# Settled Bounty/Task URL Safety Scanner

> Settled Bounty/Task URL Safety Scanner is a paid API for AI agents from settled.tools, paid per call via x402, $0.005/call, status unknown (last checked 2026-10-02).

Scans a bounty, task, or repository URL for honeypot patterns and prompt injection risks, returning a trust score, label, and detailed flags with reasons.

## Facts

- Endpoint: GET https://settled.tools/v1/income/check?utm_source=zero.xyz
- Price: $0.005/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/settled-bounty-task-url-safety-scanner-add0b2cb
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_B7l37scoxnI1eDBiQUNR4

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability settled-bounty-task-url-safety-scanner-add0b2cb
```

Example prompt: Before I start working on this bounty, can you scan https://github.com/some-org/some-repo/issues/42 for honeypot patterns, prompt injection tricks, or anything suspicious, and give me its trust score?

## When to prefer this

Use this endpoint when an AI agent or human developer needs to vet a bounty, task, or repository URL for safety before investing effort — especially in adversarial or open internet contexts where prompt injection, honeypots, or credential phishing are risks. Prefer this over manual inspection when automating agent workflows that process untrusted external task listings or GitHub issues.

## Known failure modes

- Invalid or non-HTTPS URL returns an error
- Private or access-restricted GitHub repos may return incomplete data
- Rate limiting if many scans are made in rapid succession
- Dead links or 404 URLs may return a partial result or error
- GitHub API rate limits could affect freshness of data for repo/issue fetches

## How this service works

Scan one bounty / task / repository URL before working on it: fetches it (GitHub issues and repos via the API), runs the honeypot pattern scan (hidden HTML-comment instructions, prompt injection, credential requests, fork/star anomalies, dead or archived repos, reward anomalies) and returns a trust score, a label and every flag with its reason.

## Output

Returns a structured response containing a numeric trust score (0–1 or similar scale), a human-readable trust label (e.g. 'safe', 'suspicious', 'honeypot'), and a list of flags each with a category and reason — covering honeypot HTML comments, prompt injection attempts, credential requests, fork/star anomalies, dead/archived repo status, and reward anomalies.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET"
     ],
     "type": "string"
    },
    "queryParams": {
     "type": "object",
     "required": [
      "url"
     ],
     "properties": {
      "url": {
       "type": "string",
       "description": "https URL of a bounty issue, repository, or listing page"
      }
     }
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object"
    }
   }
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "url": "https://github.com/owner/repo/issues/123",
  "repo": {
   "forks": 40,
   "stars": 3
  },
  "flags": [
   {
    "flag": "hidden_instructions",
    "reason": "HTML comment (invisible to humans) contains instructions aimed at an AI agent or asks for secrets"
   }
  ],
  "label": "suspected_honeypot",
  "trust": 12
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/settled-bounty-task-url-safety-scanner-add0b2cb/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from settled.tools](https://www.zero.xyz/host/settled.tools/llms.txt)
