pr-verdict

One merge-safety verdict for a public GitHub pull request. Fetches the PR diff and runs it through code, secret, CI/CD pipeline and dependency scanners, returning a single verdict (pass, caution, block), a risk score and findings with severity, file, line and a fix hint. One call instead of slicing the diff into several. Security indicators, not a guarantee.

DataLiveeip155:8453Exactvia cdp
GithubPull-requestCode-reviewSecurityMerge
Calls · 30d
1→ 0%
This endpoint's own trailing-30-day call count, as published by the upstream catalog and snapshotted daily. 14 snapshots so far.
$42.97
Verified settled volume
3,793 settlements proven x402 by their on-chain EIP-3009 marker.
$0.030
Listed price
As published in the catalog. Always read the live 402 before paying.
1
Calls · 30d
Upstream's own call count for this endpoint, not ours.
1
Unique payers · 30d
Last called 2026-09-10 15:39Z
Upstream on-chain volume
Reported by the source catalog.
Paid to
0xF22e558a00D91Ee12A1F50C52186FecB8dDFf493

The wallet the 402 directs payment to. Its whole payment record — every payer, every chain — is on the merchant page.

Asset 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913

Provider

The payTo wallet does not resolve to a registered ERC-8004 agent. That is not a verdict on the service — most of the catalog is unregistered.

Accepts

The payment requirements as published to the catalog. Read the live 402 before paying — a price here is a claim, not a quote.

0.03USDC≈ $0.03 USD
on Base · exact scheme

Pay 0.03 USDC on Base to 0xF22e…Ff493. The signed payment is good for 5 minutes.

USD Coin contract
0x8335…02913
Payment window
5 minutes
As published
30000 smallest units
The catalog’s raw entry
[
  {
    "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
    "extra": {
      "name": "USD Coin",
      "version": "2"
    },
    "payTo": "0xF22e558a00D91Ee12A1F50C52186FecB8dDFf493",
    "amount": "30000",
    "scheme": "exact",
    "network": "eip155:8453",
    "maxTimeoutSeconds": 300
  }
]

Extensions

{
  "bazaar": {
    "info": {
      "input": {
        "body": {
          "pr_url": "https://github.com/gitpython-developers/GitPython/pull/1901"
        },
        "type": "http",
        "method": "POST",
        "bodyType": "json"
      },
      "output": {
        "type": "json",
        "example": {
          "pr": {
            "repo": "widget",
            "owner": "acme",
            "title": "Add uploader",
            "number": 42,
            "head_sha": "d34db33f…"
          },
          "object": "pr_verdict",
          "verdict": "block",
          "coverage": {
            "source": "diff",
            "truncated": false,
            "files_total": 6,
            "files_scanned": 6,
            "skipped_files": [],
            "dimensions_run": [
              "code",
              "secret",
              "ci"
            ],
            "graph_rules_ran": true,
            "dimensions_partial": []
          },
          "findings": [
            {
              "line": 12,
              "path": "src/upload.py",
              "reason": "A hardcoded AWS access key appears in an added line.",
              "rule_id": "aws.akia",
              "evidence": "AWS_KEY = \"AKIA…4E7Q\"",
              "fix_hint": "Remove the hardcoded AWS credential, rotate it, and load it from a secret manager / environment variable.",
              "provider": "secretscan",
              "severity": "high",
              "dimension": "secret"
            },
            {
              "line": null,
              "path": ".github/workflows/ci.yml",
              "reason": "Third-party action pinned to a mutable tag, not a commit SHA.",
              "rule_id": "gha.unpinned_uses",
              "evidence": "uses: actions/checkout@v4",
              "fix_hint": "Pin to the full 40-char commit SHA.",
              "provider": "cicdscan",
              "severity": "high",
              "dimension": "ci"
            }
          ],
          "disclaimer": "Automated merge-risk indicators — security signals, not a guarantee.",
          "risk_score": 80,
          "ruleset_versions": {
            "ci": "2026.07.24",
            "code": "2026.07.16",
            "secret": "2026.07.16"
          },
          "counts_by_severity": {
            "high": 2,
            "medium": 1
          },
          "findings_truncated": false,
          "counts_by_dimension": {
            "ci": 1,
            "code": 1,
            "secret": 1
          }
        }
      }
    },
    "schema": {
      "type": "object",
      "$schema": "https://json-schema.org/draft/2020-12/schema",
      "required": [
        "input"
      ],
      "properties": {
        "input": {
          "type": "object",
          "required": [
            "type",
            "method",
            "bodyType",
            "body"
          ],
          "properties": {
            "body": {
              "required": [
                "pr_url"
              ],
              "properties": {
                "pr_url": {
                  "type": "string",
                  "description": "Public GitHub pull-request URL (github.com/owner/repo/pull/N)"
                },
                "max_files": {
                  "type": "integer",
                  "description": "Optional cap on files scanned for a large PR"
                },
                "dimensions": {
                  "type": "array",
                  "items": {
                    "type": "string"
                  },
                  "description": "Optional subset of code, secret, ci, deps (default: all)"
                }
              }
            },
            "type": {
              "type": "string",
              "const": "http"
            },
            "method": {
              "enum": [
                "POST",
                "PUT",
                "PATCH"
              ],
              "type": "string"
            },
            "bodyType": {
              "enum": [
                "json",
                "form-data",
                "text"
              ],
              "type": "string"
            }
          },
          "additionalProperties": false
        },
        "output": {
          "type": "object",
          "required": [
            "type"
          ],
          "properties": {
            "type": {
              "type": "string"
            },
            "example": {
              "type": "object"
            }
          }
        }
      }
    }
  }
}

Provenance

Seen in the source catalog
2026-09-10 15:39Z
Last indexed by Roundhouse
2026-09-24 13:00Z
Last enriched (probe, favicon, geo)
2026-09-10 16:15Z
x402 version
2
Max timeout
300s
Liveness probe
HTTP 405
Report

Hand this page to an agent

Copy the prompt and paste it into Claude, an MCP client or your own agent — it will vet this service and call it over the free read API. No key, no account.

GET api.roundhouseai.io/v0/endpoints

This endpoint's own trailing-30-day call count, as published by the upstream catalog and snapshotted daily. 14 snapshots so far. Verified volume counts only settlements with an on-chain EIP-3009 marker.

Open skill.md
Show the prompt
Using Roundhouse, look up the x402 service pr-verdict and tell me whether it is
worth paying: what a call costs, whether the endpoint answered when last probed, and what
its payment record actually shows.

curl -s 'https://api.roundhouseai.io/v0/endpoints?q=pr-verdict'
curl -s 'https://api.roundhouseai.io/v0/merchants/<the payTo wallet returned above>'

Then call it: read the price from the live 402 at https://api.agentstools.dev/pr/verdict, never from
a cached figure, and pay with an x402 client.

The /v0 API needs an API key (`authorization: Bearer rh_live_…`) on everything except
/v0/unified* and /v0/endpoints. Mint a personal key for $0.01 at GET https://api.roundhouseai.io/v0/test/x402,
or use an organization key from https://roundhouseai.io/dashboard/team.

If you do not have Roundhouse tools or skills installed, read
https://roundhouseai.io/skill.md first — it is the whole procedure.