x402 List

x402 Protocol Service Directory

SYNTHORA MCP Server Security Scan

Verification

Scans an MCP server for security issues. Send a target URL or a pasted manifest; a deterministic rule engine checks embedded secrets, shell and filesystem capabilities, prompt injection surface and permissive input schemas, returning a security score, a risk tier and findings with remediation.

Pay from $0.004 per request in USDC on Base, settled onchain via the x402 protocol, no signup, no API key needed.

UPTIME 24H 91.8% 7D 91.9% 30D 91.9%
BASE URL https://mcpscan.hergertsynthora.com ENDPOINTS 1 NETWORK Base ASSET USDC MEMBER SINCE 2026-07-20 MONITORED SINCE 2026-07-20

ASSESSMENT

updated 4h ago

Evidence-backed signals, not a single score. Click any chip for the proof. Measured values stay read-only; unknown is honest.

reliability 95.5%
uptime 24h
96.8%
uptime 7d
95.5%
uptime 30d
95.5%
uptime 90d
95.5%
response p95
5438ms
avg response
1931ms
total checks
47
compliance A (11/11)

11 of 11 x402 conformance checks pass. Full checklist below.

jump to compliance checklist

price $0.004 (p46 in Verification)
price (min)
$0.004
category percentile (min)
p46 in Verification
endpoints / prices
1 / 1
model
flat
stability
0%
risk clean

No deterministic risk flag. Risk fires only on an exact blocklist match, or a reserved-brand name with a mismatched verified payTo. Never from low uptime, a high price, or a model guess.

traction $0.03 30d · 0 buyers
volume 30d
$0.03
buyers 30d
0
settlements 30d
3
last settlement
2026-07-21
top buyer share
48% of 30d volume
trend 7d vs 30d
0.12x the 30d daily rate
networks
eip155:8453

Attributed pro-quota: this payout address is shared, so volume and buyers are the operator-level figure divided by the services sharing it. A declared convention, not an individually observed measure, and still a conservative undercount.

Top buyer share is a concentration signal, not part of the ranking score.

WHAT IT DOES

ai-derived

No AI synthesis has been produced for this service yet.

ENDPOINTS

Service endpoints with HTTP method, path, description, pricing, and network
METHOD PATH DESCRIPTION PRICE NETWORK ASSET
POST /service MCP Server Security Scan: probes an MCP server (JSON-RPC initialize + tools/list) and applies a deterministic rule engine over its tools — embedded secrets, dangerous shell/exec/filesystem capabilities, prompt-injection surface, hidden unicode, permissive input schemas, and auth/TLS/CORS headers — returning a security_score + findings[]. The trust layer for the agent economy. Zero-LLM, Ed25519-signed. 0.05 USDC via x402 on Base. SYNTHORA. $0.004 Base USDC
1 endpoints

REQUEST / RESPONSE EXAMPLE

An unpaid request to POST /service returns HTTP 402 with the payment terms. Settle onchain via your facilitator, then retry with the X-Payment header.

// request
curl -i -X POST 'https://mcpscan.hergertsynthora.com/service'
// 402 response (captured by monitor) · 1 payload · click to expand
[
  {
    "error": "Payment required",
    "accepts": [
      {
        "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
        "extra": {
          "name": "USD Coin",
          "version": "2"
        },
        "payTo": "0x10800a5a5B9d72251566EC651E862A8b4B427dE0",
        "amount": "4000",
        "scheme": "exact",
        "network": "eip155:8453",
        "mimeType": "application/json",
        "resource": "https://mcpscan.hergertsynthora.com/service",
        "description": "MCP Server Security Scan: probes an MCP server (JSON-RPC initialize + tools/list) and applies a deterministic rule engine over its tools — embedded secrets, dangerous shell/exec/filesystem capabilities, prompt-injection surface, hidden unicode, permissive input schemas, and auth/TLS/CORS headers — returning a security_score + findings[]. The trust layer for the agent economy. Zero-LLM, Ed25519-signed. 0.05 USDC via x402 on Base. SYNTHORA.",
        "maxAmountRequired": "4000",
        "maxTimeoutSeconds": 300
      }
    ],
    "freeTier": {
      "note": "send header X-WALLET: 0x<your Base address> for a free trial",
      "header": "X-WALLET",
      "callsPerWallet": 3
    },
    "resource": {
      "url": "https://mcpscan.hergertsynthora.com/service",
      "mimeType": "application/json",
      "description": "MCP Server Security Scan: probes an MCP server (JSON-RPC initialize + tools/list) and applies a deterministic rule engine over its tools — embedded secrets, dangerous shell/exec/filesystem capabilities, prompt-injection surface, hidden unicode, permissive input schemas, and auth/TLS/CORS headers — returning a security_score + findings[]. The trust layer for the agent economy. Zero-LLM, Ed25519-signed. 0.05 USDC via x402 on Base. SYNTHORA."
    },
    "extensions": {
      "bazaar": {
        "info": {
          "input": {
            "body": {
              "manifest": {
                "name": "demo-mcp",
                "tools": [
                  {
                    "name": "search",
                    "description": "web search"
                  },
                  {
                    "name": "fetch",
                    "description": "http fetch"
                  }
                ],
                "version": "1.0.0"
              }
            },
            "type": "http",
            "method": "POST",
            "bodyType": "json"
          },
          "output": {
            "type": "json",
            "example": {
              "ok": true,
              "niche": "mcp_scan",
              "result": {
                "counts": {
                  "low": 0,
                  "high": 2,
                  "medium": 2,
                  "critical": 1
                },
                "signed": "ed25519",
                "target": "https://mcp.example.dev/mcp",
                "verdict": "critico",
                "findings": [
                  {
                    "id": "MCP-S01",
                    "rule": "secret_in_manifest",
                    "tool": "read_file",
                    "detail": "openai_key embedded in tool",
                    "severity": "critical"
                  }
                ],
                "tools_scanned": 2,
                "security_score": 14
              }
            }
          }
        },
        "schema": {
          "type": "object",
          "$schema": "https://json-schema.org/draft/2020-12/schema",
          "required": [
            "input"
          ],
          "properties": {
            "input": {
              "type": "object",
              "required": [
                "type",
                "method",
                "bodyType",
                "body"
              ],
              "properties": {
                "body": {
                  "type": "object",
                  "properties": {
                    "url": {
                      "type": "string",
                      "description": "MCP server URL (Streamable-HTTP endpoint)"
                    },
                    "manifest": {
                      "type": "object",
                      "description": "Or paste the MCP manifest (serverInfo + tools) directly"
                    }
                  }
                },
                "type": {
                  "type": "string",
                  "const": "http"
                },
                "method": {
                  "enum": [
                    "POST",
                    "PUT",
                    "PATCH"
                  ],
                  "type": "string"
                },
                "bodyType": {
                  "enum": [
                    "json",
                    "form-data",
                    "text"
                  ],
                  "type": "string"
                }
              },
              "additionalProperties": false
            },
            "output": {
              "type": "object",
              "required": [
                "type"
              ],
              "properties": {
                "type": {
                  "type": "string"
                },
                "example": {
                  "ok": {
                    "type": "boolean"
                  },
                  "type": "object",
                  "niche": {
                    "type": "string"
                  }
                }
              }
            }
          }
        }
      }
    },
    "x402Version": 2
  }
]

UPTIME

07-20 · uptime 92.3% · 1441ms avg07-21 · uptime 91.8% · 2163ms avg07-20 · uptime 92.3% · 1441ms avg07-21 · uptime 91.8% · 2163ms avg07-2007-21
RESPONSE TIME
07-20 · 1441ms avg07-20 · 1441ms avg07-21 · 2163ms avg07-21 · 2163ms avg07-2007-21
90d UPTIME 91.9%
UPTIME 90D 91.9%
AVG RESP 2002ms
TOTAL CHECKS 63

RECENT CHECKS

TIME STATUS RESP
● OK 1467ms
● OK 2852ms
● OK 1809ms
● OK 2751ms
● OK 1148ms
● OK 1140ms
● SLOW 3272ms
● OK 2395ms
● OK 728ms
● OK 884ms
● OK 2369ms
● SLOW 7263ms
● OK 808ms
● OK 951ms
● SLOW 3202ms
○ DOWN 468ms
○ DOWN 625ms
○ DOWN 10001ms

OVER TIME

All charts share the 90d window selected here. Every series is also served as JSON at /api/v1/services/synthora-mcp-server-security-scan/price, /scores, /volume and /buyers. On-chain volume and distinct buyers are measured over the service's settlement address and are a conservative undercount (only settlements that reach a measured facilitator are counted).

PRICE (captured 402, USD)
07-20 · $0.0507-21 · $0.004$0.00407-2007-21
SUB-SCORES (uptime + x402 compliance)
07-20 compliance: 100% checks07-21 uptime: 95.5% compliance: 100% checksuptimecompliance07-2007-21
VOLUME (on-chain settlement, USD)
06-29 · $0.0706-30 · $0.5807-01 · $0.1007-02 · $0.0107-03 · $0.0107-04 · $0.0107-05 · $0.0007-06 · $0.0307-07 · $0.2107-08 · $0.6007-09 · $0.0207-15 · $0.0007-16 · $0.0107-18 · $0.0207-19 · $0.0007-20 · $0.0107-21 · $0.01peak $0.6006-2907-21

Shared payout address (61 other services). These bars are the full shared address (operator-level), so do not sum them across the services that share it. Where a per-service figure is attributed, the assessment block and the ranking, it is the address total divided pro-quota by the 62 services sharing it: a declared convention, not an individually observed measure.

DISTINCT BUYERS
06-29 · 1 buyer06-30 · 1 buyer07-01 · 1 buyer07-02 · 1 buyer07-03 · 1 buyer07-04 · 1 buyer07-05 · 1 buyer07-06 · 3 buyers07-07 · 3 buyers07-08 · 5 buyers07-09 · 3 buyers07-15 · 3 buyers07-16 · 2 buyers07-18 · 2 buyers07-19 · 1 buyer07-20 · 2 buyers07-21 · 1 buyerpeak 5 buyers06-2907-21

Shared payout address (61 other services). These bars are the full shared address (operator-level), so do not sum them across the services that share it. Where a per-service buyer count is attributed, the assessment block and the ranking, it is divided pro-quota by the 62 services sharing the address and can be fractional: a declared convention, not an individually observed measure.

COMPLIANCE

11/11 checks pass · grade A
  • 402 payload captured
  • accepts[] array present
  • payTo address recoverable
  • payTo at accepts[0].payTo (conformant shape)
  • payTo is a valid on-chain address
  • atomic price declared
  • atomic price in a sane range
  • asset (token) address declared
  • network resolves to CAIP-2
  • payment scheme declared
  • served over HTTPS

EMBED THIS BADGE

Show that SYNTHORA MCP Server Security Scan is monitored on x402-list. Paste this on your site or README, it links back to this live listing.

SYNTHORA MCP Server Security Scan listed on x402-list
status
SYNTHORA MCP Server Security Scan uptime on x402-list
live uptime
// HTML
<a href="https://x402-list.com/services/synthora-mcp-server-security-scan?utm_source=badge&utm_medium=referral&utm_campaign=embed">
  <img src="https://x402-list.com/badge/synthora-mcp-server-security-scan.svg" alt="SYNTHORA MCP Server Security Scan listed on x402-list" height="28">
</a>
// Markdown
[![SYNTHORA MCP Server Security Scan on x402-list](https://x402-list.com/badge/synthora-mcp-server-security-scan.svg)](https://x402-list.com/services/synthora-mcp-server-security-scan?utm_source=badge&utm_medium=referral&utm_campaign=embed)
// HTML · live uptime variant
<a href="https://x402-list.com/services/synthora-mcp-server-security-scan?utm_source=badge&utm_medium=referral&utm_campaign=embed">
  <img src="https://x402-list.com/badge/synthora-mcp-server-security-scan.svg?data=uptime" alt="SYNTHORA MCP Server Security Scan uptime on x402-list" height="28">
</a>

RUN THIS SERVICE?

Keep this listing accurate: propose changes to the name, description, website, category or add new endpoints to monitor. Ownership is verified with a domain proof and every change is reviewed manually; measured data stays read-only.

[ update this listing ]