目录 / PulseFeed
PulseFeed
Verify before you pay or install. **Before you pay an x402 endpoint** — liveness, a 0–100 trust score, scam flags (payTo hijack, bait-and-switch pricing, honeypot receiver) and a pay/avoid verdict, with on-chain proof links on Base. **Before you trust an MCP server or npm package** — what changed *after* people adopted it: install script added in a later version, ownership swapped, repository removed, package unpublished, build provenance lost. Static scanners answer whether a package is safe today. This answers the other question, and it needs yesterday's snapshot to exist. PulseFeed diffs the entire MCP registry against the previous day's snapshot every night, and re-probes the x402 endpoint population daily. The series runs from 2026-07-30 and cannot be reconstructed after the fact. Open data: [drift feed](https://pulsefeed.dev/mcp/drift) · [correction page](https://pulsefeed.dev/correction) · [dataset](https://huggingface.co/datasets/Nikolife/pulsefeed-x402-security)
接入信息
- 传输形态
- http
- 鉴权方式
- 鉴权未知
- 端点
https://pulsefeed-x402--nikolife2016.run.tools
{
"mcpServers": {
"PulseFeed": {
"url": "https://pulsefeed-x402--nikolife2016.run.tools"
}
}
}
能力清单
| 工具 | 说明 |
|---|---|
| check_x402_endpoint | Before paying an unknown x402 endpoint, check whether it is safe: liveness, trust score (0-100), anomaly flags (receiver address changed between observations, catalog price vs. challenge price, invalid receiver, testnet listed as production, scheme outside the x402 spec), receiver stability and observation-count-qualified uptime — with a pay/avoid verdict. Reads the challenge from both the response body and the v2 PAYMENT-REQUIRED header. Free. |
| mcp_check_server | Before installing an MCP server or npm package, audit it: does it run an INSTALL SCRIPT (arbitrary code execution at `npm i`), is it abandoned, does it ship a repository and license, weekly downloads, provenance — with a safe/caution/avoid verdict. ~11% of audited MCP servers run install scripts. Free. |
| mcp_drift_check | The rug pull check. `mcp_check_server` answers whether a package is safe TODAY; this answers what CHANGED after it was adopted: an install script added in a later version (arbitrary code on `npm i` that was not there at review time), package ownership swapped, repository removed, package unpublished, build provenance lost. Pass your own dependency list to check it in one call. Derived from a daily external re-audit of the whole MCP package population — an event exists only because a snapshot from before it exists. Free. |
| mcp_security_report | State of MCP Security: how many audited MCP servers run an arbitrary install script, are abandoned, ship no repository or license — with day-over-day deltas and a sample of currently-flagged servers. From a daily audit of the MCP server catalog. Free. |
| pulsefeed_products | List PulseFeed's paid products and how to pay via x402 (USDC on Base): deep trust check, endpoint track record, bulk trust dataset, and the cross-domain Data API. Includes the client-side spend-cap gotcha for x402-fetch. |
| x402_changes | What changed in the x402 ecosystem recently: services that stopped returning a valid challenge, receiver (payTo) changes, price changes, recoveries, newly-seen services. Derived from compounding time-series that cannot be reconstructed after the fact. Free. |
| x402_data_sample | FREE sample of the PulseFeed Data API: top-10 live x402 services as FULL records (compounding payTo/price history, anomaly flags, on-chain receiver profile), top-10 MCP servers with full audit profile, and 3 live incidents. |
| x402_ecosystem_stats | Live health of the whole x402 agent-payment ecosystem: tracked/alive/dead counts, catalog-accuracy audit (what share of listings called 'healthy' actually work), risk-level distribution, receiver stability and on-chain receiver profiles. Free. |
| x402_incidents | Anomalies observed in live x402 endpoints by continuous independent measurement: receiver-address changes between observations, catalog price vs. challenge price mismatches, invalid receivers, testnet endpoints listed as production, payment schemes outside the x402 spec — EACH WITH AN ON-CHAIN REFERENCE on Base. Measurements, not accusations of intent. Check before paying anything. Free. |
| x402_leaderboard | Top x402 services ranked by the open PulseFeed Trust Score (0-100), with price and network — the most reliable live agent-payment endpoints right now. Free. |
| x402_working_services | List x402 agent-payment services that are currently ALIVE and return a valid x402 challenge, ranked by PulseFeed Trust Score, plus ecosystem risk map. Use this to pick a service with a track record instead of paying an endpoint you have not checked. Free. |
提交举报 / 纠错
侵权举报经核验成立后,我们会即时下线该条目并删除已存的内容副本。