x402 List

x402 Protocol Service Directory

SYNTHORA MCP Server Security Scan

Verification PAYMENT-READY imported

payment-ready until 2026-08-20

imported from the x402 Bazaar, not submitted by the operator · own this service? claim it · or ask to be removed

Scans an MCP server for security issues. Send a target URL or a pasted manifest; a deterministic rule engine checks embedded secrets, shell and filesystem capabilities, prompt injection surface and permissive input schemas, returning a security score, a risk tier and findings with remediation.

Pay from $0.05 per request in USDC on Base, settled onchain via the x402 protocol, no signup, no API key needed.

first settlement 2026-06-29 · $0.05 all-time · settled via coinbase, payAI

BASE URL https://mcpscan.hergertsynthora.com ENDPOINTS 1 NETWORK Base ASSET USDC MEMBER SINCE 2026-07-20 MONITORED SINCE 2026-07-20

ASSESSMENT

updated 4h ago

Evidence-backed signals, not a single score. Click any chip for the proof. Measured values stay read-only; unknown is honest.

reliability 95.8%
uptime 24h
100%
uptime 7d
100%
uptime 30d
95.8%
uptime 90d
95.8%
response p95
2238ms
avg response
903ms
total checks
2,131

Measured on the unpaid 402 handshake, not the paid call. A service can 402 correctly and still fail after payment.

compliance A (14/14)

14 of 14 x402 conformance checks pass. Full checklist below.

jump to compliance checklist

price $0.05 (p63 in Verification)
price (min)
$0.05
category percentile (min)
p63 in Verification
endpoints / prices
1 / 1
model
flat
stability
0%
risk clean

No deterministic risk flag. Risk fires only on an exact blocklist match, or a reserved-brand name with a mismatched verified payTo. Never from low uptime, a high price, or a model guess.

domain age
-
registrar
-
hosting
custom
domain created
---

Identity facts, not a risk score.

traction $0.0225606061 30d · 11 buyers
volume 30d
$0.0225606061
buyers 30d
11
settlements 30d
103
first settlement
2026-06-29
last settlement
2026-08-13
top buyer share
85% of 30d volume
trend 7d vs 30d
3.93x the 30d daily rate
networks
eip155:8453
volume all-time
$0.05
settlements all-time
232
median settlement 30d
$0.001
max settlement 30d
$0.10
settled via
coinbase ($1.44, 102 tx), payAI ($0.05, 1 tx)

Attributed pro-quota: this payout address is shared, so volume is the operator-level figure divided by the services sharing it, while buyer and transaction counts stay whole. A declared convention, not an individually observed measure, and still a conservative undercount.

Currently sharing this payout address with Agent Card Validator (A2A), Crypto 24h Trading Stats (Binance data), Crypto Fear & Greed Index, Crypto OHLCV Candles (Binance data), DEX Token Price (GeckoTerminal data), Email Deliverability Audit (SPF, DKIM, DMARC), FX Exchange Rates (ECB), German VAT Number Validator (SYNTHORA), Global Crypto Market Stats (CoinGecko data), Hyperliquid Perps Snapshot, iCalendar (.ics) Generator, LEI Lookup (GLEIF), Order Book Liquidity (Binance depth), Perp Funding Rates (Binance data), Polymarket Prediction Markets Feed, Public Holidays API (Nager.Date), SYNTHORA Address Risk Screen, SYNTHORA Agent Capability Attestation, SYNTHORA Agent Pre-Trade Safety, SYNTHORA AML Wallet Screen, SYNTHORA Base Block Metrics, SYNTHORA BIC/SWIFT Check, SYNTHORA Bridge Risk Evaluator, SYNTHORA Contract Code Check (eth_getCode), SYNTHORA Contract Guard, SYNTHORA Contract Watch, SYNTHORA Counterparty Risk Verdict, SYNTHORA Crypto News Sentiment, SYNTHORA DeFi Data (Hyperliquid perp feed), SYNTHORA DeFi Strategy Verdict, SYNTHORA Derivatives Intel Bundle, SYNTHORA DNS + WHOIS Domain Report, SYNTHORA ENS Resolver, SYNTHORA ERC-20 Token Balance, SYNTHORA Forex Rates (ECB), SYNTHORA FX Exchange Rates, SYNTHORA Gas & MEV Oracle, SYNTHORA IBAN Check, SYNTHORA Inference Router, SYNTHORA Keyless Web Search, SYNTHORA Liquidation Risk Signal (Aave v3), SYNTHORA Mailcheck, SYNTHORA MEV Exposure Detector, SYNTHORA MTA-STS Audit, SYNTHORA Native Balance (eth_getBalance), SYNTHORA Open Interest Oracle, SYNTHORA Pre-Sign Transaction Verdict, SYNTHORA Routing Check, Synthora RPC Contract Metadata, SYNTHORA RPC Network Metadata, SYNTHORA RPC Proxy Detect, SYNTHORA RPC Receipt, SYNTHORA RPC Transaction by Hash, SYNTHORA Slippage Oracle, SYNTHORA Stablecoin Peg Monitor, SYNTHORA Stablecoin Supply, SYNTHORA Token Risk, SYNTHORA Translate, SYNTHORA Trending Coins, SYNTHORA Tx Intent Classifier, SYNTHORA Wallet Reputation Score, SYNTHORA x402 Endpoint Preflight, SYNTHORA x402 Registry Watch, VIN Decoder (NHTSA vPIC), Wikipedia Article Summary.

Top buyer share is a concentration signal, not part of the ranking score.

CHANGES

3 events, detecting since 2026-07-24

Payout, price, and schema changes detected on this service's x402 wire. A payout rotation at an unchanged price shows up here even when nothing else moves. Full feed at /changes.

changes schema changed 8d ago (3 since 2026-07-24)

schema changed · 8d ago

schema removed POST /service exact eip155:8453 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 USDC 2 application/json 300 https://mcpscan.hergertsynthora.com/service {"name":"USD Coin","version":"2"}

schema added POST /service exact eip155:8453 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 USDC 2 application/json 300 https://api.hergertsynthora.com/v1/mcpscan {"name":"USD Coin","version":"2"}

price changed · 9d ago

POST /service · eip155:8453 · USDC: 10000050000

price changed · 12d ago

POST /service · eip155:8453 · USDC: 4000100000

Amounts are on-wire atomic units in the named asset.

see all changes for this service

WHAT IT DOES

ai-derived

Scans MCP servers for security vulnerabilities by probing them with JSON-RPC and analyzing their responses.

category
security-scanner
in
body
securityvulnerability-scanningmcp-server-rpc

AI-generated summary. The measured data is never altered by it.

ENDPOINTS

Service endpoints with HTTP method, path, description, pricing, and network
METHOD PATH DESCRIPTION PRICE NETWORK ASSET 402 CHANNEL
POST /service MCP Server Security Scan: probes an MCP server (JSON-RPC initialize + tools/list) and applies a deterministic rule engine over its tools — embedded secrets, dangerous shell/exec/filesystem capabilities, prompt-injection surface, hidden unicode, permissive input schemas, and auth/TLS/CORS headers — returning a security_score + findings[]. The trust layer for the agent economy. Zero-LLM, Ed25519-signed. 0.05 USDC via x402 on Base. SYNTHORA. $0.05 Base USDC header
1 endpoints

REQUEST / RESPONSE EXAMPLE

An unpaid request to POST /service returns HTTP 402 with the payment terms. Settle onchain via your facilitator, then retry with the X-Payment header.

// request
curl -i -X POST 'https://mcpscan.hergertsynthora.com/service'
// 402 response (captured by monitor) · 1 payload · click to expand
[
  {
    "error": "Payment required",
    "accepts": [
      {
        "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
        "extra": {
          "name": "USD Coin",
          "version": "2"
        },
        "payTo": "0x10800a5a5B9d72251566EC651E862A8b4B427dE0",
        "amount": "50000",
        "scheme": "exact",
        "network": "eip155:8453",
        "mimeType": "application/json",
        "resource": "https://api.hergertsynthora.com/v1/mcpscan",
        "description": "MCP Server Security Scan: probes an MCP server (JSON-RPC initialize + tools/list) and applies a deterministic rule engine over its tools — embedded secrets, dangerous shell/exec/filesystem capabilities, prompt-injection surface, hidden unicode, permissive input schemas, and auth/TLS/CORS headers — returning a security_score + findings[]. The trust layer for the agent economy. Zero-LLM, Ed25519-signed. 0.05 USDC via x402 on Base. SYNTHORA.",
        "maxAmountRequired": "50000",
        "maxTimeoutSeconds": 300
      }
    ],
    "resource": {
      "url": "https://api.hergertsynthora.com/v1/mcpscan",
      "iconUrl": "https://api.hergertsynthora.com/icon.svg",
      "mimeType": "application/json",
      "description": "MCP Server Security Scan: probes an MCP server (JSON-RPC initialize + tools/list) and applies a deterministic rule engine over its tools — embedded secrets, dangerous shell/exec/filesystem capabilities, prompt-injection surface, hidden unicode, permissive input schemas, and auth/TLS/CORS headers — returning a security_score + findings[]. The trust layer for the agent economy. Zero-LLM, Ed25519-signed. 0.05 USDC via x402 on Base. SYNTHORA.",
      "serviceName": "SYNTHORA"
    },
    "extensions": {
      "bazaar": {
        "info": {
          "input": {
            "body": {
              "manifest": {
                "name": "demo-mcp",
                "tools": [
                  {
                    "name": "search",
                    "description": "web search"
                  },
                  {
                    "name": "fetch",
                    "description": "http fetch"
                  }
                ],
                "version": "1.0.0"
              }
            },
            "type": "http",
            "method": "POST",
            "bodyType": "json"
          },
          "output": {
            "type": "json",
            "example": {
              "ok": true,
              "niche": "mcp_scan",
              "result": {
                "counts": {
                  "low": 0,
                  "high": 2,
                  "medium": 2,
                  "critical": 1
                },
                "signed": "ed25519",
                "target": "https://mcp.example.dev/mcp",
                "verdict": "critico",
                "findings": [
                  {
                    "id": "MCP-S01",
                    "rule": "secret_in_manifest",
                    "tool": "read_file",
                    "detail": "openai_key embedded in tool",
                    "severity": "critical"
                  }
                ],
                "tools_scanned": 2,
                "security_score": 14
              }
            }
          }
        },
        "schema": {
          "type": "object",
          "$schema": "https://json-schema.org/draft/2020-12/schema",
          "required": [
            "input"
          ],
          "properties": {
            "input": {
              "type": "object",
              "required": [
                "type",
                "method",
                "bodyType",
                "body"
              ],
              "properties": {
                "body": {
                  "type": "object",
                  "properties": {
                    "url": {
                      "type": "string",
                      "description": "MCP server URL (Streamable-HTTP endpoint)"
                    },
                    "manifest": {
                      "type": "object",
                      "description": "Or paste the MCP manifest (serverInfo + tools) directly"
                    }
                  }
                },
                "type": {
                  "type": "string",
                  "const": "http"
                },
                "method": {
                  "enum": [
                    "POST",
                    "PUT",
                    "PATCH"
                  ],
                  "type": "string"
                },
                "bodyType": {
                  "enum": [
                    "json",
                    "form-data",
                    "text"
                  ],
                  "type": "string"
                }
              },
              "additionalProperties": false
            },
            "output": {
              "type": "object",
              "required": [
                "type"
              ],
              "properties": {
                "type": {
                  "type": "string"
                },
                "example": {
                  "ok": {
                    "type": "boolean"
                  },
                  "type": "object",
                  "niche": {
                    "type": "string"
                  }
                }
              }
            }
          }
        }
      }
    },
    "x402Version": 2
  }
]

OVER TIME

All charts use the 7d selector; each series spans only the dates it has data for. Every series is also served as JSON at /api/v1/services/synthora-mcp-server-security-scan/price, /scores, /volume and /buyers. On-chain volume and distinct buyers are measured over the service's settlement address and are a conservative undercount (only settlements that reach a measured facilitator are counted). The on-chain series roll up hourly, so the latest day can be up to about an hour behind; distinct buyers are counted per payout address, so a service that settles to more than one address is an upper bound.

UPTIME
08-07 · uptime 100.0% · 439ms avg08-08 · uptime 100.0% · 569ms avg08-09 · uptime 100.0% · 621ms avg08-10 · uptime 100.0% · 682ms avg08-11 · uptime 100.0% · 626ms avg08-12 · uptime 100.0% · 820ms avg08-13 · uptime 100.0% · 833ms avg08-0708-13
7d UPTIME 100%
RESPONSE TIME
08-07 · 439ms avg08-07 · 439ms avg08-08 · 569ms avg08-08 · 569ms avg08-09 · 621ms avg08-09 · 621ms avg08-10 · 682ms avg08-10 · 682ms avg08-11 · 626ms avg08-11 · 626ms avg08-12 · 820ms avg08-12 · 820ms avg08-13 · 833ms avg08-13 · 833ms avg08-0708-13
AVG RESP 901ms
PRICE (captured 402, USD)
08-06 · $0.0508-13 · $0.05$0.0508-0608-13
SUB-SCORES (uptime + x402 compliance)
08-06 uptime: 94.2% compliance: 100% checks08-07 uptime: 94.5% compliance: 100% checks08-08 uptime: 94.8% compliance: 100% checks08-09 uptime: 95.1% compliance: 100% checks08-10 uptime: 95.3% compliance: 100% checks08-11 uptime: 95.5% compliance: 100% checks08-12 uptime: 95.7% compliance: 100% checks08-13 uptime: 95.8% compliance: 100% checksuptimecompliance08-0608-13

checklist grew 11->14 on 2026-07-28; a step here is a metric change, not a regression

PILLARS OVER TIME (measured)

Measured site and economics pillars from the assessment history, so the latest value shown elsewhere on this page reads as a point on a trend rather than a permanent state.

VOLUME (on-chain settlement, USD)
08-12 · $108-13 · $0.42peak $108-1208-13

Shared payout address (65 other services). These bars are the full shared address (operator-level), so do not sum them across the services that share it. Where a per-service figure is attributed, the assessment block and the ranking, it is the address total divided pro-quota by the 66 services sharing it: a declared convention, not an individually observed measure.

DISTINCT BUYERS
08-12 · 1 buyer08-13 · 3 buyerspeak 3 buyers08-1208-13

Shared payout address (65 other services). These bars are the full shared address (operator-level), so do not sum them across the services that share it. Per-service buyer and transaction counts are shown whole (integers), not divided; only volume is attributed pro-quota. A declared convention, not an individually observed measure.

COMPLIANCE

14/14 checks pass · grade A

last 402 captured 2026-08-05 · last up 2026-08-13

  • 402 payload captured
  • accepts[] array present
  • payTo address recoverable
  • payTo at accepts[0].payTo (conformant shape)
  • payTo is a valid on-chain address
  • atomic price declared
  • atomic price in a sane range
  • asset (token) address declared
  • network resolves to CAIP-2
  • payment scheme declared
  • served over HTTPS
  • declares the current x402 version (2)
  • EIP-712 domain parameters present on every EVM entry
  • x402 v2 envelope delivered in the payment-required header

SITE PILLARS

  • homepage reachable
  • openapi doc
  • pricing page
  • llms.txt
  • robots.txt
  • terms page
recent checks (18) live · click to expand
TIME STATUS RESP CAUSE
● OK 668ms
● OK 622ms
● OK 589ms
● OK 454ms
● OK 781ms
● OK 630ms
● OK 551ms
● OK 395ms
● OK 503ms
● OK 522ms
● OK 645ms
● OK 643ms
● OK 288ms
● OK 846ms
● OK 1337ms
● OK 349ms
● OK 914ms
● OK 532ms

EMBED THIS BADGE

Show that SYNTHORA MCP Server Security Scan is monitored on x402-list. Paste this on your site or README, it links back to this live listing.

SYNTHORA MCP Server Security Scan listed on x402-list
status
SYNTHORA MCP Server Security Scan uptime on x402-list
live uptime
// HTML
<a href="https://x402-list.com/services/synthora-mcp-server-security-scan?utm_source=badge&utm_medium=referral&utm_campaign=embed">
  <img src="https://x402-list.com/badge/synthora-mcp-server-security-scan.svg" alt="SYNTHORA MCP Server Security Scan listed on x402-list" height="28">
</a>
// Markdown
[![SYNTHORA MCP Server Security Scan on x402-list](https://x402-list.com/badge/synthora-mcp-server-security-scan.svg)](https://x402-list.com/services/synthora-mcp-server-security-scan?utm_source=badge&utm_medium=referral&utm_campaign=embed)
// HTML · live uptime variant
<a href="https://x402-list.com/services/synthora-mcp-server-security-scan?utm_source=badge&utm_medium=referral&utm_campaign=embed">
  <img src="https://x402-list.com/badge/synthora-mcp-server-security-scan.svg?data=uptime" alt="SYNTHORA MCP Server Security Scan uptime on x402-list" height="28">
</a>

RUN THIS SERVICE?

Keep this listing accurate: propose changes to the name, description, website, category or add new endpoints to monitor. Ownership is verified with a domain proof and every change is reviewed manually; measured data stays read-only.

[ update this listing ]

Earn the verified tier: x402list pays a real call to this endpoint and, if it delivers, the service is delivery-verified. The fee covers the cost of the probe, not the badge; there is no refund if the call does not deliver. Agent and API only, no in-browser signing. See /api.

[ verify this service ($0.25) ]

To request delisting, email info@x402-list.com or update your listing at /services/synthora-mcp-server-security-scan/update.