Skill: Contract audit

$0.022 per call · USDC via x402 · POST /api/skill/contract-audit

Triage a smart contract before an agent interacts with it: verified Solidity source, heuristic vulnerability scan, known-address check, function-selector resolution, and a read-only dry-run of the exact call you plan to make. Send POST /api/skill/contract-audit with the required field address and pay $0.022 per call over x402 or MPP (there is no free tier). It returns a JSON object with pack, args, steps and summary.

Contract audit skill pack: one x402 payment runs 5 underlying tools (contract-source, solidity-scan, selector-lookup, address-label, tx-simulate); partial-success per step.

Category: Skill packs · Tags: skill-pack workflow contract-audit · Pack overview

TRY IN PLAYGROUND →

Parameters

NameTypeRequiredDescription
addressstringyes0x-prefixed contract address to audit Also accepted as addr, wallet, account.
networkstringnoEVM network (ethereum / base / polygon / arbitrum / optimism, default base)
datastringno0x-prefixed calldata you intend to send (default: a balanceOf probe)

Example request

curl -i -X POST https://agent402.tools/api/skill/contract-audit \
  -H "Content-Type: application/json" \
  -d '{"address":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","network":"base","data":"0x70a08231000000000000000000000000abf4fabd7c416fb67202e5f9002389fc75e2a9d0"}'

Without payment this returns HTTP 402 Payment Required with the exact price for skill-contract-audit; any x402 v2 or MPP client pays it and retries.

Example response

{
  "pack": "contract-audit",
  "args": {
    "address": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
    "network": "base",
    "data": "0x70a08231000000000000000000000000abf4fabd7c416fb67202e5f9002389fc75e2a9d0"
  },
  "steps": [
    {
      "slug": "contract-source",
      "ok": true,
      "result": {}
    },
    {
      "slug": "solidity-scan",
      "ok": true,
      "result": {}
    },
    {
      "slug": "selector-lookup",
      "ok": true,
      "result": {}
    },
    {
      "slug": "address-label",
      "ok": true,
      "result": {}
    },
    {
      "slug": "tx-simulate",
      "ok": true,
      "result": {}
    }
  ],
  "summary": "5/5 steps succeeded"
}
FieldTypeAlways presentIn the example
packstringyescontract-audit
argsobjectyes3 fields: address, network, data
stepsarray of objectsyes5 items in the example
summarystringyes5/5 steps succeeded

From an MCP client

catalog.call {
  "slug": "skill-contract-audit",
  "params": {
    "address": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
    "network": "base",
    "data": "0x70a08231000000000000000000000000abf4fabd7c416fb67202e5f9002389fc75e2a9d0"
  }
}

The hosted connector at https://agent402.tools/mcp needs a payment for skill-contract-audit; the stdio package pays it from a wallet or from AGENT402_CREDITS_KEY. Local install: npx -y agent402-mcp.

Errors and behavior

Paid call (JavaScript agent)

import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { registerExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const client = new x402Client();
client.setSpendControls?.(false); // keep your own spending ceiling in code
registerExactEvmScheme(client, { signer: privateKeyToAccount(KEY) });
const payFetch = wrapFetchWithPayment(fetch, client);

const res = await payFetch("https://agent402.tools/api/skill/contract-audit", {
  method: "POST",
  headers: { "Content-Type": "application/json" },
  body: JSON.stringify({
    "address": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
    "network": "base",
    "data": "0x70a08231000000000000000000000000abf4fabd7c416fb67202e5f9002389fc75e2a9d0"
  }),
});

Related tools

Skill: Convert anything to markdown

$0.026 · POST /api/skill/any-to-markdown

Convert anything at a URL - HTML, PDF, or an image - to clean markdown. The 'I have a URL but it might be any content-ty…

Skill: API health check

$0.005 · POST /api/skill/api-health

Is this API endpoint healthy? Liveness check, response headers, and TLS certificate status in one pass. API health check…

Skill: API investigation

$0.017 · POST /api/skill/api-investigation

Point at an unknown API endpoint and figure out how to use it: auth scheme, content type, version, rate limits, OpenAPI/…

Skill: Article digest

$0.09 · POST /api/skill/article-digest

Quick research brief on any topic - web search results plus an AI-generated answer in one pass. Article digest skill pac…

Skill: Brand protection

$0.018 · POST /api/skill/brand-protection

Is this domain legitimate? WHOIS age, DNS resolution, scam/phishing search results, and HTTP headers for a quick trust a…

Skill: Cheapest rail right now

$0.009 · POST /api/skill/cheapest-rail

Where should an agent transact this minute? Live gas on Ethereum + every major L2 side by side, Base gas tiers, a fee es…