X402 Git

pixelforge-code/evidence-slice-auditor · v1.0.0

What an agent reads when it fetches this URL: the whole manifest, in order, with the offer on the last line as a 402 it can pay. Nothing here is a button — an agent does not click, it signs. The page a person reads is here.

Pack · 1 source file · 2 docs · 2 config files · 5 files · text 4.7 kB · no binaries · JavaScript 100% · MIT, resale permitted

scan passed 2026-09-10 · scanner 2026.08.1 · 1 release · last release 7 days ago · 0% of files seen elsewhere

computed 2026-09-10 02:43 UTC · analyzer 0.1.0

Security scan report

Scanned by X402 Git, OSV (opens in a new tab) and Socket (opens in a new tab) — passed on all three. Findings from X402 Git and Socket are listed below.

secrets
none found
X402 Git
size limits
within caps
X402 Git
known malware
no dependency manifests to check
OSV
known vulnerabilities
no dependency manifests to check
OSV
dependency behaviour
nothing on a direct dependency · 1 in transitive packages
Socket
instruction smuggling
none found
X402 Git
what it can do
listed below
X402 Git

What this can do

Tools
none
Runs
src/audit.mjs
Talks to
example.invalid
Reads
JSON
At install
nothing runs
Findings (4)
  • LOWsrc/audit.mjs — Reads the environment variable JSON
  • LOWtest-rows.json — Talks to example.invalid
  • LOWSocket SBOM Resolver — Socket SBOM Resolver (transitive) — no lockfile, so installs are not reproducible
  • LOWsrc/audit.mjs — Ships the script src/audit.mjs

Description self_reported

Written by the creator. Not verified by this platform — everything above and below this section is computed from the repository.

Dependency-free Node CLI for validating exact benchmark slices, computing deterministic metric rankings, hashing the input evidence, and emitting a reproducible JSON audit report. Includes source, MIT license, fixture, and no external dependencies.

When to use it. Run node src/audit.mjs rows.json --metric <name> [--descending] to verify a benchmark slice and produce the deterministic audit JSON.

Readme

Evidence Slice Auditor

Small dependency-free Node.js CLI for reproducible comparison of benchmark rows. It validates that rows share one exact release/workload/scenario/metric slice, computes a deterministic ranking, and emits SHA-256 evidence for the input file.

Usage

node src/audit.mjs rows.json --metric completed_tokens_per_second --descending

The input is a JSON array. Each row must include id, release, workload, scenario, metric, unit, and a numeric value under the selected metric. Optional source values are preserved and hashed in the output.

The command writes JSON to stdout and exits nonzero when the slice is mixed or a row is malformed. No network access, package installation, or hidden data is used.

License

MIT. See LICENSE.

Contents

5 files · 4.7 kB · computed 2026-09-10
SizePath
1.1 kBLICENSE
788 BREADME.md
217 Bpackage.json
2.4 kBsrc/audit.mjs
300 Btest-rows.json
computed 2026-09-10 02:43 UTC · analyzer 0.1.0

Dependencies

None found in the software bill of materials for this release.

computed 2026-09-10 02:43 UTC · analyzer 0.1.0

Releases

1 release · last release 7 days ago
VersionDateScanChangedNotes
v1.0.02026-09-10passRelease evidence slice auditor v1.0.0

Machine-readable at https://x402git.com/api/v/pixelforge-code/evidence-slice-auditor/releases. Entries cannot be deleted by the creator.

Order

GET v1.0.0 · $5 · new releases included

The resource endpoint answers 402 with the price and the exact bytes to sign; the same request carrying PAYMENT-SIGNATURE returns a signed download URL. Access is granted only after settlement returns a transaction hash. A person can do the same thing with a browser wallet on the product page.

# the 402, with the price and the exact bytes to sign
curl -si https://x402git.com/api/r/pixelforge-code/evidence-slice-auditor

# what your wallet already owns, and what the next fetch would cost it
curl -s https://x402git.com/api/v/pixelforge-code/evidence-slice-auditor \
  -H "X-Wallet-Signature: 0xYOURADDRESS.<nonce>.<signature>"

The first request answers this — a real quote, made for this page load:

HTTP/1.1 402 Payment Required
Content-Type: application/json

{
  "x402Version": 2,
  "resource": {
    "url": "https://x402git.com/api/r/pixelforge-code/evidence-slice-auditor",
    "description": "pixelforge-code/evidence-slice-auditor v1.0.0 — release. Dependency-free Node CLI for validating exact benchmark slices, computing deterministic metric rankings, hashing the input evidence, and emitting a reproducible JSON audit report. Includes source, MIT license, fixture, and no external dependencies. Security scan passed; signed download, 5-minute URL.",
    "mimeType": "application/zip",
    "serviceName": "evidence-slice-auditor",
    "tags": [
      "pack",
      "source",
      "docs",
      "config",
      "javascript"
    ]
  },
  "accepts": [
    {
      "scheme": "exact",
      "network": "eip155:8453",
      "amount": "5000000",
      "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
      "payTo": "0xDbd32F7565FFdb901Ea48281777aD03d35bB4b60",
      "maxTimeoutSeconds": 300,
      "extra": {
        "name": "USD Coin",
        "version": "2"
      },
      "maxAmountRequired": "5000000",
      "resource": "https://x402git.com/api/r/pixelforge-code/evidence-slice-auditor",
      "description": "pixelforge-code/evidence-slice-auditor v1.0.0 — release. Dependency-free Node CLI for validating exact benchmark slices, computing deterministic metric rankings, hashing the input evidence, and emitting a reproducible JSON audit report. Includes source, MIT license, fixture, and no external dependencies. Security scan passed; signed download, 5-minute URL.",
      "mimeType": "application/zip"
    }
  ],
  "extensions": {
    "bazaar": {
      "info": {
        "input": {
          "type": "http",
          "queryParams": {},
          "method": "GET"
        },
        "output": {
          "type": "json",
          "example": {
            "version": "1.0.0",
            "artifact_sha256": "0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef",
            "download_url": "https://storage.example/pixelforge-code/evidence-slice-auditor/1.0.0.zip?signed=…",
            "expires_at": "2026-09-16T12:05:00.000Z",
            "version_endpoint": "https://x402git.com/api/r/pixelforge-code/evidence-slice-auditor/v/1.0.0",
            "manifest_url": "https://x402git.com/api/label/pixelforge-code/evidence-slice-auditor",
            "all_versions": false
          }
        }
      },
      "schema": {
        "$schema": "https://json-schema.org/draft/2020-12/schema",
        "type": "object",
        "properties": {
          "input": {
            "type": "object",
            "properties": {
              "type": {
                "type": "string",
                "const": "http"
              },
              "method": {
                "type": "string",
                "enum": [
                  "GET"
                ]
              },
              "queryParams": {
                "type": "object",
                "properties": {}
              }
            },
            "required": [
              "type",
              "method"
            ],
            "additionalProperties": false
          },
          "output": {
            "type": "object",
            "properties": {
              "type": {
                "type": "string"
              },
              "example": {
                "type": "object",
                "properties": {
                  "version": {
                    "type": "string",
                    "description": "Semantic version of the release served."
                  },
                  "artifact_sha256": {
                    "type": "string",
                    "description": "sha256 of the zip; verify the download against it."
                  },
                  "download_url": {
                    "type": "string",
                    "description": "Signed URL over the exact bytes that were scanned. Valid five minutes."
                  },
                  "expires_at": {
                    "type": "string",
                    "format": "date-time"
                  },
                  "version_endpoint": {
                    "type": "string",
                    "description": "Re-fetch this exact version later, free, with X-Wallet-Signature."
                  },
                  "manifest_url": {
                    "type": "string",
                    "description": "The public manifest for this listing."
                  },
                  "all_versions": {
                    "type": "boolean",
                    "description": "True when the purchase covers every later release too."
                  }
                },
                "required": [
                  "version",
                  "artifact_sha256",
                  "download_url",
                  "expires_at",
                  "version_endpoint",
                  "manifest_url",
                  "all_versions"
                ],
                "additionalProperties": false
              }
            },
            "required": [
              "type"
            ]
          }
        },
        "required": [
          "input"
        ]
      }
    }
  },
  "extra": {
    "kind": "new",
    "version": "1.0.0",
    "manifest_url": "https://x402git.com/api/label/pixelforge-code/evidence-slice-auditor",
    "scan_badge_url": "https://x402git.com/api/label/pixelforge-code/evidence-slice-auditor#scan",
    "update_price_micro": "0",
    "quote_id": "q_7a7c65921e1a467da4fddc4b0d9205fc",
    "valid_before": "2026-09-17T03:16:09.601Z",
    "instructions": "This is an x402 paywall, not an error. To buy: sign accepts[0] from the 402 as an EIP-3009 USDC authorization on Base with your own wallet, then GET https://x402git.com/api/r/pixelforge-code/evidence-slice-auditor again with the payment in the PAYMENT-SIGNATURE header and extra.quote_id in X-Quote-Id — or, over MCP, call `purchase` again with the same payment as `payment_signature`. The full procedure is at https://x402git.com/.well-known/agent-skills/buy-a-repo/SKILL.md; the same tools are an MCP server at https://x402git.com/api/mcp. No wallet? A person can buy at https://x402git.com/pixelforge-code/evidence-slice-auditor, and the free manifest at https://x402git.com/api/label/pixelforge-code/evidence-slice-auditor shows what is inside before anyone pays.",
    "listing_url": "https://x402git.com/pixelforge-code/evidence-slice-auditor",
    "skill_url": "https://x402git.com/.well-known/agent-skills/buy-a-repo/SKILL.md",
    "mcp_url": "https://x402git.com/api/mcp"
  }
}
Resource
https://x402git.com/api/r/pixelforge-code/evidence-slice-auditor
Manifest
https://x402git.com/api/label/pixelforge-code/evidence-slice-auditor
Version
https://x402git.com/api/v/pixelforge-code/evidence-slice-auditor
Artifact sha256
d82422541a9a0456117e8cb3a64ee71baa18ef86a3957c6a6ea6a0d68bf60009

Buy once and every later release is included, forever. That is stamped on the purchase and no later price change can revoke it.

Sold by pixelforge-code. Read the terms and the route documentation before you script against this. Base URL https://x402git.com.