Security audit

Enumerate a domain's external attack surface in one workflow: certs, DNS posture, email auth, HTTP security headers, and tech stack.

$0.017 per call · one payment for the whole workflow
POST /api/skill/security-audit
Sample output + API docs →

7 tools run server-side in one request. You pay once, settle once, and get a single response - no orchestration, no per-step payments, and a partial-success envelope if any step fails. USDC over x402 on any supported chain.

When to use this pack

Before a pentest, an acquisition diligence call, or a quarterly review - you want a fast read on what an attacker sees from the outside.

Tools in this pack

All 7 run inside the single $0.017 call above. Each is also callable on its own if you only need one part.

Bought one at a time, these 7 tools cost $0.018 together; the pack is that sum less a 10% bundle discount, rounded up to the $0.001 settlement floor, which is $0.017.

Workflow

  1. Pull the certificate transparency log to enumerate every subdomain a CA has ever issued a cert for - this is the fastest external recon step.
  2. Resolve the apex's A and CAA records, then A records for up to three subdomains the log named (shallowest first), to map the live infrastructure and certificate authority constraints.
  3. Check SPF and DMARC on the apex to see whether the domain can be spoofed in email - a missing or weak DMARC is one of the highest-impact findings on most audits.
  4. Pull HTTP response headers on the apex and up to two of those subdomains; the security analyzer scores HSTS, CSP, XFO, XCTO, Referrer-Policy, Permissions-Policy, and the COOP/CORP/COEP triad.
  5. Inspect the live TLS cert (chain, expiry, SANs) - useful for spotting near-expiry, mismatched SANs, or weak chain configurations.
  6. Fingerprint the tech stack so you know what CMS/framework/CDN to research for known CVEs.

Arguments

NameRequiredDescriptionExample
domainyesTarget domain to audit (e.g. stripe.com)agent402.tools

What one call returns

A JSON object with pack, args, steps, summary; steps holds one entry per tool (cert-transparency, dns-lookup, spf-check, dmarc-check, http-headers, tls-cert, tech-stack), each with its own result or error. Full example on the API page.

Call it directly

Any x402 client pays the 402 and gets the whole workflow back in one response. With the agent402-client SDK (npm i agent402-client, an ES module):

import { Agent402 } from "agent402-client";
// payFetch: an x402-wrapped fetch your wallet signs (@x402/fetch).
// Tools on the free tier need no options: new Agent402() pays them by proof-of-work.
// an existing prepaid credits key also works: new Agent402({ creditsKey })
const client = new Agent402({ fetch: payFetch });
const result = await client.call("skill-security-audit", {"domain":"agent402.tools"});

Run it in Claude

claude mcp add agent402 -s user -- npx -y agent402-mcp@latest

Then paste this prompt into Claude:

Run a security audit on agent402.tools. Use Agent402 to: (1) pull the certificate transparency log, (2) check SPF and DMARC on the apex, (3) fetch HTTP security headers and the TLS cert, (4) fingerprint the tech stack. Report findings ranked by severity, and call out anything that would block a SOC 2 review.

← All skill packs