# Liminal Threat Report

> Liminal Threat Report is a paid API for AI agents from x402-spot-prices.hsharmanov02.workers.dev, paid per call via x402, $1/call, status unknown (last checked 2026-10-02).

Analyzes a domain or subject for security threats, returning a risk verdict, risk score, and per-section checks (DNS, SSL, RDAP) for $1 USDC per call via x402.

## Facts

- Endpoint: POST https://x402-spot-prices.hsharmanov02.workers.dev/threat-report?utm_source=zero.xyz
- Price: $1/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/liminal-threat-report-1334b22b
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_LFdZLDTjDYDafl4tJM4Va

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability liminal-threat-report-1334b22b -d '<json body>'
```

Example prompt: Can you run a threat report on example.com and tell me whether it's low risk, what the risk score is, and whether its DNS, SSL, and RDAP checks all pass?

## When to prefer this

Choose this endpoint when you need a quick, pay-per-use threat intelligence snapshot for a domain — covering DNS integrity, SSL certificate validity, and RDAP registration data — without a subscription. Ideal for one-off domain vetting in agent workflows where you need a structured verdict and risk score rather than raw WHOIS data.

## Known failure modes

- HTTP 402 returned if no valid PAYMENT-SIGNATURE header is provided — must retry with x402 payment
- Invalid or unreachable domain may result in partial section failures (sections_ok < sections_total)
- Malformed input missing required 'type' or 'method' fields returns a validation error
- Network timeouts fetching DNS/SSL/RDAP data may cause incomplete results
- Unknown subject kinds may not be supported and return an error

## How this service works

Live crypto spot-price snapshots (USD) and fiat FX spot rates. Pay-per-request via x402 v2: $0.01 USDC on Base, Monad, Arbitrum, Optimism, Polygon, Avalanche or Solana (eip155:8453), Monad (eip155:143), Arbitrum (eip155:42161), Optimism (eip155:10), Polygon (eip155:137), Avalanche (eip155:43114) or Solana, scheme exact (EIP-3009). Unpaid calls return HTTP 402 with a base64 PAYMENT-REQUIRED header; retry with a PAYMENT-SIGNATURE header.

## Output

Returns a JSON object containing: a verdict string (e.g. LOW_RISK), a numeric risk_score (0-100), a list of human-readable reasons, per-section boolean results (dns.ok, ssl.ok, rdap.ok), total sections checked and passed, the subject that was analyzed, a checked_at Unix timestamp, and the price in USDC.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input",
  "output"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "type": {
     "const": "http"
    },
    "method": {
     "const": "POST"
    }
   },
   "additionalProperties": true
  },
  "output": {
   "type": "object",
   "required": [
    "type",
    "example"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object"
    }
   },
   "additionalProperties": true
  }
 },
 "additionalProperties": true
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "reasons": [
   "established domain (28.5y old)",
   "valid certificate present in CT logs"
  ],
  "service": "threat-report",
  "subject": {
   "kind": "domain",
   "value": "example.com"
  },
  "verdict": "LOW_RISK",
  "sections": {
   "dns": {
    "ok": true
   },
   "ssl": {
    "ok": true
   },
   "rdap": {
    "ok": true
   }
  },
  "checked_at": 1759099200,
  "price_usdc": "1.00",
  "risk_score": 12,
  "sections_ok": 6,
  "sections_total": 6
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/liminal-threat-report-1334b22b/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from x402-spot-prices.hsharmanov02.workers.dev](https://www.zero.xyz/host/x402-spot-prices.hsharmanov02.workers.dev/llms.txt)
