SkillAgentSearch skills...

jev-risk-check-provider

x402 risk-check provider: signed pre-payment verdicts — OFAC, phishing feeds, transaction simulation, drainer-kit code, and our own EIP-7702 kit watch (poisoners, sweepers). $0.001 per check with prepaid credits; per call via x402 from $0.0035.

Install / Use

claude mcp add caiovicentino -- npx -y github:caiovicentino/jev-risk-check-provider

If the server publishes to npm under a different name, use that package instead — check the repo README.

About this skill
🔌

MCP Server

Model Context Protocol server

Quality Score

84/100

Category

Security

Supported Platforms

Claude Code
Claude Desktop

Our assessment of jev-risk-check-provider

jev-risk-check-provider scores 84/100 on our quality scale, 856th of 1,122 Security skills we index.

Its MCP Server is 32 KB long, well organised into 20 sections with 10 code examples: a thorough specification that gives an agent plenty to work with.

It has 10 GitHub stars, so there is little community track record yet; judge it on its content.

Substance
30/30
Structure
20/20
Description
15/15
Adoption
4/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated today, so jev-risk-check-provider is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 97/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

jev-risk-check-provider compared with similar skills

All 4 of these similar skills score higher than jev-risk-check-provider; compare them before choosing.

SkillScoreStarsUpdatedFormat
jev-risk-check-provider (this skill)by caiovicentino8410todayMCP Server
Agent-Reachby Panniantong10093.0k22d agoCLAUDE.md
headroomby headroomlabs-ai10074.6ktodayCLAUDE.md
CowAgentby zhayujie10047.3ktodayCLAUDE.md
Scraplingby D4Vinci10086.1ktodayMCP Server

Frequently asked questions

How do I install jev-risk-check-provider?
Run claude mcp add caiovicentino -- npx -y github:caiovicentino/jev-risk-check-provider. The install tabs above show the steps for each supported agent.
Which AI agents does jev-risk-check-provider work with?
It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
Is jev-risk-check-provider safe to use?
It is MIT-licensed and scores 97/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is jev-risk-check-provider still maintained?
The repository was last updated today, so jev-risk-check-provider is actively maintained.

x402check — pre-payment risk checks for x402 agents and wallets

LIVE: https://x402check.xyz · did:web:x402check.xyz · $0.001 per evaluation with prepaid credits, or per call via x402 ($0.0035 on Base; $0.005 with transaction simulation) · discovery · DID document · JWKS

x402check is an x402 risk-check provider (wire format of x402 PR #2422). You call it before an agent or a wallet pays or signs, and it checks the counterparty. It combines provider-verified evidence with a typed model:

  • the OFAC SDN list, refreshed daily;
  • curated phishing and drainer feeds;
  • transaction simulation: where the assets actually go, and which approvals are granted;
  • drainer-kit code fingerprints, which recognize redeployed drainer contracts before their address is listed;
  • our own kit watch: every Ethereum and Base block is read as it is produced. It records look-alike wallets that delegate (EIP-7702) to an address-poisoning executor, wallets whose delegate forwards whatever they receive (sweepers), and new contracts running drainer-kit code;
  • look-alike domain analysis;
  • on-chain facts about the counterparty, such as whether an approval is being granted to a plain wallet;
  • a typed model (TypeSafe Jev) that reads the content the agent acted on for injected instructions.

Every verdict is an ES256 attestation. It states which checks the provider actually ran and which fields the caller merely asserted.

Scope, stated plainly. x402check catches what the chain, the lists, its own kit watch, and the content in front of it reveal. It does not see laundering patterns or other transaction-graph behaviour. It cannot flag an unknown drainer address that is simply sent funds, unless the address is one of the look-alikes or compromised wallets the kit watch has seen. A clean verdict means "none of these checks fired", not "safe". Measured limits are in docs/EVIDENCE.md.

x402check demo

<sub>The demo video predates v0.2.0. Its evidence slide shows v5 corpus numbers that EVIDENCE.md supersedes, and it predates the v0.3 layers (simulation, code fingerprints) and pricing (every evaluation is paid; there is no free tier).</sub>

What it checks

| Check | Source | Effect on the verdict | |---|---|---| | Sanctioned address | Official OFAC SDN XML: 1,056 digital-currency addresses, dated snapshot | score 0 / critical, deterministic, no model call | | Known phishing domain | MetaMask eth-phishing-detect (~100k hosts, embedded) | capped at 20 (critical) | | Known drainer / scam address | ScamSniffer (EVM, runtime KV, 7-day publication lag) | capped at 20 | | Community-flagged domain | ScamSniffer domain list | capped at 40 only when our own domain analysis corroborates it | | Look-alike domain | public-suffix aware: leet, IDN homoglyphs, typosquats, brand + lure word, official domain reused as a subdomain | "strong" impersonation → capped at 40 | | Approval granted to a plain wallet | on-chain eth_getCode / activity (EVM), account data (Solana) | permits and approvals to an EOA → capped at 55; 40 if the address has no activity | | Hidden recipient | simulation of transaction (eth_simulateV1 + traceTransfers) | assets leave, nothing comes back, and a wallet the user never named ends up with them → 40 (75, review, when a source-verified contract such as a bridge forwarded them) | | Payee gets more than declared | simulation + payment / the explicit transfer in the calldata | the named payee receives a different asset, or more, than declared → 40 | | Assets parked in an unverified contract | simulation + Blockscout source verification | nothing in return, contract source not verified → 55 | | Drainer-kit code | logic-code fingerprints of contracts listed by Forta (embedded) and ScamSniffer (runtime) | the subject, or a contract in the simulated transaction, runs a listed drainer's code → 30 | | Address-poisoning look-alike | kit watch (our own scan of every Ethereum and Base block) | the wallet delegates (EIP-7702) to an address-poisoning executor → 20 (address_poisoning) | | Compromised wallet | kit watch | the wallet delegates to a labelled sweeper family → 20 (compromised_wallet); to code that forwards what it receives, with no label → 40 (auto_forwarding_wallet) | | Drainer operator | kit watch | the address deployed drainer-kit code → 30 (drainer_operator). A forwarder's destinations are not flagged (v0.6.0): whoever deploys a forwarder chooses them | | Unverified spender | Blockscout source verification | approval or permit to an unverified contract → 75 and at least medium (review) | | Injected / manipulated intent | Jev typed questions over context (what the agent acted on) | model penalties and caps | | New address | on-chain activity | informational new_address category |

Caller-supplied screening and authorization fields are recorded as asserted in the attestation and can never lower the score. Prose claims such as "already screened" are unverified by construction.

Quickstart

Every evaluation is paid; there is no free tier. There are two ways to pay:

  • Prepaid credits: one x402 payment buys a balance, and each check then costs $0.001 with no payment round trip. This is the cheapest and fastest option.
  • Per call: an x402 client pays when it gets the 402 and retries.
  1. See the price. An unpaid call returns 402 with the accepted mainnet options in the PAYMENT-REQUIRED header:

    curl -si -X POST https://x402check.xyz/v1/risk-check -H "Content-Type: application/json" -d '{"wallet":"0x7a3e8f0c2b1d4e5f6a7b8c9d0e1f2a3b4c5d6e7f","chain":"base"}' | head -1
    # HTTP/2 402
    
  2. Pay and check. Use the TypeScript SDK with an x402-paying fetch (see Payments), the MCP server, or any x402 client:

    const verdict = await x402check.check({
      wallet: "0x7a3e8f0c2b1d4e5f6a7b8c9d0e1f2a3b4c5d6e7f",
      chain: "eip155:1",
      domain: "https://app.example-dapp.org",
      context: "Permit2 signature: unlimited USDC allowance to this spender",
      interaction: { type: "permit_signature", unlimited: true },
      payment: { network: "eip155:1", asset: "0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48", pay_to: "0x7a3e8f0c2b1d4e5f6a7b8c9d0e1f2a3b4c5d6e7f" },
    });
    

The same request as the raw body the client sends:

curl -X POST https://x402check.xyz/v1/risk-check \
  -H "Content-Type: application/json" \
  -H "PAYMENT-SIGNATURE: <x402 payment payload>" \
  -d '{
    "wallet": "0x7a3e8f0c2b1d4e5f6a7b8c9d0e1f2a3b4c5d6e7f",
    "chain": "eip155:1",
    "domain": "https://app.example-dapp.org",
    "context": "Permit2 signature: unlimited USDC allowance to this spender",
    "interaction": { "type": "permit_signature", "unlimited": true },
    "payment": { "network": "eip155:1", "asset": "0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48", "pay_to": "0x7a3e8f0c2b1d4e5f6a7b8c9d0e1f2a3b4c5d6e7f" }
  }'
{
  "checked": true,
  "score": 40,
  "tier": "high",
  "categories": ["intent_risk", "behavioral", "approval_to_eoa", "new_address"],
  "provider": "did:web:x402check.xyz",
  "evidence": {
    "sanctions": { "list": "ofac-sdn", "as_of": "2026-09-29", "status": "not_listed" },
    "domain": { "host": "app.example-dapp.org", "registrable": "example-dapp.org", "official": false, "impersonation": "none", "signals": [] },
    "onchain": { "status": "ok", "network": "eip155:1", "is_contract": false, "activity": "none", "tx_count": 0 },
    "feeds": [{ "source": "metamask-phishing-detect", "kind": "domain", "as_of": "2026-09-29", "status": "clear" }, "…"],
    "model": "jev-wallet-risk/v6"
  },
  "jws": "eyJhbGciOiJFUzI1NiIsInR5cCI6InJpc2stY2hlY2srand0Ii…",
  "jwks_url": "https://x402check.xyz/.well-known/jwks.json",
  "checked_at": "…", "expires_at": "…"
}

To also check what a transaction will do, send it as transaction ($0.005 per simulated evaluation). The provider simulates it against the latest block and reports the net asset movements, the approvals granted, and any findings:

curl -X POST https://x402check.xyz/v1/risk-check -H "Content-Type: application/json" -d '{
  "wallet": "0x…called contract or decoded counterparty…", "chain": "eip155:1",
  "transaction": { "from": "0x…user…", "to": "0x…contract…", "value": "0x2386f26fc10000", "data": "0x…" }
}'
# evidence.simulation → { "status": "ok", "outflows": [{ "standard": "native", "amount": "10000000000000000",
#   "counterparty": "0x…", "counterparty_is_contract": false }], "inflows": [], "approvals": [],
#   "findings": ["outflow_to_undisclosed_eoa"] }   → score capped at 40

Request fields

| Field | Required | Rules | |---|---|---| | wallet | yes | the subject address: EVM 0x…, base58 (Solana/Tron/BTC…), bech32, cashaddr, or CAIP-10. Anything else → 422 {error, field:"wallet"} | | chain | no | alias (ethereum, base, solana, …) or a known CAIP-2 id (eip155:8453, the Solana mainnet or devnet id, bip122:…, tron:…); enables on-chain facts on supported mainnets. An unknown id (solana:mainnet) or a chain that cannot hold the wallet (an EVM address with solana) → 422 | | domain | no | hostname or http(s) URL (normalized server-side); the site the payment or signature is for | | context | no | ≤ 4096 chars: what the agent acted on (tool output, page text, instruction). Untrusted by design. Leave out secrets and personal data: keys, seed phrases and credit tokens are redacted before the model sees it, but nothing else is (see Data handling) | | interaction | no | {type, unlimited?}; type ∈ native_transfer, token_transfer, token_approval, nft_approval, permit_signature, order_signature, message_signature, contract_call | | payment | no | binds the attestation to a payment: {network, pay_to, amount (base units), asset, resource} | | aud | no | ≤ 256 chars; copied into the attestation, never shown to the model | | transaction | no | EVM {from, to?, value?, data?} to simulate; needs an eip155 chain. value is decimal or 0x-hex; data is 0x-hex, ≤ 49,152 chars. Simulated on Ethereum, Base, Polygon, Arbitrum, Optimism and BSC | | screening, authorization | no | caller assertions, recorded as asserted (can only raise risk) |

A field not in this table is refused (422 naming it), never ignored, and a mixed-case EVM address must carry a valid EIP-55 checksum.

Batch: POST /v1/risk-check/batch with {"requests": [...]} (≤ 25). It is all-or-nothing: an invalid item returns 422 with its index.

Attestation

A compact JWS (alg: ES256, typ: risk-check+jwt, kid as published in the DID document, today jev-attest-v1), TTL 1 h. Claims:

| Claim | Meaning | |---|---| | iss, sub, iat, exp, jti | issuer did:web:x402check.xyz, the subject wallet, times, unique id | | score, tier, categories | the verdict and the findings behind it | | checks | what the provider verified, each item with its freshness anchor (since 0.6.1; METHODOLOGY §5): sanctions (list, date, digest of OFAC's SDN.XML, status), domain (impersonation), onchain (status, network, activity), feeds (source@date:status, including code-fingerprint sets), simulation (status, network, findings, at_block), kit_watch (scan clock, status, complete_through per chain), model (question set, or skipped), model_id (the model id the backend reported; through the AI Gateway this is the alias typesafe-ai/jev) | | `asse

Truncated for display — read the full file on GitHub.

Related Skills

View on GitHub
GitHub Stars10
CategorySecurity
Updated6h ago
Forks1

Languages

TypeScript

Trust signals

97/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

1 info