Token & contract risk report - PRO (static scan + reputation)

$0.85 per call · USDC via x402 · POST /v1/token-risk/pro

The deeper tier: everything in the standard report plus a deterministic static-pattern scan of the verified source (tx.origin auth, delegatecall, selfdestruct, unchecked calls, reentrancy surface, etc. - heuristic triage, not a formal audit) and a web reputation check. Send POST /v1/token-risk/pro with the required field address and pay $0.85 per call over x402 with USDC on an EVM chain. It returns a JSON object with report, address, chain, sources, tables and 1 more.

Still evidence, never a verdict. USDC (x402/MPP). Not cached.

Category: LLM gateway · Tags: crypto token risk rug static-analysis solidity reputation contract

TRY IN PLAYGROUND →

Parameters

NameTypeRequiredDescription
addressstringyesToken contract address (0x + 40 hex). Also accepted as addr, wallet, account.
chainstringnoChain, one of: base, ethereum, polygon, arbitrum, optimism, bsc, gnosis (default base).
formatstring (one of: markdown, json)noResponse shape (default markdown report).

Example request

curl -i -X POST https://agent402.tools/v1/token-risk/pro \
  -H "Content-Type: application/json" \
  -d '{"address":"0x4200000000000000000000000000000000000006","chain":"base"}'

Without payment this returns HTTP 402 Payment Required with the exact price for token-risk-pro; any x402 v2 or MPP client pays it and retries.

Example response

{
  "report": "# Token & Contract Risk Report: EXAMPLE (0x…)\n\n## Snapshot\n...\n\n## Risk summary\n... This is not financial advice and not exhaustive.",
  "address": "0x0000000000000000000000000000000000000000",
  "chain": "base",
  "sources": [],
  "tables": [
    {
      "name": "holders",
      "label": "Top holders",
      "columns": [
        "Rank",
        "Address",
        "Share of supply",
        "Type",
        "Label"
      ],
      "rows": [
        [
          "1",
          "0x…",
          "42.10%",
          "contract",
          "Uniswap V3 Pool"
        ]
      ]
    }
  ],
  "meta": {
    "tier": "token-risk-pro",
    "address": "0x…",
    "chain": "base",
    "name": "Example",
    "symbol": "EXMP",
    "verified_source": true,
    "holder_count": 1234,
    "top1_share_pct": 42.1,
    "top10_share_pct": 71.5,
    "synthesis_model": "anthropic/claude-opus-5",
    "disclaimer": "Evidence-based on-chain risk signals only. Not financial advice."
  }
}
FieldTypeAlways presentIn the example
reportstringyes# Token & Contract Risk Report: EXAMPLE (0x…) ## Snapshot ... ## Risk summa...
addressstringyes0x0000000000000000000000000000000000000000
chainstringyesbase
sourcesarrayyes0 items in the example
tablesarray of objectsyes1 item in the example
metaobjectyes11 fields: tier, address, chain, name, symbol, verified_source

From an MCP client

catalog.call {
  "slug": "token-risk-pro",
  "params": {
    "address": "0x4200000000000000000000000000000000000006",
    "chain": "base"
  }
}

The hosted connector at https://agent402.tools/mcp needs a payment for token-risk-pro; the stdio package pays it from a wallet or from AGENT402_CREDITS_KEY. Local install: npx -y agent402-mcp.

Errors and behavior

Paid call (JavaScript agent)

import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { registerExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const client = new x402Client();
client.setSpendControls?.(false); // keep your own spending ceiling in code
registerExactEvmScheme(client, { signer: privateKeyToAccount(KEY) });
const payFetch = wrapFetchWithPayment(fetch, client);

const res = await payFetch("https://agent402.tools/v1/token-risk/pro", {
  method: "POST",
  headers: { "Content-Type": "application/json" },
  body: JSON.stringify({
    "address": "0x4200000000000000000000000000000000000006",
    "chain": "base"
  }),
});

Related tools

Token & contract risk report (on-chain evidence)

$0.60 · POST /v1/token-risk

Hand over a token contract address (and chain) and get one evidence-based on-chain risk report: whether the source is ve…

Solidity heuristic pattern scan

FREE w/ compute · or $0.01 · POST /api/solidity-scan

Deterministic static pattern scan of Solidity smart-contract source text - a fixed ruleset flagging tx.origin authentica…

Domain security & deliverability audit (graded)

$0.60 · POST /v1/domain-audit

Hand over a domain and get one graded security & email-deliverability audit: SPF, DMARC, DKIM and MX (why your mail land…

Domain security audit - PRO (attack surface + stack)

$0.85 · POST /v1/domain-audit/pro

The deeper tier: everything in the standard audit plus the attack surface from Certificate Transparency logs (subdomains…

Company due-diligence dossier (grounded, cited)

$0.85 · POST /v1/dossier

Hand over a ticker and get one due-diligence dossier back. Pulls the company's SEC EDGAR filings (10-K / 10-Q / 8-K) and…

Company due-diligence dossier - MAX (exhaustive)

$1.10 · POST /v1/dossier/max

The exhaustive due-diligence tier: more filings, a full year of Form 4 insider activity, wider web research (up to 8 ang…