# token-security-scan

> token-security-scan is a paid API for AI agents from chain.intel.rallylive.ca, paid per call via x402, $0.02/call, status unknown (last checked 2026-10-02).

Performs a comprehensive multi-source smart-contract security scan of an ERC-20 token on Base (or other EVM chains), checking for honeypots, taxes, malicious traits, and market listings.

## Facts

- Endpoint: GET https://chain.intel.rallylive.ca/token/security?utm_source=zero.xyz
- Price: $0.02/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/token-security-scan-3c131a58
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_IcoE-oCCOjSgkSvETPfu7

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability token-security-scan-3c131a58
```

Example prompt: Can you run a full security scan on this Base token at 0x4ed4E862860beD51a9570b96d89aF5E1B0Efefed — I want to know if it's a honeypot, what the buy/sell taxes are, whether the contract is mintable or has a hidden owner, and if the creator has launched honeypots before?

## When to prefer this

Choose this endpoint when you need a comprehensive, multi-source security audit of an ERC-20 token before trading or listing — it merges GoPlus and honeypot.is data in a single call and covers more risk vectors (creator history, taxes, proxy, blacklist, CEX/DEX) than any single-source honeypot checker. Prefer it over chain-specific honeypot-check endpoints when you need the full security picture or are scanning on Base, Ethereum, Arbitrum, Optimism, or Polygon.

## Known failure modes

- Invalid or non-existent contract address returns an error or empty result
- Unsupported chain prefix causes a lookup failure
- Token not yet indexed by GoPlus or honeypot.is returns incomplete data
- Network timeout on simulation for very new or low-liquidity tokens
- Malformed chain prefix syntax results in a bad request error

## How this service works

Full smart-contract security scan of an ERC-20 token: honeypot, buy/sell/transfer tax, mintable, proxy, hidden owner, self-destruct, pausable, blacklist/whitelist, tax-modifiable, owner and creator share, creator's past honeypots, CEX/DEX listings. GoPlus + honeypot.is simulation merged in one JSON. Default chain Base; prefix another: ethereum:, arbitrum:, optimism:, polygon:, bsc:. $0.02 per call.

## Output

A merged JSON object from GoPlus and honeypot.is containing: honeypot simulation result (is_honeypot), buy/sell/transfer taxes, mintable/proxy/hidden-owner/self-destruct/pausable flags, blacklist and whitelist presence, tax-modifiability, owner and creator token share percentages, number of past honeypots by the creator address, and CEX/DEX listing status.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET"
     ],
     "type": "string"
    },
    "queryParams": {
     "type": "object",
     "properties": {}
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object"
    }
   }
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/token-security-scan-3c131a58/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from chain.intel.rallylive.ca](https://www.zero.xyz/host/chain.intel.rallylive.ca/llms.txt)
