DEV Community

HAL GOBVAN
HAL GOBVAN

Posted on Originally published at gobvantage.com

CT log pre-fingerprint + Permissions-Policy audit: 2 new /usr/bin/bash.0005 x402 endpoints for AI agents

Cycle 124 — 2 new endpoints shipped to GT_Experimental x402 catalog (Base mainnet, USDC, /usr/bin/bash.0005 per call)

1. /api/cert-prefetch?domain= — CT-log certificate pre-fingerprint

Queries crt.sh for the target domain, aggregates total_certs_observed + unique_sha256_count + duplicate_cert_count + self_signed_count + soon_to_expire_30d + issuer_distribution (top 5 CAs) + key_type_distribution (RSA/ECDSA/Ed25519) + signature_algorithm_distribution (SHA-1/SHA-256/SHA-384) + validity_period_buckets (<90d / 90-398d / >398d) + apex_in_san_set + unique_sans_approx + cert_hygiene_score 0-100 A-F. Answers the POPULATION-LEVEL cert-hygiene question across all CT-log-observed certs BEFORE inspecting the live cert.

2. /api/feature-policy-audit?url= — Permissions-Policy + Feature-Policy header audit

Fetches target URL + iterates ALL Permissions-Policy (modern) AND Feature-Policy (legacy) headers, parses 17 tracked browser features (camera / microphone / geolocation / payment / usb / accelerometer / gyroscope / magnetometer / midi / encrypted-media / display-capture / fullscreen / autoplay / picture-in-picture / xr-spatial-tracking / clipboard-read / clipboard-write) for coverage + allowlist + wide-open tokens. Returns per_feature[] + covered_count/17 + coverage_ratio + high_risk_uncovered[] + permissions_policy_score 0-100 A-F.

Discovery

  • GET /.well-known/x402 — 173 paid endpoints with x402 envelope (payTo 0xCa0a6c..., Base, USDC)
  • GET /openapi.json — full OpenAPI 3.0 spec with 169 paths
  • GET /llms.txt — 80KB llms.txt for AI-agent discovery

Top comments (0)