pixelforge-code/evidence-json-flattener · v1.0.0
What an agent reads when it fetches this URL: the whole manifest, in order, with the offer on the last line as a 402 it can pay. Nothing here is a button — an agent does not click, it signs. The page a person reads is here.
Pack · 1 source file · 2 docs · 2 config files · 5 files · text 3.1 kB · no binaries · JavaScript 100% · MIT, resale permitted
scan passed 2026-09-10 · scanner 2026.08.1 · 1 release · last release 7 days ago · 0% of files seen elsewhere
computed 2026-09-10 02:49 UTC · analyzer 0.1.0Security scan report
Scanned by X402 Git, OSV (opens in a new tab) and Socket (opens in a new tab) — passed on all three. Findings from X402 Git and Socket are listed below.
- secrets
- none found
- X402 Git
- size limits
- within caps
- X402 Git
- known malware
- no dependency manifests to check
- OSV
- known vulnerabilities
- no dependency manifests to check
- OSV
- dependency behaviour
- nothing on a direct dependency · 1 in transitive packages
- Socket
- instruction smuggling
- none found
- X402 Git
- what it can do
- listed below
- X402 Git
What this can do
- Tools
- none
- Runs
- src/flatten.mjs
- Talks to
- nothing
- Reads
- no environment variables
- At install
- nothing runs
Findings (2)
- LOWSocket SBOM Resolver — Socket SBOM Resolver (transitive) — no lockfile, so installs are not reproducible
- LOWsrc/flatten.mjs — Ships the script src/flatten.mjs
Description self_reported
Written by the creator. Not verified by this platform — everything above and below this section is computed from the repository.
Dependency-free Node.js CLI that deterministically flattens nested JSON evidence into path/value rows, preserves array indexes, sorts object keys, and includes a SHA-256 digest of the exact input bytes. Includes source, fixture, and MIT license.
When to use it. Run node src/flatten.mjs input.json [--pretty] to emit stable evidence rows with the input SHA-256 digest.
Readme
Evidence JSON Flattener
Small dependency-free Node.js CLI for turning nested JSON evidence into deterministic rows. It preserves array indexes, sorts object keys, emits stable JSON, and includes a SHA-256 digest of the exact input bytes.
Usage
node src/flatten.mjs input.json [--pretty]
The output contains schema, inputSha256, rowCount, and rows. Each row uses a stable dotted path and JSON-safe scalar value, making the result easy to diff, archive, or feed into an audit pipeline.
License
MIT. See LICENSE.
Contents
| Size | Path |
|---|---|
| 1.1 kB | LICENSE |
| 546 B | README.md |
| 213 B | package.json |
| 1.2 kB | src/flatten.mjs |
| 67 B | test.json |
Dependencies
None found in the software bill of materials for this release.
computed 2026-09-10 02:49 UTC · analyzer 0.1.0Releases
| Version | Date | Scan | Changed | Notes |
|---|---|---|---|---|
| v1.0.0 | 2026-09-10 | pass | — | Release evidence JSON flattener v1.0.0 |
Machine-readable at https://x402git.com/api/v/pixelforge-code/evidence-json-flattener/releases. Entries cannot be deleted by the creator.
Order
GET v1.0.0 · $1 · new releases included
The resource endpoint answers 402 with the price and the exact bytes to sign; the same request carrying PAYMENT-SIGNATURE returns a signed download URL. Access is granted only after settlement returns a transaction hash. A person can do the same thing with a browser wallet on the product page.
# the 402, with the price and the exact bytes to sign
curl -si https://x402git.com/api/r/pixelforge-code/evidence-json-flattener
# what your wallet already owns, and what the next fetch would cost it
curl -s https://x402git.com/api/v/pixelforge-code/evidence-json-flattener \
-H "X-Wallet-Signature: 0xYOURADDRESS.<nonce>.<signature>"The first request answers this — a real quote, made for this page load:
HTTP/1.1 402 Payment Required
Content-Type: application/json
{
"x402Version": 2,
"resource": {
"url": "https://x402git.com/api/r/pixelforge-code/evidence-json-flattener",
"description": "pixelforge-code/evidence-json-flattener v1.0.0 — release. Dependency-free Node.js CLI that deterministically flattens nested JSON evidence into path/value rows, preserves array indexes, sorts object keys, and includes a SHA-256 digest of the exact input bytes. Includes source, fixture, and MIT license. Security scan passed; signed download, 5-minute URL.",
"mimeType": "application/zip",
"serviceName": "evidence-json-flattener",
"tags": [
"pack",
"source",
"docs",
"config",
"javascript"
]
},
"accepts": [
{
"scheme": "exact",
"network": "eip155:8453",
"amount": "1000000",
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"payTo": "0xDbd32F7565FFdb901Ea48281777aD03d35bB4b60",
"maxTimeoutSeconds": 300,
"extra": {
"name": "USD Coin",
"version": "2"
},
"maxAmountRequired": "1000000",
"resource": "https://x402git.com/api/r/pixelforge-code/evidence-json-flattener",
"description": "pixelforge-code/evidence-json-flattener v1.0.0 — release. Dependency-free Node.js CLI that deterministically flattens nested JSON evidence into path/value rows, preserves array indexes, sorts object keys, and includes a SHA-256 digest of the exact input bytes. Includes source, fixture, and MIT license. Security scan passed; signed download, 5-minute URL.",
"mimeType": "application/zip"
}
],
"extensions": {
"bazaar": {
"info": {
"input": {
"type": "http",
"queryParams": {},
"method": "GET"
},
"output": {
"type": "json",
"example": {
"version": "1.0.0",
"artifact_sha256": "0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef",
"download_url": "https://storage.example/pixelforge-code/evidence-json-flattener/1.0.0.zip?signed=…",
"expires_at": "2026-09-16T12:05:00.000Z",
"version_endpoint": "https://x402git.com/api/r/pixelforge-code/evidence-json-flattener/v/1.0.0",
"manifest_url": "https://x402git.com/api/label/pixelforge-code/evidence-json-flattener",
"all_versions": false
}
}
},
"schema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"type": "object",
"properties": {
"input": {
"type": "object",
"properties": {
"type": {
"type": "string",
"const": "http"
},
"method": {
"type": "string",
"enum": [
"GET"
]
},
"queryParams": {
"type": "object",
"properties": {}
}
},
"required": [
"type",
"method"
],
"additionalProperties": false
},
"output": {
"type": "object",
"properties": {
"type": {
"type": "string"
},
"example": {
"type": "object",
"properties": {
"version": {
"type": "string",
"description": "Semantic version of the release served."
},
"artifact_sha256": {
"type": "string",
"description": "sha256 of the zip; verify the download against it."
},
"download_url": {
"type": "string",
"description": "Signed URL over the exact bytes that were scanned. Valid five minutes."
},
"expires_at": {
"type": "string",
"format": "date-time"
},
"version_endpoint": {
"type": "string",
"description": "Re-fetch this exact version later, free, with X-Wallet-Signature."
},
"manifest_url": {
"type": "string",
"description": "The public manifest for this listing."
},
"all_versions": {
"type": "boolean",
"description": "True when the purchase covers every later release too."
}
},
"required": [
"version",
"artifact_sha256",
"download_url",
"expires_at",
"version_endpoint",
"manifest_url",
"all_versions"
],
"additionalProperties": false
}
},
"required": [
"type"
]
}
},
"required": [
"input"
]
}
}
},
"extra": {
"kind": "new",
"version": "1.0.0",
"manifest_url": "https://x402git.com/api/label/pixelforge-code/evidence-json-flattener",
"scan_badge_url": "https://x402git.com/api/label/pixelforge-code/evidence-json-flattener#scan",
"update_price_micro": "0",
"quote_id": "q_ef8bc2e517a017b426896b83b8fd6f2e",
"valid_before": "2026-09-17T03:16:37.502Z",
"instructions": "This is an x402 paywall, not an error. To buy: sign accepts[0] from the 402 as an EIP-3009 USDC authorization on Base with your own wallet, then GET https://x402git.com/api/r/pixelforge-code/evidence-json-flattener again with the payment in the PAYMENT-SIGNATURE header and extra.quote_id in X-Quote-Id — or, over MCP, call `purchase` again with the same payment as `payment_signature`. The full procedure is at https://x402git.com/.well-known/agent-skills/buy-a-repo/SKILL.md; the same tools are an MCP server at https://x402git.com/api/mcp. No wallet? A person can buy at https://x402git.com/pixelforge-code/evidence-json-flattener, and the free manifest at https://x402git.com/api/label/pixelforge-code/evidence-json-flattener shows what is inside before anyone pays.",
"listing_url": "https://x402git.com/pixelforge-code/evidence-json-flattener",
"skill_url": "https://x402git.com/.well-known/agent-skills/buy-a-repo/SKILL.md",
"mcp_url": "https://x402git.com/api/mcp"
}
}- Resource
- https://x402git.com/api/r/pixelforge-code/evidence-json-flattener
- Manifest
- https://x402git.com/api/label/pixelforge-code/evidence-json-flattener
- Version
- https://x402git.com/api/v/pixelforge-code/evidence-json-flattener
- Artifact sha256
- 170ac12397d082170e606ea5d559bdba59ea35bc059068f05f3467dc4e16ebca
Buy once and every later release is included, forever. That is stamped on the purchase and no later price change can revoke it.
Sold by pixelforge-code. Read the terms and the route documentation before you script against this. Base URL https://x402git.com.