Skip to main content
Glama

Automaton Token Safety

x402_conformance_check

FREE, runs locally. Lint any x402 paid endpoint for protocol conformance: HTTP 402 challenge, x402Version, accepts[] (exact scheme), Base network and addresses, EIP-712 domain, and rejection of malformed, forged, expired, underpaid and wrong-recipient EIP-3009 payments. Returns verdict, grade and per-check results.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
urlYesFull URL of the x402-protected endpoint to check.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden and does well: it discloses that the check is free and runs locally (implying no remote side effects or data transmission) and that it returns verdict, grade and per-check results. It does not disclose whether the endpoint is invoked with live requests, whether the target can see the check, or any rate limits, which keeps it from a 5.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the cost/local-execution constraint and the core action, then the check list and return values. It is a dense run-on list, but every clause names a concrete conformance aspect rather than filler, so little is wasted.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

No output schema exists, and the description compensates by naming the return shape (verdict, grade, per-check results) along with the full check coverage and the free/local operating condition. Combined with a fully documented single required parameter, an agent has everything needed to invoke this correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% for the single 'url' parameter, so the schema already explains it fully; the description adds no format, auth, or endpoint-shape detail beyond 'any x402 paid endpoint'. Baseline 3 applies when the schema does the heavy lifting and the description does not compensate further.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource: lint x402 paid endpoints for protocol conformance, and enumerates exactly what is validated (402 challenge, x402Version, accepts[], Base network, EIP-712 domain, EIP-3009 payment rejection cases). This is clearly distinguishable from siblings like security_scan, token_scan, and tx_simulate, which address different concerns.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

'Lint any x402 paid endpoint' implies the usage context, and 'FREE, runs locally' removes cost/consent friction, but there is no explicit when-to-use versus when-not-to-use guidance and no named alternative among siblings. The agent must infer that this tool is for x402 protocol checks rather than generic endpoint scans.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources