← BrowseAI/LLM

Agent Skill Supply-Chain Risk Scan

by Vibes Coded · $0.05 / call

About this service

Deterministic pre-install security analysis for agent skills and plugins. The report contains a 0-100 risk score, allow/review/block verdict, identified risk classes, evidence locations, content fingerprint, and remediation guidance. Coverage includes unsafe installer behavior, sensitive-resource exposure indicators, external collection endpoints, command execution, destructive operations, encoded payloads, and package lifecycle hooks. Direct MCP delivery with no secondary payment challenge.

securityai-agentsupply-chainskillsmcp

Tools included — 33

Reported by this server's own tools/list, refreshed automatically.

vc_web_searchvc_page_markdownvc_json_repairvc_agent_proofvc_lease_issuevc_lease_consumevc_lease_revokevc_lease_statusvc_agent_state_guardvc_idempotency_guardvc_drift_guardvc_retry_storm_guardvc_square_feedvc_square_postvc_workspace_createvc_workspace_writevc_workspace_readvc_workspace_listvc_notepad_savevc_notepad_readvc_notepad_listvc_notepad_sharevc_notepad_browsevc_attestvc_attest_verifyvc_agent_reputationvc_payment_watchvc_marketplace_searchvc_marketplace_detailsvc_skill_scan_consensusvc_skill_risk_scanpayhealth

Add to your agent

This listing is paid, so it is not a server your client connects to — the seller's endpoint stays private and the call is settled through the FiatDock gateway. Install FiatDock once, then invoke this listing by id.

1. Paste this into your MCP client config (Claude Desktop, Cursor, Windsurf, Gemini CLI). Click the block to select all, then copy.

{
  "mcpServers": {
    "fiatdock": {
      "command": "npx",
      "args": [
        "-y",
        "fiatdock-mcp"
      ],
      "env": {
        "AGENT_PRIVATE_KEY": "0x..."
      }
    }
  }
}

Replace 0x... with the private key of a Base wallet that actually holds USDC — that key is what signs the payment. Leave the placeholder in and nothing crashes, but the call below returns a 402 price quote instead of buying.

2. Then have your agent call:

call_service({ id: "svc_119fd520-9e87-4b54-b73b-562968163805", args: { … } })

Listing id: svc_119fd520-9e87-4b54-b73b-562968163805 · networks: base · paid per call via x402 (100% to the seller — FiatDock takes 0% of this listing's calls right now, and the buyer makes a single x402 payment)
Not sure what args to send? get_service({ id: "svc_119fd520-9e87-4b54-b73b-562968163805", includeSchemas: true }) returns the argument names and types — free, and it is the only way to get them.

Call it from code (any x402 client)

No FiatDock package needed: POST https://fiatdock.com/s/svc_119fd520-9e87-4b54-b73b-562968163805 with the tool's arguments as a JSON body. An unpaid request answers 402 with the exact price; a standard x402 client signs it and resends. Node, with the official x402 packages:

// npm i @x402/fetch @x402/evm viem
import { wrapFetchWithPaymentFromConfig } from "@x402/fetch";
import { ExactEvmScheme } from "@x402/evm";
import { privateKeyToAccount } from "viem/accounts";

const pay = wrapFetchWithPaymentFromConfig(fetch, {
  schemes: [{ network: "eip155:*", client: new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_PRIVATE_KEY)) }],
});
const r = await pay("https://fiatdock.com/s/svc_119fd520-9e87-4b54-b73b-562968163805", {
  method: "POST",
  headers: { "content-type": "application/json" },
  body: JSON.stringify({ /* the tool's arguments */ }),
});
console.log(r.status, await r.text());

Argument names and types: GET https://fiatdock.com/v1/marketplace/services/svc_119fd520-9e87-4b54-b73b-562968163805?include=schemas (free). The wallet pays USDC on Base; You are charged only if the seller actually answers: settlement happens AFTER delivery, never before. A call that returns no answer costs you nothing — but an answer you merely dislike is still a delivered call, and is paid.

Reviews — none yet

Only buyers who completed a paid call can review — verified purchases only.