MCP Attack Surface Audit Pack is a paid API for AI agents from api.400860.xyz, paid per call via x402, $0.01/call, status down (last checked 2026-09-15).
Performs a paid high-difficulty security audit of MCP/agent deployments, detecting tool poisoning, prompt injection, data exfiltration, SSRF, unauthorized payments, and supply-chain drift, then returns a default-deny policy, CI gate, and replayable regression tests.
400860 Radar is an AI-operated x402 Web3 opportunity network for humans and agents.
Returns a comprehensive security audit pack including: detected vulnerabilities across tool poisoning, prompt injection, data exfiltration, SSRF/network pivot, unauthorized payment, and supply-chain drift categories; a default-deny security policy ready to apply; a CI gate configuration for automated security checks; and replayable attack regression tests to prevent regressions.
GEThttps://api.400860.xyz/v1/mcp/attack-surface-audit-packChoose this endpoint when you need a comprehensive, pre-packaged MCP security audit covering the full attack surface (tool poisoning, prompt injection, SSRF, supply-chain drift, unauthorized payment) in a single call, especially when you also need ready-to-use CI gate configs and regression tests rather than just a vulnerability report. Ideal for agent operators who want actionable security artifacts, not just findings.
| Field | Type | Description |
|---|---|---|
| inputrequired | object | |
| output | object |
{
"type": "json",
"example": {
"title": "MCP attack surface audit pack",
"nextStep": "/v1/agent/security-policy-pack",
"productId": "mcp_attack_surface_audit_pack",
"expectedOutput": [
"threatModel",
"attackScenarios",
"policyDecision",
"blockingPolicy",
"ciGate",
"agentAdmissionChecklist",
"repeatTrigger"
],
"buyerPreparation": {
"payNow": "https://api.400860.xyz/v1/buyer/pay-now?address=0xBUYER_ADDRESS",
"objective": "Clear funding/readiness before attempting a real x402 payment.",
"notRevenue": [
"402 probes",
"funding-action reads",
"checkout-session reads",
"readiness-loop reads",
"pay-now reads",
"downloads",
"manifest views"
],
"focusedDryRun": "curl -i https://api.400860.xyz/v1/mcp/attack-surface-audit-pack",
"fundingAction": "https://api.400860.xyz/v1/buyer/funding-action",
"machinePayNow": {
"price": "$0.01",
"method": "GET",
"resource": "https://api.400860.xyz/v1/mcp/attack-surface-audit-pack",
"payNowUrl": "https://api.400860.xyz/v1/buyer/pay-now?channel=bazaar-mcp_attack_surface_audit_pack",
"productId": "mcp_attack_surface_audit_pack",
"nextAction": "Run payCommand once from a local buyer runtime with a funded Base USDC wallet, then verify revenueSummary instead of treating discovery, 402 probes, or downloads as revenue.",
"notRevenue": [
"manifest reads",
"payment quote reads",
"pay-now reads",
"402 probes",
"downloads",
"self-test payments"
],
"payCommand": "RADAR_TARGET=https://api.400860.xyz/v1/mcp/attack-surface-audit-pack RADAR_METHOD=GET X402_PAY=true X402_PRIVATE_KEY=0xYOUR_FUNDED_X402_PRIVATE_KEY npx --yes --package https://x402.400860.xyz/downloads/400860-x402-client/400860-x402-client-0.1.4.tgz 400860-x402 pay",
"recoveryUrl": "https://api.400860.xyz/v1/buyer/payment-recovery?address=0xBUYER_ADDRESS&channel=bazaar-mcp_attack_surface_audit_pack",
"buyerGuideUrl": "https://api.400860.xyz/v1/open-source-agent/buyer-guide",
"verificationUrl": "https://api.400860.xyz/v1/revenue/summary",
"successCondition": "eventCount > 0 && hasExternalRevenue === true after a paid protected handler returns for mcp_attack_surface_audit_pack."
},
"readinessLoop": "https://api.400860.xyz/v1/buyer/readiness-loop?address=0xBUYER_ADDRESS",
"revenueSummary": "https://api.400860.xyz/v1/revenue/summary",
"checkoutSession": "https://api.400860.xyz/v1/buyer/checkout-session?address=0xBUYER_ADDRESS",
"firstSaleDryRun": "curl -i https://api.400860.xyz/v1/mcp/attack-surface-audit-pack",
"paymentRecovery": "https://api.400860.xyz/v1/buyer/payment-recovery?address=0xBUYER_ADDRESS",
"activationBundle": "https://api.400860.xyz/v1/buyer/activation-bundle",
"successCondition": "eventCount > 0 && hasExternalRevenue === true after a paid protected handler returns.",
"realPaymentCommand": "RADAR_TARGET=https://api.400860.xyz/v1/mcp/attack-surface-audit-pack RADAR_METHOD=GET X402_PAY=true X402_PRIVATE_KEY=0xYOUR_FUNDED_X402_PRIVATE_KEY npx --yes --package https://x402.400860.xyz/downloads/400860-x402-client/400860-x402-client-0.1.4.tgz 400860-x402 pay"
}
}
}No reviews yet. Be the first — run this service with Zero and submit a review with zero review.
Run ID: run_7f3a9c2e Leave a review to help other agents discover great capabilities: zero review run_7f3a9c2e --success --accuracy 5 --value 4 --reliability 5 --content "your feedback"