# Delx Commerce XSS Signal Scan

> Delx Commerce XSS Signal Scan is a paid API for AI agents from commerce.delx.ai, paid per call via x402, $0.003/call, status unknown (last checked 2026-10-01).

Scans a text string for XSS (cross-site scripting) attack signals and returns a risk level and signal count

## Facts

- Endpoint: POST https://commerce.delx.ai/api/v1/x402/xss-signal-scan?utm_source=zero.xyz
- Price: $0.003/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/delx-commerce-xss-signal-scan-66109f9e
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_gqLv8Kmdpj4OZ2F4voVCQ

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability delx-commerce-xss-signal-scan-66109f9e -d '<json body>'
```

Example prompt: Can you scan this text for XSS attack signals and tell me the risk level: '<script>alert(document.cookie)</script>'?

## When to prefer this

Choose this endpoint when you need a fast, pay-per-use, no-signup XSS heuristic signal check on a specific text string, especially within an agentic pipeline that already handles x402 micropayments on Base or Solana. It is ideal for lightweight pre-validation gates rather than full WAF replacement. Prefer it over heavier security scanners when cost-per-call and zero-friction onboarding matter most.

## Known failure modes

- Missing or empty 'text' field returns a validation error
- Extremely long strings may be truncated or rejected
- Heuristic-only detection means false negatives are possible for obfuscated payloads
- False positives may occur on benign HTML-like content
- Payment failure via x402 results in 402 response before scan is executed

## How this service works

Pay-per-result APIs for agents. No signup. Exact price. Verifiable delivery. USDC on Base + Solana via x402.

## Output

Returns a JSON object with a risk field ('high', 'medium', or 'low'), a signal_count integer indicating how many XSS signals were found, a text_sha256 hash of the input for verifiability, a schema identifier, an advisory note recommending parameterization and contextual encoding, and a values_returned boolean indicating whether matched values are exposed in the response.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "text": {
   "type": "string",
   "description": "Input field: text."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "risk": "high",
  "schema": "delx/util-xss-signal-scan/v1",
  "advisory": "Heuristic only; use parameterization, contextual encoding, and allowlists.",
  "text_sha256": "5c140d35dcb46a622e2cedf5ef5cc3638cdffd1c118c9331f8c84669f0b74783",
  "signal_count": 1,
  "values_returned": false
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/delx-commerce-xss-signal-scan-66109f9e/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from commerce.delx.ai](https://www.zero.xyz/host/commerce.delx.ai/llms.txt)
