a summary, and a data_as_of timestamp. Findings vary by each supplier's snapshot freshness and converge as mirrors sync. The exact shape is the service's own and is not pinned here; errors return a JSON object with an `error` field, and the GET routes return their own small JSON documents."
},
"portal": {
"type": "object",
"required": [
"provenance",
"serviceId",
"schemaCheck"
],
"properties": {
"serviceId": {
"const": "taint-check"
},
"provenance": {
"const": "third-party-supplier"
},
"schemaCheck": {
"enum": [
"passed",
"undeclared",
"unchecked"
]
}
}
}
}
}
}
}
}
}
}
}Provenance
- Seen in the source catalog
- 2026-09-24 04:30Z
- Last indexed by Roundhouse
- 2026-09-24 08:00Z
- Last enriched (probe, favicon, geo)
- 2026-09-21 13:45Z
- x402 version
- 2
- Max timeout
- 60s
- Liveness probe
- HTTP 402
Hand this page to an agent
Copy the prompt and paste it into Claude, an MCP client or your own agent — it will vet this service and call it over the free read API. No key, no account.
GET api.roundhouseai.io/v0/endpoints
This endpoint's own trailing-30-day call count, as published by the upstream catalog and snapshotted daily. 3 snapshots so far. Verified volume counts only settlements with an on-chain EIP-3009 marker.
Show the promptHide the prompt
Using Roundhouse, look up the x402 service Pocket Network and tell me whether it is worth paying: what a call costs, whether the endpoint answered when last probed, and what its payment record actually shows. curl -s 'https://api.roundhouseai.io/v0/endpoints?q=Pocket%20Network' curl -s 'https://api.roundhouseai.io/v0/merchants/<the payTo wallet returned above>' Then call it: read the price from the live 402 at https://agent.pocket.network/v1/taint-check, never from a cached figure, and pay with an x402 client. The /v0 API needs an API key (`authorization: Bearer rh_live_…`) on everything except /v0/unified* and /v0/endpoints. Mint a personal key for $0.01 at GET https://api.roundhouseai.io/v0/test/x402, or use an organization key from https://roundhouseai.io/dashboard/team. If you do not have Roundhouse tools or skills installed, read https://roundhouseai.io/skill.md first — it is the whole procedure.