# Services from atq6wtkp6k.execute-api.us-east-1.amazonaws.com on Zero

> atq6wtkp6k.execute-api.us-east-1.amazonaws.com serves 25 paid API services for AI agents, indexed by Zero. Each is callable per call with payment handled by Zero.

Canonical page: https://www.zero.xyz/host/atq6wtkp6k.execute-api.us-east-1.amazonaws.com
Live health (JSON, refreshed every minute): https://www.zero.xyz/host/atq6wtkp6k.execute-api.us-east-1.amazonaws.com/health.json

## Services

- [Domain Cyberattack Target Risk Scorer](https://www.zero.xyz/c/domain-cyberattack-target-risk-scorer-0fc873c9/llms.txt): $0.5/call via x402. Scores a domain's probability of being an active or upcoming cyberattack target using a 6-signal correlation model covering breach, infostealer, ransomware, session, CVE, and threat-actor targeting history.
- [Supply Chain Vendor Risk Batch Assessment](https://www.zero.xyz/c/supply-chain-vendor-risk-batch-assessment-5f56eda1/llms.txt): $0.1/call via x402. Checks up to 10 vendor domains simultaneously for combined breach, infostealer, and dark-web exposure, returning a composite risk score per vendor.
- [Ransomware Risk Check](https://www.zero.xyz/c/ransomware-risk-check-8533ca45/llms.txt): $0.4/call via x402. Checks whether a domain appears on a ransomware group's victim or leak-site list and whether pre-ransomware credential harvesting was detected beforehand.
- [GitHub/GitLab Secret Scanner](https://www.zero.xyz/c/github-gitlab-secret-scanner-997369c2/llms.txt): $0.35/call via x402. Scans public GitHub/GitLab repositories associated with a domain to detect exposed API keys, tokens, and credentials committed in source code.
- [RelayShield SIM Swap Check](https://www.zero.xyz/c/relayshield-sim-swap-check-62704794/llms.txt): $0.25/call via x402. Checks whether a given phone number has recently had its SIM swapped, returning the carrier, swap status, and timestamp of the swap event.
- [Batch Wallet Address Risk Screener](https://www.zero.xyz/c/batch-wallet-address-risk-screener-c13fec51/llms.txt): $0.5/call via x402. Screen up to 10 wallet addresses across EVM, Solana, TON, or Bitcoin chains in one call for known scam, exploit, drainer, or sanctions association, returning per-address risk level and flags.
- [Tech Stack CVE Risk Checker (CISA KEV & EPSS)](https://www.zero.xyz/c/tech-stack-cve-risk-checker-cisa-kev-epss-5cdd5495/llms.txt): $0.2/call via x402. Checks a declared technology stack against actively-exploited CVEs from CISA's Known Exploited Vulnerabilities (KEV) catalog and high-EPSS-score vulnerabilities to surface critical security risks.
- [Domain Phishing Lookalike Scanner](https://www.zero.xyz/c/domain-phishing-lookalike-scanner-596bb5c3/llms.txt): $0.5/call via x402. Scans a domain for typosquats, homoglyphs, and phishing lookalike registrations that may be impersonating a brand.
- [MCP Server Registry Risk Assessor](https://www.zero.xyz/c/mcp-server-registry-risk-assessor-1c16ce1e/llms.txt): $0.35/call via x402. Assesses a given MCP server URL for supply-chain and registry risk, flagging unverified publishers, known-malicious servers, and other trust signals before an agent connects.
- [OAuth Watchlist - Email OAuth App Exposure Checker](https://www.zero.xyz/c/oauth-watchlist-email-oauth-app-exposure-checker-eea7ebe2/llms.txt): $0.3/call via x402. Checks whether an email address has OAuth-connected app credentials exposed in known SaaS breaches across GitHub, Slack, Notion, Zapier, and 30+ other high-risk OAuth-capable apps, returning matched apps and direct revoke-access links.
- [RelayShield Scan Wallet Check](https://www.zero.xyz/c/relayshield-scan-wallet-check-310f82f8/llms.txt): $0.1/call via x402. Scans a blockchain wallet address for risk flags and returns a risk level assessment (e.g. LOW/MEDIUM/HIGH) along with detailed risk indicators.
- [RelayShield Identity Risk Score](https://www.zero.xyz/c/relayshield-identity-risk-score-abd7d532/llms.txt): $0.35/call via x402. Returns a graded identity risk score for a domain, covering breach exposure, CVE exposure, infostealer density, ransomware exposure, session exposure, and threat actor targeting dimensions.
- [RelayShield Token Security Check](https://www.zero.xyz/c/relayshield-token-security-check-7c4b00d7/llms.txt): $0.05/call via x402. Analyzes a crypto token's smart contract for security risks including honeypots, mintable supply, and other critical or warning flags.
- [Session Risk / Stolen Session Cookie Check by Email](https://www.zero.xyz/c/session-risk-stolen-session-cookie-check-by-email-4a53cd6d/llms.txt): $0.3/call via x402. Checks whether an email address has an active stolen session cookie circulating in a criminal archive, signaling an account takeover via AiTM/session-hijacking attack.
- [LLM Credential Exposure Check](https://www.zero.xyz/c/llm-credential-exposure-check-d34effb0/llms.txt): $0.4/call via x402. Checks whether a domain's AI/LLM provider API keys (OpenAI, Anthropic, Google, Groq, xAI, Replicate) have been harvested by infostealer malware and exposed in criminal stealer logs.
- [Bulk Identity Risk Scorer (Enterprise)](https://www.zero.xyz/c/bulk-identity-risk-scorer-enterprise-64861519/llms.txt): $2/call via x402. Score up to 10 organizational domains with up to 5 agent/employee emails each for combined breach, infostealer, session, and CVE risk in a single API call.
- [Identity Graph - Email-to-Breach Correlation](https://www.zero.xyz/c/identity-graph-email-to-breach-correlation-c11d8a11/llms.txt): $0.35/call via x402. Correlates an email address against criminal breach and infostealer corpora to surface linked phone numbers, domains, and other identifiers tied to the same compromised identity.
- [NHI API Key & Token Exposure Check](https://www.zero.xyz/c/nhi-api-key-token-exposure-check-5eadbc1c/llms.txt): $0.4/call via x402. Checks whether API keys or tokens associated with a domain — used by non-human identities such as AI agents, service accounts, or CI/CD pipelines — have been exposed in criminal infostealer logs.
- [RelayShield NFT Security Check](https://www.zero.xyz/c/relayshield-nft-security-check-11b2cf8d/llms.txt): $0.1/call via x402. Analyzes an NFT contract for security risks, returning risk level, risk flags, and collection metadata for a given contract address and chain.
- [RelayShield Infostealer Check](https://www.zero.xyz/c/relayshield-infostealer-check-45e0e787/llms.txt): $0.15/call via x402. Checks whether a given email address has been found in infostealer malware logs or credential theft datasets
- [RelayShield Wallet Risk Check](https://www.zero.xyz/c/relayshield-wallet-risk-check-95595835/llms.txt): $0.05/call via x402. Assesses the risk level of an EVM wallet address, returning risk flags and a risk level classification (e.g. LOW, MEDIUM, HIGH).
- [RelayShield Scan File Check](https://www.zero.xyz/c/relayshield-scan-file-check-77916d34/llms.txt): $0.1/call via x402. Submits a file URL for asynchronous security scanning and returns an analysis ID to poll for results
- [RelayShield Breach Check](https://www.zero.xyz/c/relayshield-breach-check-9a56a40e/llms.txt): $0.1/call via x402. Checks whether an email address has appeared in known data breaches, returning breach details and count
- [RelayShield URL Scan](https://www.zero.xyz/c/relayshield-url-scan-fa89eb72/llms.txt): $0.05/call via x402. Submits a URL for asynchronous security analysis, returning an analysis ID to poll for phishing/malicious content results
- [Prompt-Injection Breach Session Check](https://www.zero.xyz/c/prompt-injection-breach-session-check-224b076b/llms.txt): $0.35/call via x402. Checks whether an email address tied to an AI agent session has active stolen sessions or credential exposures from prompt-injection-driven breaches that could enable account takeover.

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

- [Zero catalog index](https://www.zero.xyz/llms.txt)
