# Delx Commerce Path Safety Check

> Delx Commerce Path Safety Check is a paid API for AI agents from commerce.delx.ai, paid per call via x402, $0.003/call, status unknown (last checked 2026-10-01).

Analyzes a filesystem or URL path string for security risks such as traversal attacks, injection patterns, and unsafe characters, returning a risk level and signal count.

## Facts

- Endpoint: POST https://commerce.delx.ai/api/v1/x402/path-safety-check?utm_source=zero.xyz
- Price: $0.003/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/delx-commerce-path-safety-check-a2c4b3a5
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_soGu-a8VrdLzO2eyI0A_F

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability delx-commerce-path-safety-check-a2c4b3a5 -d '<json body>'
```

Example prompt: Can you run a path safety check on this user-supplied input: '../../../etc/passwd' — I want to know the risk level before I pass it to my file handler.

## When to prefer this

Choose this endpoint when an AI agent needs a fast, pay-per-call, no-signup heuristic check on a user-supplied path string before passing it to a file system, router, or backend — especially in agentic workflows where path traversal or injection risks are a concern and you want a verifiable, auditable result with a SHA-256 receipt. Prefer alternatives if you need a full WAF, deep static analysis, or compliance-grade security scanning.

## Known failure modes

- Missing or empty 'path' field returns an error response
- Extremely long path strings may be rejected
- Network or payment processing failures result in no response
- Path containing only whitespace may yield ambiguous results

## How this service works

Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.

## Output

Returns a JSON object with a 'risk' field (e.g. 'low', 'medium', 'high'), a 'signal_count' integer indicating how many suspicious patterns were detected, a 'values_returned' boolean, an 'advisory' string recommending best practices, a 'schema' identifier for the response format, and a 'text_sha256' hash of the analyzed path for auditability.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "path": {
   "type": "string",
   "description": "Input field: path."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "risk": "low",
  "schema": "delx/util-path-safety-check/v1",
  "advisory": "Heuristic only; use parameterization, contextual encoding, and allowlists.",
  "text_sha256": "873456cf6e41efa219c32b5b9c782135f2d5a425db8d703eaccc783982e0fa7b",
  "signal_count": 0,
  "values_returned": false
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/delx-commerce-path-safety-check-a2c4b3a5/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from commerce.delx.ai](https://www.zero.xyz/host/commerce.delx.ai/llms.txt)
