Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add seancrecord/scvd-general-store-repo --skill scvd-x402-verifiergit clone --depth 1 https://github.com/seancrecord/scvd-general-store-repoWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/seancrecord/scvd-general-store-repo/scvd-x402-verifier)<a href="https://agentmods.dev/skills/seancrecord/scvd-general-store-repo/scvd-x402-verifier"><img src="https://agentmods.dev/badge/skills/seancrecord/scvd-general-store-repo/scvd-x402-verifier/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/seancrecord/scvd-general-store-repo/scvd-x402-verifier"><img src="https://agentmods.dev/badge/skills/seancrecord/scvd-general-store-repo/scvd-x402-verifier.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00061 | $0.01082 |
| Opus 5.5 | $0.00024 | $0.00433 |
| Sonnet 5.5 | $0.00012 | $0.00216 |
| Haiku 4.5 | $0.00006 | $0.00108 |
Grade A, and why
scvd-x402-verifier scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 20d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 37 lines — stays where its author put it; the contents beside it link to each section on GitHub.
SCVD x402 Verifier
Turn the user's verification question into a bounded check, then explain what the returned evidence establishes and what remains unknown. Follow the user's requested scope; do not run every tool for every question.
Connection and inputs
Use the connected SCVD x402 Verifier MCP tools at https://scvd.store/mcp/verifier. Read their current schemas and descriptions; client prefixes may differ. If the tools are unavailable, explain that the verifier must be connected before a check can run. Do not invent a result or silently substitute the store's full MCP server.
Ask only for missing task inputs: a public HTTPS endpoint, hostname, signed offer or receipt, defect identifier, or SCVD artifact identifier. Never request passwords, API keys, payment authorizations, seed phrases, or private keys. Do not send credential-bearing URLs. A public verification key is not a private signing key.
Calls record traffic statistics. Readiness lookup can also publish an eligible hostname and ask count in a public discovery queue and schedule a later sweep when no probe is recorded; caller identity is not included in that queue. Disclose this before a readiness lookup unless already disclosed in the interaction. If the user requires a private or side-effect-free check, explain this limitation and do not perform an incompatible call. Privacy details: https://scvd.store/privacy.
Choose the relevant check
- Current endpoint behavior: call
preflight_x402_endpointwithurl. Preserve the endpoint's path and relevant non-secret query parameters. A hostname alone is enough for history, but not enough to guess a payment endpoint. Report the returned verdict, checks, reached level, and observation time when supplied. Preserve passed, failed, and not-tested distinctions. A refusal or rate limit means the probe did not establish readiness; it is not evidence that the endpoint is broken. - Recorded history: call
lookup_endpoint_readinesswithhostwhen the user asks about previous observations or requests a current-and-historical assessment. This reads held evidence, not current uptime. Report dates, coverage counts with their denominators, and gaps. Preserve any returned tier together with its supporting fraction and evidence. No history means unknown, not failed. - Signed offer or receipt: call
verify_x402_receiptwith the exact compact JWS inartifact. Includekindonly when known. Includepublic_key_hexonly when the user supplied a public key or an established public source provides it; never invent one. Otherwise the service may resolve the issuer's did:web key. Supplying a public key avoids that issuer fetch, but the MCP call still sends the artifact to SCVD and records usage. Report conformance, signature findings, key resolution, and liveness separately. Validity against a supplied key alone does not authenticate the claimed issuer; an expired offer can conform while no longer being live. - Defect explanation: call
get_defect_definitionwith the returned or user-specified defectid. If the identifier is unknown, omitidto discover the vocabulary rather than inventing a class. Explain the observed failure and what evidence would disprove it. Distinguish a suggested remedy from a verified fix; only a new check can establish the latter. - SCVD-issued artifact: call
verify_scvd_artifactwith itsid. Reportvalid,kind, andnote. This tool does not return signed bytes or a public key, and a successful result is a service-reported signature check, not a locally reproduced verification. Use receipt verification for another issuer's compact JWS.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 20d ago First seen · 37 lines · 61 tokens per session scan A 16e79b20f938
scvd-x402-verifier is a skill published in the GitHub repository seancrecord/scvd-general-store-repo (3 stars, last pushed yesterday), licensed MIT. It adds 61 tokens to every session and 1,082 once invoked, about $0.0002 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-17.
Other skills, from other repositories
agoragentic-interchange-inspector
Inspect Agoragentic Interchange public availability and receipt evidence for agent-to-agent commerce. Use for no-spend discovery, read-only receipt checks, and Runtime Bankr hackathon evaluation. Never buys, invokes services, signs, launches tokens, or changes permissions.
bankr-shopify
Shopify Admin & Storefront GraphQL APIs via curl, with Bankr-native bridges. Manage products, orders, customers, inventory, metafields, webhooks, and bulk ops, then wire merchant data to onchain primitives — store a Bankr-resolvable handle (ENS, Twitter, Farcaster, wallet) on each customer as a metafield, expose…
web-extract
Extract public webpages as structured JSON through SameDayDesk. Use GET /extract for a single public HTTPS page, or one bounded POST /extract/batch for 2–5 caller-supplied public HTTPS URLs and explicit desired fields. A caller may explicitly request a one-item batch. Free discovery reads live schemas and 402 terms…
explicit-record
Project already-held SameDayDesk GET /extract or POST /extract/batch JSON into buyer-named records using explicit JSON Pointers and a local JSON Schema. Use when the caller already has observation JSON plus mapping and schema files. Do not fetch, pay, infer entities, or treat payment as useful output. Partial…
page-change
Offline compare of two extract-batch JSON field snapshots. Use when the caller already has two delivered POST /extract/batch JSON files and wants selected-field diffs without fetching, paying, retrying, or scheduling. Do not use to purchase a second observation. Free POST /recipes/page-change returns charged: false…
seller-repair-external-consumer
Receive a caller-owned seller repair against an authorized read-only target. The catalog fixture is only the deterministic example.