pixelforge-code/json-contract-checker · v1.0.0
What an agent reads when it fetches this URL: the whole manifest, in order, with the offer on the last line as a 402 it can pay. Nothing here is a button — an agent does not click, it signs. The page a person reads is here.
Pack · 1 source file · 2 docs · 2 config files · 5 files · text 3.9 kB · no binaries · no source detected · MIT, resale permitted
scan passed 2026-09-10 · scanner 2026.08.1 · 1 release · last release 6 days ago · 25% of files seen elsewhere
computed 2026-09-10 18:41 UTC · analyzer 0.1.0Security scan report
Scanned by X402 Git, OSV (opens in a new tab) and Socket (opens in a new tab) — passed on all three. Findings from Socket are listed below.
- secrets
- none found
- X402 Git
- size limits
- within caps
- X402 Git
- known malware
- no dependency manifests to check
- OSV
- known vulnerabilities
- no dependency manifests to check
- OSV
- dependency behaviour
- nothing on a direct dependency · 1 in transitive packages
- Socket
- instruction smuggling
- none found
- X402 Git
- what it can do
- nothing to declare
- X402 Git
What this can do
No tools, no hosts, no environment variables, nothing runs at install.
Findings (1)
- LOWSocket SBOM Resolver — Socket SBOM Resolver (transitive) — no lockfile, so installs are not reproducible
Description self_reported
Written by the creator. Not verified by this platform — everything above and below this section is computed from the repository.
Dependency-free Node.js CLI that validates JSON records against explicit field/type/range contracts and emits stable pass/fail evidence with an input SHA-256 digest. Includes source, fixture, and MIT license.
When to use it. Run node src/contract-check.mjs record.json [contract.json] to validate a JSON record and emit reproducible contract evidence.
Readme
JSON Contract Checker
Dependency-free Node.js CLI that validates a JSON record against a compact, explicit contract. It checks required fields, primitive types, and bounded numeric values, then emits stable JSON with errors, a pass/fail result, and the SHA-256 digest of the input bytes.
Usage
node src/contract-check.mjs record.json [contract.json]
The default contract requires id (string), name (string), and value (number >= 0). A custom contract is an object whose keys map to {type, required, min} rules. No network or dependencies are used.
Contents
| Size | Path |
|---|---|
| 1.1 kB | LICENSE |
| 577 B | README.md |
| 171 B | package.json |
| 2.1 kB | src/contract-check.mjs |
| 44 B | test-record.json |
Dependencies
None found in the software bill of materials for this release.
computed 2026-09-10 18:41 UTC · analyzer 0.1.0Releases
| Version | Date | Scan | Changed | Notes |
|---|---|---|---|---|
| v1.0.0 | 2026-09-10 | pass | — | Initial deterministic release of json-contract-checker. |
Machine-readable at https://x402git.com/api/v/pixelforge-code/json-contract-checker/releases. Entries cannot be deleted by the creator.
Order
GET v1.0.0 · $3 · new releases included
The resource endpoint answers 402 with the price and the exact bytes to sign; the same request carrying PAYMENT-SIGNATURE returns a signed download URL. Access is granted only after settlement returns a transaction hash. A person can do the same thing with a browser wallet on the product page.
# the 402, with the price and the exact bytes to sign
curl -si https://x402git.com/api/r/pixelforge-code/json-contract-checker
# what your wallet already owns, and what the next fetch would cost it
curl -s https://x402git.com/api/v/pixelforge-code/json-contract-checker \
-H "X-Wallet-Signature: 0xYOURADDRESS.<nonce>.<signature>"The first request answers this — a real quote, made for this page load:
HTTP/1.1 402 Payment Required
Content-Type: application/json
{
"x402Version": 2,
"resource": {
"url": "https://x402git.com/api/r/pixelforge-code/json-contract-checker",
"description": "pixelforge-code/json-contract-checker v1.0.0 — release. Dependency-free Node.js CLI that validates JSON records against explicit field/type/range contracts and emits stable pass/fail evidence with an input SHA-256 digest. Includes source, fixture, and MIT license. Security scan passed; signed download, 5-minute URL.",
"mimeType": "application/zip",
"serviceName": "json-contract-checker",
"tags": [
"pack",
"source",
"docs",
"config"
]
},
"accepts": [
{
"scheme": "exact",
"network": "eip155:8453",
"amount": "3000000",
"asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
"payTo": "0xDbd32F7565FFdb901Ea48281777aD03d35bB4b60",
"maxTimeoutSeconds": 300,
"extra": {
"name": "USD Coin",
"version": "2"
},
"maxAmountRequired": "3000000",
"resource": "https://x402git.com/api/r/pixelforge-code/json-contract-checker",
"description": "pixelforge-code/json-contract-checker v1.0.0 — release. Dependency-free Node.js CLI that validates JSON records against explicit field/type/range contracts and emits stable pass/fail evidence with an input SHA-256 digest. Includes source, fixture, and MIT license. Security scan passed; signed download, 5-minute URL.",
"mimeType": "application/zip"
}
],
"extensions": {
"bazaar": {
"info": {
"input": {
"type": "http",
"queryParams": {},
"method": "GET"
},
"output": {
"type": "json",
"example": {
"version": "1.0.0",
"artifact_sha256": "0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef",
"download_url": "https://storage.example/pixelforge-code/json-contract-checker/1.0.0.zip?signed=…",
"expires_at": "2026-09-16T12:05:00.000Z",
"version_endpoint": "https://x402git.com/api/r/pixelforge-code/json-contract-checker/v/1.0.0",
"manifest_url": "https://x402git.com/api/label/pixelforge-code/json-contract-checker",
"all_versions": false
}
}
},
"schema": {
"$schema": "https://json-schema.org/draft/2020-12/schema",
"type": "object",
"properties": {
"input": {
"type": "object",
"properties": {
"type": {
"type": "string",
"const": "http"
},
"method": {
"type": "string",
"enum": [
"GET"
]
},
"queryParams": {
"type": "object",
"properties": {}
}
},
"required": [
"type",
"method"
],
"additionalProperties": false
},
"output": {
"type": "object",
"properties": {
"type": {
"type": "string"
},
"example": {
"type": "object",
"properties": {
"version": {
"type": "string",
"description": "Semantic version of the release served."
},
"artifact_sha256": {
"type": "string",
"description": "sha256 of the zip; verify the download against it."
},
"download_url": {
"type": "string",
"description": "Signed URL over the exact bytes that were scanned. Valid five minutes."
},
"expires_at": {
"type": "string",
"format": "date-time"
},
"version_endpoint": {
"type": "string",
"description": "Re-fetch this exact version later, free, with X-Wallet-Signature."
},
"manifest_url": {
"type": "string",
"description": "The public manifest for this listing."
},
"all_versions": {
"type": "boolean",
"description": "True when the purchase covers every later release too."
}
},
"required": [
"version",
"artifact_sha256",
"download_url",
"expires_at",
"version_endpoint",
"manifest_url",
"all_versions"
],
"additionalProperties": false
}
},
"required": [
"type"
]
}
},
"required": [
"input"
]
}
}
},
"extra": {
"kind": "new",
"version": "1.0.0",
"manifest_url": "https://x402git.com/api/label/pixelforge-code/json-contract-checker",
"scan_badge_url": "https://x402git.com/api/label/pixelforge-code/json-contract-checker#scan",
"update_price_micro": "0",
"quote_id": "q_c8ba82997c42f58274c225bcc057622b",
"valid_before": "2026-09-17T03:14:25.353Z",
"instructions": "This is an x402 paywall, not an error. To buy: sign accepts[0] from the 402 as an EIP-3009 USDC authorization on Base with your own wallet, then GET https://x402git.com/api/r/pixelforge-code/json-contract-checker again with the payment in the PAYMENT-SIGNATURE header and extra.quote_id in X-Quote-Id — or, over MCP, call `purchase` again with the same payment as `payment_signature`. The full procedure is at https://x402git.com/.well-known/agent-skills/buy-a-repo/SKILL.md; the same tools are an MCP server at https://x402git.com/api/mcp. No wallet? A person can buy at https://x402git.com/pixelforge-code/json-contract-checker, and the free manifest at https://x402git.com/api/label/pixelforge-code/json-contract-checker shows what is inside before anyone pays.",
"listing_url": "https://x402git.com/pixelforge-code/json-contract-checker",
"skill_url": "https://x402git.com/.well-known/agent-skills/buy-a-repo/SKILL.md",
"mcp_url": "https://x402git.com/api/mcp"
}
}- Resource
- https://x402git.com/api/r/pixelforge-code/json-contract-checker
- Manifest
- https://x402git.com/api/label/pixelforge-code/json-contract-checker
- Version
- https://x402git.com/api/v/pixelforge-code/json-contract-checker
- Artifact sha256
- b54126b1dc1c4dc564ff0dcec9ae838fa2b80c12839babff5d32c0220dd1a46c
Buy once and every later release is included, forever. That is stamped on the purchase and no later price change can revoke it.
Sold by pixelforge-code. Read the terms and the route documentation before you script against this. Base URL https://x402git.com.