pulsefeed-x402-mcp
PulseFeed — open-source x402 client tools
Client-side, MIT-licensed tools for PulseFeed — the independent trust & safety layer for the x402 agent-payment economy.
Before an AI agent pays an x402 endpoint, it should know whether that endpoint is safe to pay — ~70% of x402 endpoints are dead, invalid, or scams, and only about half of what catalogs call "healthy" actually work. PulseFeed independently probes every x402 service, scans for scams (payTo hijack, bait-and-switch, honeypot), verifies the receiver on-chain, and publishes an open Trust Score.
This repo holds the open-source client packages. They talk to PulseFeed's public API (free /verify, live /status, paid /trust). The crawler, scoring engine, and dataset are the service itself at pulsefeed.dev.
Packages
Package | What it does | Install |
Drop-in tools for the Vercel AI SDK and LangChain: verify an x402 endpoint before your agent pays + discover working services |
| |
Wrap your paying |
| |
MCP server: gives Claude Desktop / Cursor / Cline tools to find live x402 services and verify endpoints before paying |
|
Related MCP server: BlueAgent x402 Services
Quick example
import { verifyX402Endpoint } from "pulsefeed-x402-ai-tools";
const v = await verifyX402Endpoint("https://api.some-x402-service.com/data");
if (v.verdict === "avoid") throw new Error("don't pay this endpoint");MCP config
{ "mcpServers": { "pulsefeed": { "command": "npx", "args": ["-y", "pulsefeed-x402-mcp"] } } }MCP server safety
Beyond x402, PulseFeed applies the same independent-audit playbook to the MCP server ecosystem — because a bad MCP server can run arbitrary code on your machine the moment you install it, and most people connect one without ever checking.
🔎 MCP Observatory — independent safety audit of the MCP server ecosystem (install-script / code-execution risk, abandonment, provenance, license, liveness)
📊 State of MCP Security — daily report. Right now ~10% of ~800 audited MCP servers run an install script (arbitrary code at
npm i), and dozens ship no repo to review. (Install scripts aren't always malicious — native builds use them — but each is an unreviewed code-execution vector.)✅ Check any server free:
GET https://pulsefeed.dev/mcp/verify?package=<npm-name>— verdict + flags before you connect it
Security Disclosures & Data API
🚨 Security Disclosures — a live feed of real threats caught in the x402 economy (receiver hijacks, bait-and-switch pricing, honeypots, unverified receivers), each with on-chain proof you can verify yourself. Machine feed:
/incidents.json· RSS📦 Data API — the wholesale trust backbone for agentic commerce: every x402 service’s moat profile + every audited MCP server + ecosystem aggregates + live incidents in one call ($1 over x402). Free preview + full schema:
/data.json
Links
🌐 Live observatory: pulsefeed.dev/status — the live state of x402
🧩 MCP Observatory · State of MCP Security — is that MCP server safe to install?
🚨 Security Disclosures (RSS) · 📦 Data API — cross-domain trust dataset in one call
📖 Methodology · OpenAPI · llms.txt
MIT © PulseFeed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Nikolife2016/pulsefeed-x402'
If you have feedback or need assistance with the MCP directory API, please join our Discord server