22 x402 pay-per-call utility tools for AI agents — scrape, validate, embed, store, moderate, notify, convert, prevent loops. No accounts, no API keys. USDC on Base via the x402 protocol.
SaferSkills independently audited X402 Tools Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Boring infrastructure for agent builders. 22 pay-per-call utility tools served as an MCP server — scrape, validate, embed, store, moderate, notify, convert, prevent loops. No accounts, no API keys, no subscriptions. Pay with USDC on Base via the x402 protocol.
npx @melis-ai/x402-tools-mcp→ Full catalogue with prices and live examples: [agents.melis.ai](https://agents.melis.ai) → Canonical 5-step RAG pipeline: [agents.melis.ai/pipelines/rag](https://agents.melis.ai/pipelines/rag) → 5-minute getting started: [agents.melis.ai/docs/getting-started](https://agents.melis.ai/docs/getting-started)
| Tool | Price (USDC) | Description |
|---|---|---|
list_services | free | Returns the full catalogue with prices and endpoint URLs |
cacheserve | $0.001 | Fetch a URL with server-side caching — avoids redundant origin hits |
docconvert_text | $0.001 | Format conversion: md↔html, json↔csv, html→txt, etc. |
intentflow | $0.001 | Context handoff relay for multi-agent delegation (async, returns retrieve_url) |
memoryserve_write | $0.001 | Store text + embedding in Qdrant + SQLite, namespaced per agent_id |
memoryserve_query | $0.001 | Recall most-similar memories by semantic query |
memscrub | $0.001 | Scan retrieved RAG content for indirect prompt injection (10 patterns) |
notifyrelay_webhook | $0.001 | POST a JSON payload to a URL with optional HMAC-SHA256 signing |
schemagate | $0.001 | Validate a JSON response against a JSON Schema, return a hint on failure |
loopwall_hop | $0.0005 | Validate one hop of a signed multi-agent chain (loop / budget enforcement) |
loopwall_issue | $0.001 | Issue a signed Job Envelope at chain start with budget + hop cap |
imageguard | $0.002 | NSFW image classification (multi-class moderation on roadmap) |
notifyrelay_telegram | $0.002 | Send a Telegram message to a known chat ID |
promptguard | $0.002 | Score untrusted input for prompt injection risk (0–100) |
structextract | $0.002 | Extract structured JSON from HTML — tables, links, emails, phones |
xaudit | $0.002 | Validate API response content with a cryptographically signed certificate |
docconvert_pdf | $0.005 | Convert HTML or markdown to PDF (base64 output) |
kyaoracle | $0.005 | On-chain trust score (0–100) for an Ethereum/Base wallet address |
linkrisk | $0.005 | URL risk profile — heuristic phishing signals, redirect tracing |
markdownopt | $0.005 | Convert URL or HTML to clean LLM-ready markdown (~70% token reduction) |
notifyrelay_email | $0.005 | Send a transactional email via Resend (allowlisted, rate-limited) |
embedpay | $0.00005 / 1k tokens | OpenAI text-embedding-3-small wrapper, batch tier available |
linksafe | $0.01 | Definitive URL safety check via Playwright sandbox + VirusTotal |
scrapepay | $0.01 | Web extraction via Playwright (robots.txt enforced, SSRF-safe) |
pdf_render | $0.49 | High-fidelity URL or HTML → PDF via Playwright |
22 services. Live prices and live wallet on Basescan.
Add to your claude_desktop_config.json:
{
"mcpServers": {
"x402-tools": {
"command": "npx",
"args": ["@melis-ai/x402-tools-mcp"]
}
}
}macOS: ~/Library/Application Support/Claude/claude_desktop_config.json Windows: %APPDATA%\Claude\claude_desktop_config.json
Restart Claude Desktop. All 22 tools appear in the tool picker.
See agents.melis.ai/docs/install-mcp for per-client setup.
// All 22 tools registered as MCP tools — your agent calls them like any function
const page = await callTool('scrapepay', { url: 'https://example.com/article' });
const md = await callTool('markdownopt', { html: page.content });
const vec = await callTool('embedpay', { input: md.markdown });
const stored = await callTool('memoryserve_write', {
agent_id: 'agent-1', content: md.markdown, vector: vec.embedding,
});
// Later — recall and guard against indirect injection
const hits = await callTool('memoryserve_query', {
agent_id: 'agent-1', query: 'what did we learn about X?',
});
for (const chunk of hits.matches) {
const scrub = await callTool('memscrub', { content: chunk.content });
if (scrub.risk_level === 'safe') useChunk(chunk);
}Total cost per 5k-token page: ~$0.017 USDC. Detailed walkthrough: agents.melis.ai/pipelines/rag.
x402 settles in USDC on Base (Coinbase L2). Two paths:
$1.00 of USDC covers 100 ScrapePay calls, 200 PromptGuard calls, or one full RAG-pipeline ingestion run.
| URL | Purpose |
|---|---|
| agents.melis.ai/llms.txt | Concise LLM-readable catalogue |
| agents.melis.ai/llms-full.txt | Full schemas + composition recipes |
| agents.melis.ai/openapi.json | OpenAPI 3.1 spec for all 22 endpoints |
| agents.melis.ai/ai-plugin.json | ChatGPT-plugin manifest |
https://<service>.melis.ai/.well-known/mcp.json | Per-service MCP discovery |
| agents.melis.ai/agents-faq | Agent-builder FAQ (distinct from human FAQ) |
Found a vulnerability? See SECURITY.md. Email [email protected]. Critical issues acknowledged within 24 hours.
If you use melis x402 Tools in research or downstream products, see CITATION.cff for the canonical citation.
mizukaizen — agent operator and builder. Catalogue: agents.melis.ai · Email: [email protected]
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.