# Delx Commerce SQL Injection Scan

> Delx Commerce SQL Injection Scan is a paid API for AI agents from commerce.delx.ai, paid per call via x402, $0.003/call, status unknown (last checked 2026-10-01).

Scans a text string for SQL injection patterns and returns a risk level with heuristic signal analysis

## Facts

- Endpoint: POST https://commerce.delx.ai/api/v1/x402/sql-injection-scan?utm_source=zero.xyz
- Price: $0.003/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/delx-commerce-sql-injection-scan-432f4c3c
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_UpGuOjVcXpgNxN2x6-JnR

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability delx-commerce-sql-injection-scan-432f4c3c -d '<json body>'
```

Example prompt: Check this user-submitted input for SQL injection risk: "1' OR '1'='1'; DROP TABLE users;" — I need to know if it's high, medium, or low risk before I pass it to my database query.

## When to prefer this

Choose this endpoint when you need a fast, stateless, pay-per-use SQL injection pre-screen with no API key signup — especially in agentic pipelines where you want cryptographically verifiable delivery (SHA-256 audit trail) and USDC micropayment billing. Prefer this over full WAF solutions when you need lightweight, per-request heuristic scanning without infrastructure overhead.

## Known failure modes

- Missing or empty 'text' field returns an error
- Very long inputs may hit payload size limits
- Heuristic-only detection — may miss novel or obfuscated injection patterns
- False positives on legitimate SQL-like syntax in non-database contexts
- Payment failure via x402 results in 402 response before scan is performed

## How this service works

Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.

## Output

Returns a JSON object with a 'risk' field (e.g. 'high', 'medium', 'low'), a 'signal_count' integer indicating how many injection indicators were found, a 'values_returned' boolean indicating whether the pattern attempted data exfiltration, a SHA-256 hash of the input text for auditability, and a human-readable advisory recommending parameterization and allowlists.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "text": {
   "type": "string",
   "description": "Input field: text."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "risk": "high",
  "schema": "delx/util-sql-injection-scan/v1",
  "advisory": "Heuristic only; use parameterization, contextual encoding, and allowlists.",
  "text_sha256": "ca73936c7f13f709163098de9eeba474c05ba16cc18a4c7212b839ba3ea78a18",
  "signal_count": 2,
  "values_returned": false
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/delx-commerce-sql-injection-scan-432f4c3c/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from commerce.delx.ai](https://www.zero.xyz/host/commerce.delx.ai/llms.txt)
