x402trace CLAUDE.md

x402trace CLAUDE.md is an instructions file for coding agents from fardinvahdat/x402trace. It costs 5,308 tokens per session, scanned A, original, Apache-2.0.

A project guide for x402trace, a local command-line tool that checks x402 payments on the Base blockchain. It records the project's purpose, current status, rules, and audit requirements for Claude Code.

In plain words
What is it for?
Use it when changing or reviewing x402trace, especially its checks for payment timeouts, blockchain settlement, facilitator availability, and JSON API behavior.
Why use it?
It gives the coding agent the project's shared memory and strict rules at the start of each session, reducing the risk of work that conflicts with the payment-debugging goals.

Instructions file

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/fardinvahdat/x402trace/claude-md
Clone the repo
git clone --depth 1 https://github.com/fardinvahdat/x402trace

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for x402trace CLAUDE.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/fardinvahdat/x402trace/claude-md.svg)](https://agentmods.dev/instructions/fardinvahdat/x402trace/claude-md)
Your own site
<a href="https://agentmods.dev/instructions/fardinvahdat/x402trace/claude-md"><img src="https://agentmods.dev/badge/instructions/fardinvahdat/x402trace/claude-md.svg" alt="Measured on agentmods" height="20"></a>
Per session 5,308 This file is loaded in full into every session.
When invoked 5,308 The same file — it is already loaded in full.
Security scan A 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.05308 $0.05308
Opus 5 $0.02654 $0.02654
Sonnet 5 $0.01062 $0.01062
Haiku 4.5 $0.00531 $0.00531

Measured 4d ago against content hash 231557d8e53e, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

x402trace CLAUDE.md scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

- **Phase:** **v0.3.4 SHIPPED to npm 2026-05-30** — trust-taxonomy cycle. Four committed items closed: L (host_pollution, ADR-008, PR #101) + K (payment-payload echo gap rule pair + `upstream_stuck.cause` discriminator,
CLAUDE.md · 156 lines

How it starts

The opening of the file, as written. The whole thing — 156 lines — stays where its author put it; the contents beside it link to each section on GitHub.

CLAUDE.md — Operating manual for x402trace

This file is read by Claude Code at the start of every session. Keep it current; it is the project's living memory.

Project mission

x402trace is a local CLI for debugging x402 payment flows on Base. Its first job is detecting timeout reconciliation failures — cases where the facilitator times out but the on-chain transaction settled anyway, leaving the wallet debited and the user with no recovery path.

Canonical reference: coinbase/x402 Issue #1062.

Status

  • Phase: v0.3.4 SHIPPED to npm 2026-05-30 — trust-taxonomy cycle. Four committed items closed: L (host_pollution, ADR-008, PR #101) + K (payment-payload echo gap rule pair + upstream_stuck.cause discriminator, ADR-007, PR #102) + G (facilitator-fitness per-rail, ADR-005, PR #103) + I (service_unreachable top-level verdict + first stateful event discriminant + multi-probe consensus, ADR-006, PR #104 + determinism fix #105). bazaar-check grows 5 → 8 checks. JSON API X402-44 contract preserved across all four additions. 650 tests (was 514 in v0.3.3, +136 cycle delta). 4 named contributors credited (@hypeprinter007-stack / Ferj 🙏, @RipperMercs 🙏, @TKCollective 🙏, @AsaiShota 🙏) + 5 design-refinement voices (@Cryptor, @TomSmart_ai, @Cinderwright, @evanatpizzarobot, @poteshniy). Prior cycle context preserved: v0.3.3 was rename of v0.3.2.1 fast-follow for semver compliance. v0.3.2 ([email protected], Sigstore provenance + signed attestations) external adoption confirmed: @0xdespot ran npx -y [email protected] bazaar-check against hyperD 2026-05-23, @poteshniy (AgentTrust) shipped derivative /v1/reputation product 2026-05-26, @RipperMercs + @TKCollective ran v0.3.2 verdicts in #2207 closure loop 2026-05-26. v0.3.4 committed scope (4 items, 2026-05-29 — shipped 2026-05-30): candidate_K filed as X402-50 (payment-payload echo gap diagnose rules — @RipperMercs + @TKCollective, 2 voices, ADR-007) + candidate_G (X402-51 facilitator-fitness — Cryptor + TomSmart + @Cinderwright 3rd-touch via x402-foundation/x402#1065 PayAI workaround 2026-05-29, ADR-005 accepted 2026-05-29) + candidate_I (X402-52 #88 network-layer-fail vs x402-layer-fail — TomSmart mapper.db, 2 voices; AC reshaped 2026-05-29 per TomSmart Tuesday-traceroute anti-evidence — 13/15 sampled cohort actually reachable; multi-probe consensus + DNS/TCP/TLS failure-mode classification required, ADR-006 accepted 2026-05-29 — top-level service_unreachable verdict + probe-history-via-JSONL state) + candidate_L promoted 2026-05-29 via D.5 single-voice bypass (ADR-008): host_pollution listing-hygiene verdict — Ferj cdp-verified, anchor-x402.com 23-entry curl repro 2026-05-27, renamed H→L because H taken by RipperMercs #85 directory-only-manifest signal in Notion plan. Jira X402-53 filed + Notion plan row added 2026-05-29. Forward direction: hosted-product play converges into comprehensive agentic-commerce super-app at https://deagentic.ai/ (see [[deagentic-super-app-vision]]) — recalibrates Candidate E from standalone hosted-demo to super-app component. v0.3.2 cycle shipped seven D.x + infrastructure tickets 2026-05-21 → 2026-05-22: X402-41 ADR-004 + X402-42 D.4 --endpoint + X402-43 D.5 variant-aware extensions.bazaar + X402-44 JSON API stability + X402-45 D.2 propagation diff + X402-46 D.3 indexer-state + upstream_stuck verdict + X402-47 fixture-consumption infrastructure. Separately: X402-40 Node 22 npx ESM-resolver hang — Solana-dep drop branch shelved after 2-voice convergence (hypeprinter007's anchor-x402 Solana rail + TomSmart's x402-fetch transitive diagnostic); README install-section workaround shipped unconditionally. v0.3.1 shipped 2026-05-20 ([email protected]).
  • v0.1 wedge: Local HTTP proxy + timeout-reconciliation engine. Accepted 2026-05-12 in ADR-001. Verified via three independent live Base Sepolia settlements (tx 0x116ccf73…ba52 is the X402-15 demo capture).
  • v0.2 scope: x402trace validate (pre-flight) + x402trace explain (offline plain-English 402 diagnosis), sharing the src/diagnose/ rule engine. Picked 2026-05-12 in ADR-002. Shipped in v0.2.0..v0.2.3.
  • v0.3 scope: x402trace bazaar-check (headline) + 5 facilitator-aware diagnose rules + validate --diff cross-facilitator + Base mainnet support + versions SDK skew (stretch, shipped). Picked 2026-05-14 in ADR-003. Execution autonomous per user direction; every ticket runs through the Strict audit gate. v0.3.0 shipped 2026-05-17.
  • v0.3.1 hotfix scope: #66 + #67 + package.json description fix. Both contributor PRs merged within 12h of opening — strongest "v0.3.0 found its audience" signal so far. Third independent positive: @TomSmart_ai ran bazaar-check against 19 production endpoints, 19/19 returned implementation_issue (production-scale validation of the verdict taxonomy).
  • v0.3.2 committed scope (7 items, in-flight): D.1 manifest hygiene (shipped on main via PR #70 — needs D.5 variant-aware refactor before release) + D.2 propagation diff + D.3 indexer-state probe (introduces new top-level upstream_stuck verdict, rolls up to exit code 3) + D.4 --endpoint <paid-url> per-route probe + D.5 variant-aware extensions.bazaar (BodyDiscoveryExtension vs McpDiscoveryExtension; bug-pathway from #72) + JSON API stability commitment (snapshot tests + src/bazaar/json-api.md + versioning rule) + production-set fixture consumption (6-fixture pipeline: TomSmart 19-URL + cdp-mature + AsaiShota test-echo-cdp + evanatpizzarobot tensorfeed + 0xdespot hyperd + hypeprinter007 anchor-x402 multi-rail). ADR-004 (X402-41) lands first. Held: facilitator-status (Candidate A, 1 cluster), hosted demo (Candidate E, 1/4 signals), alt-challenge-surface (Candidate F, 1/n — 0xdespot's free-tier-upgrade observation from #2207, recorded as candidate; no implementation lean).
  • Repo: https://github.com/fardinvahdat/x402trace
  • Jira: https://vahdatfardin.atlassian.net/jira/software/projects/X402
  • Notion v0.2 plan: https://www.notion.so/35c03c62b2638159a5e2d1ecaac5ff0b
  • Notion v0.3 plan: https://www.notion.so/36003c62b26381fd9ae5c48758d53ccd
  • Notion v0.3.1+/v0.3.2 evidence page: https://www.notion.so/36503c62b26381cfbd1ce4d95fabda82 (historical evidence accumulation; v0.3.1 + #2207 cluster + cdp-mature ETA)
  • Notion v0.3.2 committed plan: https://www.notion.so/36603c62b26381b4b182ee5f6e07f002 (authoritative scope + ticket layout)

Read the full file on GitHub · 156 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 156 lines · 5,308 tokens per session scan A 231557d8e53e

Subscribe to this mod's changes

x402trace CLAUDE.md is an instructions file published in the GitHub repository fardinvahdat/x402trace (5 stars, last pushed 17d ago), licensed Apache-2.0. It adds 5,308 tokens to every session, about $0.0265 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.