Server data from the Official MCP Registry
Verify x402 payment endpoints before an AI agent pays: scam scan, on-chain checks, trust scores.
About
Verify x402 payment endpoints before an AI agent pays: scam scan, on-chain checks, trust scores.
Remote endpoints: streamable-http: https://pulsefeed.dev/mcp-server
Security Report
Valid MCP server (1 strong, 1 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry.
10 tools verified · Open access · 1 issue found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
How to Install & Connect
Available as Local & Remote
This plugin can run on your machine or connect to a hosted endpoint. during install.
Documentation
View on GitHubFrom the project's GitHub README.
PulseFeed
Verify before you pay or install.
Two questions an agent has to answer before it acts, and neither is answered by a scanner that only looks at the present:
- Is this x402 endpoint safe to pay? — liveness, a 0–100 trust score, scam flags (receiver swapped, catalog price ≠ challenge price, honeypot receiver, testnet listed as production), with a pay/avoid verdict and on-chain proof links on Base.
- Did this MCP server or npm package change after people adopted it? — an install script added in a later version, ownership swapped, repository removed, package unpublished, build provenance lost.
The second question is the one static scanners cannot answer. A rug pull is clean at review
time by construction: the package collects installs for weeks, and only then ships the patch
that runs code on npm i. Answering it requires yesterday's snapshot to exist, which is why
the series here starts on 2026-07-30 and cannot be reconstructed after the fact.
PulseFeed re-audits the whole MCP registry every night and diffs it against the previous day's snapshot, and re-probes the x402 endpoint population daily. Everything below is free, needs no key, and no account.
MCP server
Hosted, no install:
https://pulsefeed.dev/mcp-server
Streamable HTTP. Also on the official MCP registry, Smithery and Glama.
Or run it locally — see mcp/:
npx pulsefeed-x402-mcp
Tools include check_x402_endpoint (is this endpoint safe to pay), mcp_check_server
(audit before installing), mcp_drift_check (the rug-pull check — pass your own
dependency list), mcp_security_report, x402_incidents and x402_changes.
Drift badge
Put it in your README. It states what changed in your package after people adopted it:
[](https://pulsefeed.dev/mcp/drift)
Use your registry name (io.github.you/your-server) or your npm package name.
A green badge is a public claim about your package, so it is only issued when the package is
actually in our snapshot. When it is not, the badge reads unwatched in grey — never
green. Reporting absence of measurement as evidence of cleanliness is a mistake we made once
publicly and will not repeat; see the correction.
CI check
Fails the build when something you already depend on changes dangerously:
- uses: Nikolife2016/mcp-drift-action@v1
Marketplace · source. Run it on a schedule, not only on pull requests — drift happens between your commits.
Free API
No key, CORS enabled, safe to call from a browser or a catalog page:
# what changed, whole registry
curl -s "https://pulsefeed.dev/mcp/drift.json?days=7"
# only your dependencies
curl -s "https://pulsefeed.dev/mcp/drift.json?packages=pkg-a,pkg-b&days=7"
# is this x402 endpoint payable
curl -s "https://pulsefeed.dev/verify?endpoint=<url>"
Subscribe without signing up — the filter lives in the URL, so there is no subscriber database and nothing to leak:
https://pulsefeed.dev/mcp/drift.rss?packages=pkg-a,pkg-b
Full spec: /openapi.json.
Open data
- Live feed: pulsefeed.dev/mcp/drift
- Ecosystem state: pulsefeed.dev/status.json
- Dataset: Nikolife/pulsefeed-x402-security
On being wrong in public
We once published that 76% of x402 endpoints were dead. That measured our own parser, not the market, and the figure was corrected twice more after that — each time downward, each time for the same class of reason: our own behaviour recorded as somebody else's track record. The whole mechanism, every correction and the checklist that came out of it are kept at pulsefeed.dev/correction rather than quietly deleted.
If you find a number here that does not hold, open an issue — that page is where it will end up.
What's in this repository
mcp/ | the MCP server (pulsefeed-x402-mcp on npm) |
lint/ | x402-payable — is your x402 endpoint actually payable |
data/ | published series and snapshots |
server.json | manifest for the official MCP registry |
License
MIT
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
