Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/fardinvahdat/x402trace/claude-mdgit clone --depth 1 https://github.com/fardinvahdat/x402traceWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/fardinvahdat/x402trace/claude-md)<a href="https://agentmods.dev/instructions/fardinvahdat/x402trace/claude-md"><img src="https://agentmods.dev/badge/instructions/fardinvahdat/x402trace/claude-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.05308 | $0.05308 |
| Opus 5 | $0.02654 | $0.02654 |
| Sonnet 5 | $0.01062 | $0.01062 |
| Haiku 4.5 | $0.00531 | $0.00531 |
Grade A, and why
x402trace CLAUDE.md scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
- **Phase:** **v0.3.4 SHIPPED to npm 2026-05-30** — trust-taxonomy cycle. Four committed items closed: L (host_pollution, ADR-008, PR #101) + K (payment-payload echo gap rule pair + `upstream_stuck.cause` discriminator, How it starts
The opening of the file, as written. The whole thing — 156 lines — stays where its author put it; the contents beside it link to each section on GitHub.
CLAUDE.md — Operating manual for x402trace
This file is read by Claude Code at the start of every session. Keep it current; it is the project's living memory.
Project mission
x402trace is a local CLI for debugging x402 payment flows on Base. Its first job is detecting timeout reconciliation failures — cases where the facilitator times out but the on-chain transaction settled anyway, leaving the wallet debited and the user with no recovery path.
Canonical reference: coinbase/x402 Issue #1062.
Status
- Phase: v0.3.4 SHIPPED to npm 2026-05-30 — trust-taxonomy cycle. Four committed items closed: L (host_pollution, ADR-008, PR #101) + K (payment-payload echo gap rule pair +
upstream_stuck.causediscriminator, ADR-007, PR #102) + G (facilitator-fitness per-rail, ADR-005, PR #103) + I (service_unreachabletop-level verdict + first stateful event discriminant + multi-probe consensus, ADR-006, PR #104 + determinism fix #105).bazaar-checkgrows 5 → 8 checks. JSON API X402-44 contract preserved across all four additions. 650 tests (was 514 in v0.3.3, +136 cycle delta). 4 named contributors credited (@hypeprinter007-stack / Ferj 🙏, @RipperMercs 🙏, @TKCollective 🙏, @AsaiShota 🙏) + 5 design-refinement voices (@Cryptor, @TomSmart_ai, @Cinderwright, @evanatpizzarobot, @poteshniy). Prior cycle context preserved: v0.3.3 was rename of v0.3.2.1 fast-follow for semver compliance. v0.3.2 ([email protected], Sigstore provenance + signed attestations) external adoption confirmed: @0xdespot rannpx -y [email protected] bazaar-checkagainst hyperD 2026-05-23, @poteshniy (AgentTrust) shipped derivative/v1/reputationproduct 2026-05-26, @RipperMercs + @TKCollective ran v0.3.2 verdicts in #2207 closure loop 2026-05-26. v0.3.4 committed scope (4 items, 2026-05-29 — shipped 2026-05-30): candidate_K filed as X402-50 (payment-payload echo gap diagnose rules — @RipperMercs + @TKCollective, 2 voices, ADR-007) + candidate_G (X402-51 facilitator-fitness — Cryptor + TomSmart + @Cinderwright 3rd-touch via x402-foundation/x402#1065 PayAI workaround 2026-05-29, ADR-005 accepted 2026-05-29) + candidate_I (X402-52 #88 network-layer-fail vs x402-layer-fail — TomSmart mapper.db, 2 voices; AC reshaped 2026-05-29 per TomSmart Tuesday-traceroute anti-evidence — 13/15 sampled cohort actually reachable; multi-probe consensus + DNS/TCP/TLS failure-mode classification required, ADR-006 accepted 2026-05-29 — top-levelservice_unreachableverdict + probe-history-via-JSONL state) + candidate_L promoted 2026-05-29 via D.5 single-voice bypass (ADR-008): host_pollution listing-hygiene verdict — Ferj cdp-verified, anchor-x402.com 23-entry curl repro 2026-05-27, renamed H→L because H taken by RipperMercs #85 directory-only-manifest signal in Notion plan. Jira X402-53 filed + Notion plan row added 2026-05-29. Forward direction: hosted-product play converges into comprehensive agentic-commerce super-app at https://deagentic.ai/ (see [[deagentic-super-app-vision]]) — recalibrates Candidate E from standalone hosted-demo to super-app component. v0.3.2 cycle shipped seven D.x + infrastructure tickets 2026-05-21 → 2026-05-22: X402-41 ADR-004 + X402-42 D.4--endpoint+ X402-43 D.5 variant-aware extensions.bazaar + X402-44 JSON API stability + X402-45 D.2 propagation diff + X402-46 D.3 indexer-state +upstream_stuckverdict + X402-47 fixture-consumption infrastructure. Separately: X402-40 Node 22npxESM-resolver hang — Solana-dep drop branch shelved after 2-voice convergence (hypeprinter007's anchor-x402 Solana rail + TomSmart's x402-fetch transitive diagnostic); README install-section workaround shipped unconditionally. v0.3.1 shipped 2026-05-20 ([email protected]). - v0.1 wedge: Local HTTP proxy + timeout-reconciliation engine. Accepted 2026-05-12 in ADR-001. Verified via three independent live Base Sepolia settlements (tx
0x116ccf73…ba52is the X402-15 demo capture). - v0.2 scope:
x402trace validate(pre-flight) +x402trace explain(offline plain-English 402 diagnosis), sharing thesrc/diagnose/rule engine. Picked 2026-05-12 in ADR-002. Shipped in v0.2.0..v0.2.3. - v0.3 scope:
x402trace bazaar-check(headline) + 5 facilitator-aware diagnose rules +validate --diffcross-facilitator + Base mainnet support +versionsSDK skew (stretch, shipped). Picked 2026-05-14 in ADR-003. Execution autonomous per user direction; every ticket runs through the Strict audit gate. v0.3.0 shipped 2026-05-17. - v0.3.1 hotfix scope: #66 + #67 +
package.jsondescription fix. Both contributor PRs merged within 12h of opening — strongest "v0.3.0 found its audience" signal so far. Third independent positive: @TomSmart_ai ranbazaar-checkagainst 19 production endpoints, 19/19 returnedimplementation_issue(production-scale validation of the verdict taxonomy). - v0.3.2 committed scope (7 items, in-flight): D.1 manifest hygiene (shipped on main via PR #70 — needs D.5 variant-aware refactor before release) + D.2 propagation diff + D.3 indexer-state probe (introduces new top-level
upstream_stuckverdict, rolls up to exit code 3) + D.4--endpoint <paid-url>per-route probe + D.5 variant-awareextensions.bazaar(BodyDiscoveryExtension vs McpDiscoveryExtension; bug-pathway from #72) + JSON API stability commitment (snapshot tests +src/bazaar/json-api.md+ versioning rule) + production-set fixture consumption (6-fixture pipeline: TomSmart 19-URL + cdp-mature + AsaiShota test-echo-cdp + evanatpizzarobot tensorfeed + 0xdespot hyperd + hypeprinter007 anchor-x402 multi-rail). ADR-004 (X402-41) lands first. Held:facilitator-status(Candidate A, 1 cluster), hosted demo (Candidate E, 1/4 signals), alt-challenge-surface (Candidate F, 1/n — 0xdespot's free-tier-upgrade observation from #2207, recorded as candidate; no implementation lean). - Repo: https://github.com/fardinvahdat/x402trace
- Jira: https://vahdatfardin.atlassian.net/jira/software/projects/X402
- Notion v0.2 plan: https://www.notion.so/35c03c62b2638159a5e2d1ecaac5ff0b
- Notion v0.3 plan: https://www.notion.so/36003c62b26381fd9ae5c48758d53ccd
- Notion v0.3.1+/v0.3.2 evidence page: https://www.notion.so/36503c62b26381cfbd1ce4d95fabda82 (historical evidence accumulation; v0.3.1 + #2207 cluster + cdp-mature ETA)
- Notion v0.3.2 committed plan: https://www.notion.so/36603c62b26381b4b182ee5f6e07f002 (authoritative scope + ticket layout)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 156 lines · 5,308 tokens per session scan A 231557d8e53e
x402trace CLAUDE.md is an instructions file published in the GitHub repository fardinvahdat/x402trace (5 stars, last pushed 17d ago), licensed Apache-2.0. It adds 5,308 tokens to every session, about $0.0265 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
agentpay AGENTS.md
Instructions for ANVEAI/agentpay, covering agents.md — agentpay runbook for coding agents, 1. configure (programmatic), create a merchant project + api key, → { project: {...}, apikey: "aplive…" } and add (provision) a paying agent.
aegis-protocol CLAUDE.md
Instructions for im-sham/aegis-protocol, covering aegis protocol — claude code project context, what this is, core architecture, job state machine and erc-8004 integration (critical — this is our moat).
universal-crypto-mcp copilot-instructions.md
Copilot instructions for nirholas/universal-crypto-mcp, covering universal-crypto-mcp and terminal management.
universal-crypto-mcp CLAUDE.md
Claude Code instructions for nirholas/universal-crypto-mcp, covering universal-crypto-mcp and terminal management.
universal-crypto-mcp GEMINI.md
Gemini CLI instructions for nirholas/universal-crypto-mcp, covering universal-crypto-mcp and terminal management.
slug-wallet AGENTS.md
AGENTS.md instructions for tyrion777-stack/slug-wallet, covering agents.md, commands, key files, env vars needed for live mode and test structure.