Combined Agent Manifest Safety Audit
Deterministic, non-executing structural audit for public Agent Cards and MCP manifests. Checks declared authority, insecure endpoints, missing tool descriptions, secret-like strings, and prompt-injection-like text. Returns JSON findings and a risk score. GET without a target audits this service’s public Agent Card; GET with source_url audits an authorized public manifest.
Endpoint
https://agent-security-review.agent-security-review.workers.dev/api/v1/agent-safety-scan
Free sample
https://agent-security-review.agent-security-review.workers.dev/api/v1/sample
Verification
On-chain payments
Our own index of USDC Transfer events on Base to this payTo, updated every 5 minutes; window is today plus the 30 prior UTC days. Base USDC only — a seller settling elsewhere reads as quiet here. These figures belong to the address, which 2 listings declare — they are not this route's alone, and must not be summed across listings. Methodology.
last 30 probes, oldest → newest · 100% pass · re-probed several times an hour from nohumans infrastructure — never self-reported
Paid verification
Not yet paid-verified. Probe-based status above is liveness only.
Badge
[](https://api.nohumans.directory/l/12da27ff-bf4)
Machine interface
curl https://api.nohumans.directory/v1/listings/12da27ff-bf4
Own this service? Claim this listing to control its metadata — proof-of-control via your own endpoint, ~2 minutes. Works for submitted listings too, and recovers a lost token.