SAVRN
Search Contact SAVRN

Dataset

pulsefeed-x402-security

by Life Nikolife/pulsefeed-x402-security

Independent, daily-updated trust & safety data for the x402 agent-payment economy (HTTP 402 + stablecoins on Base) and the MCP server ecosystem — by PulseFeed.

Rows
Configurations
Size1.5 MB
Licensecc-by-4.0
AccessPublicly accessible
Monthly Downloads820

Dataset Card

By Life, published under cc-by-4.0, revision d423e826c0a9.

PulseFeed — x402 Agent-Payment Security & Trust (open data)

Independent, daily-updated trust & safety data for the x402 agent-payment economy (HTTP 402 + stablecoins on Base) and the MCP server ecosystem — by PulseFeed.

AI agents increasingly pay for APIs autonomously over x402 and connect to MCP servers that can run code on install. But 20% of listed x402 endpoints are dead or invalid, and "live" is not the same claim as "payable": of 24131 endpoints that return a valid 402, only 22426 across 1904 operators are things an agent can actually buy — the rest are documentation placeholders, testnet sandboxes priced in dollars, or payment schemes outside the x402 spec. Both figures are in ecosystem.json as healthyEndpoints and payableEndpoints; compare the payable one. This dataset is the free, public slice of PulseFeed's continuous audit. Last updated: 2026-09-18T02:45:05+00:00.

Methodology correction — 2026-07-30. Snapshots dated before 2026-07-30 understate liveness. Our prober read x402 payment requirements only from the HTTP response body; x402 v2 moved them into the PAYMENT-REQUIRED header. 1,869 endpoints across 166 operators were live and recorded as dead, and 3,920 fabricated malformed observations were removed from their history — records repaired this way carry historyRepairedAt. The dead share moved from 74–76% to 20%: a change in the measuring instrument, not in the market. Series before and after this date are not directly comparable, and each snapshot now carries probeVersion. The scam/anomaly findings are unaffected. Full write-up, including four further errors of the same kind and a checklist for deciding whether an endpoint is genuinely payable: https://pulsefeed.dev/correction

The audit, incident feed and reports are free and open. Live pages: /incidents · /status · /reports. Machine feeds: /incidents.json · /incidents.rss. Full per-service cross-domain data feed (paid, x402): /data.

Files

File What
incidents.csv / incidents.json Active security incidents in the x402 economy — receiver hijacks, bait-and-switch pricing, honeypots, unverified receivers, price gouging — each with an on-chain proof URL.
ecosystem.json Ecosystem aggregates: totals & dead %, catalog-accuracy audit, risk distribution, receiver-stability & on-chain receiver-profile distributions, top providers.
mcp_security.json MCP server security summary: how many audited servers run an install script, are abandoned, ship no repo, etc.
mcp_drift.json / .csv MCP package drift — what changed after a package was adopted: install script added in a later version, ownership swapped, repository removed, package unpublished, build provenance lost. Every scanner answers whether a package is safe today; this is the record of what turned dangerous later. Built by diffing each daily snapshot against the previous one, so it cannot be reconstructed after the fact.

incidents schema

Field Meaning
category payto_hijack | bait_and_switch | honeypot | unverified_receiver | price_gouging | asset_mismatch | went_dark
severity high | medium
at ISO timestamp of the observation
domain / endpoint the x402 service
network payment network (e.g. base)
detail plain-language description of the finding
payTo the receiver address
onchain_proof_url Base block-explorer link to verify the receiver yourself
flags raw detector flags (|-separated)

Honesty note

Findings are stated as facts from the data, not accusations of intent. "bait-and-switch" = advertised price != amount actually charged; "unverified receiver" = payTo has no on-chain USDC history (a risk signal, not a conviction); "possible hijack" = receiver changed on an established baseline (could be a legitimate key rotation). By-design receiver rotation is excluded.

Why it's unique

The signals here (receiver-stability over time, payTo/price change history, on-chain receiver profiles) are longitudinal — derived from continuously re-probing endpoints and recording changes as they happen. This history cannot be reconstructed after the fact.

License & attribution

CC-BY-4.0. Attribution: "x402/MCP trust data by PulseFeed (pulsefeed.dev)". The full per-service cross-domain feed is a separate paid product at pulsefeed.dev/data.

Writeup: I audited the entire x402 agent-payment economy — 76% is dead, and the live half has scams. The "76% dead" headline in that article is superseded — see the methodology correction above. The scam taxonomy stands.

Details

Repository
Nikolife/pulsefeed-x402-security
Publisher
Life
Task category
Not stated by the source
Tags
x402, ai-agents, agentic-payments
Size category
n<1K
Languages
en
Revision
d423e826c0a9b7ad015618e23620830de26ba62c
Last updated
2026-09-18

Files

8 files, 1.5 MB in total.

Data6 files · 1.5 MB
Documentation1 file · 5.4 KB
Repository1 file · 2.5 KB
Every file
FileTypeSizeSHA-256
ecosystem.jsonData7.3 KB
incidents.csvData173.9 KB
incidents.jsonData405.3 KB
mcp_drift.csvData217.6 KB
mcp_drift.jsonData650.6 KB
mcp_security.jsonData4.1 KB
README.mdDocumentation5.4 KB
.gitattributesRepository2.5 KB

License and Download

License
cc-by-4.0
Access
No access gate
Download from Life

Released by Life through its official repository on Hugging Face. Read the license.