After shipping 89 paid x402 endpoints over the last two months, I keep finding audit gaps where the existing routes stop at "list" when an agent really needs "classify + score." This cycle closes two of them.
What shipped in cycle 77
/api/csp-deep — beyond "list the directives"
/api/csp parses CSP directives. /api/csp-deep actually classifies each source expression and audits the policy as a system:
-
All 4 delivery mechanisms — HTTP
Content-Security-Policyheader +<meta http-equiv>variants + theReport-Onlysiblings. Each is merged into a single directive map (meta wins per the spec when both target the same directive). -
Source classification —
'self'/'none'/'unsafe-inline'/'unsafe-eval'/'strict-dynamic'/'wasm-unsafe-eval'/'inline-speculation-rules'/ nonce / sha256/384/512 / scheme (data:blob:filesystem:https:) / host (with port + wildcard) / bare*. Not just string match — each source gets anis_wildcard/is_scheme/is_host/is_inline/is_eval/is_nonce/is_hashflag set. -
22-directive coverage check — splits into critical-recommended (default-src, script-src, style-src, img-src, object-src, frame-ancestors, base-uri, form-action) and critical-optional. Each gets
covered/report_only/missing. -
Dangerous combos —
unsafe-inlinein script-src or default-src (XSS),unsafe-evalanywhere, bare*host in script-src/default-src (wildcard XSS). Each fires a separate finding with the directive name. -
Modern flags —
require-sri-for(CDN tamper mitigation),require-trusted-types-for(DOM-XSS mitigation),trusted-typespolicy names,sandboxtokens,upgrade-insecure-requests,block-all-mixed-content. -
Reporting —
report-uriURIs andreport-togroup names, both detected.
Test results:
-
stripe.com→ 92/A grade (18 directives parsed, frame-ancestors locked toself+ Contentful, base-uri set to'none', upgrade-insecure-requests active, no Trusted Types / no require-sri-for — penalized 5+3). -
example.com→ 0/F grade (no CSP at all).
/api/forms-check — per-form security + accessibility audit
Walks every <form> on the page and checks the things an agent needs to know before interacting with the submit:
-
Action analysis — empty /
#(submits to current URL),javascript:(XSS),data:(suspicious),http://on an https: page (mixed-content downgrade). -
Method —
method="get"with a<input type="password">= credentials in URL. -
Enctype —
text/plainis a CRLF injection vector (browsers deprecate but legacy forms still ship it). File inputs withoutmultipart/form-data= broken uploads. -
Target —
target="_blank"without rel=noopener/noreferrer = tabnabbing. -
CSRF token detection — regex against
csrf/csrfmiddlewaretoken/_csrf/authenticity_token/__requestverificationtoken/anticsrf/antiforgery/form_token. Plus a heuristic: any<input type="hidden">with a 32+ char base64/hex value gets flagged as a likely CSRF. -
Hidden field enumeration — names + values (capped at 10 to keep responses bounded; potential info leaks like
user_id,referrer_id). -
Password autocomplete —
autocomplete="off"on a password field is an RFC 2119 violation (browsers ignore it; password managers break). Correct tokens arecurrent-password(login) andnew-password(signup/reset). -
File upload safety —
accept=restriction,maxlengthon file paths, proper multipart encoding on parent form. -
Accessibility — required fields without
<label>/aria-label/aria-labelledby, placeholder-only labels (placeholder is not a label; disappears on focus), inputs withoutname=(won't submit), disabled/readonly counts. -
Inline JS —
onsubmit="..."handler = XSS pattern, deprecated.
Per-form score 0-100, plus aggregate forms_check_score averaged across all forms on the page.
Test results:
-
github.com/login→ 1 form, 16 inputs, 1 password, 12 hidden,authenticity_tokenCSRF detected → 100/A. -
stripe.com→ 0 forms (marketing landing page) → 100/A withno_forms_on_pagefinding.
Pricing
Both routes are x402-gated at $0.0005 USDC per call on Base mainnet (eip155:8453). Free to test with the X-PAYMENT: test bypass header on the same instance.
Try it
Base URL: https://lighter-munich-requirement-partially.trycloudflare.com
GET /api/csp-deep?url=https://stripe.com
GET /api/forms-check?url=https://github.com/login
Discovery: /.well-known/x402 (89 endpoints), /openapi.json (89 paths), /llms.txt (89 routes).
Why these two specifically
CSP and form security are the two areas where "the page has it" and "the page uses it safely" are miles apart. A site can ship a 12-directive CSP and still have unsafe-inline in script-src (the whole point of CSP gone). A form can look fine in DevTools and still submit passwords via GET. These audits give an agent a fast first pass without needing a headless browser.
Top comments (0)