Service record

DeltaSignal ATLAS

https://api.aitrailblazer.net/
observed-mpp

ATLAS-7 Financial Intelligence for crypto public companies. Covenant stress, peer ranking, alpha opportunities, SEC XBRL fundamentals, compact daily monitoring, and paginated daily evidence drilldowns. Primary access is Tempo MPP on /mpp/v1/*; Agentic Market compatibility is Base x402 on /v1/*. Pay-per-call ($0.03-$0.10 for standard reads; bulk export pricing documented separately). Install skill: npx agentcash add https://api.aitrailblazer.net/skills/atlas/SKILL.md

Implementation fingerprint
custom 35% confidence
Fingerprint evidence
valid 402 Payment challenge observed without implementation-specific marker
First seen
Aug 25, 2026, 6:43 PM UTC
Last seen
Oct 9, 2026, 6:24 PM UTC
Origin
https://api.aitrailblazer.net
Tags
None advertised

Payment surface

61 MPP endpoints

This count includes endpoints established by catalog, OpenAPI, or valid runtime 402 evidence. It does not count every URL the harmless scanner attempted.

This bounded detail view shows 25 endpoints. Continue with the next API page or the endpoint index.

JSON record →
POST
https://api.aitrailblazer.net/mcp
DeltaSignal ATLAS-7 MCP JSON-RPC endpoint
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
unknownchargeopenapi0.040000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/alpha-opportunities
Rank the current DeltaSignal slice by deterministic Phase 1 alpha score (MPP)
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 9, 12:23 PM UTC
unknownchargeopenapi0.050000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/alpha-opportunities/audit
Explain alpha board filters, exclusions, and board-rank demotions (MPP)
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 9, 12:23 AM UTC
unknownchargeopenapi0.030000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/alpha-signals/%7Bticker%7D
Get deterministic Phase 1 alpha signals for a single issuer (MPP)
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
unknownchargeopenapi0.070000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/atlas-history/%7Bticker%7D
Get historical ATLAS-7 issuer stress and covenant series (MPP)
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
unknownchargeopenapi0.150000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/atlas7/calculation-history
Get complete ATLAS-7 calculation-history rows (MPP)
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 9, 12:21 PM UTC
unknownchargeopenapi0.200000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/company-fundamentals/%7Bticker%7D
Get provenance-rich company fundamentals from the latest SEC XBRL filing (MPP)
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
unknownchargeopenapi0.050000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/covenant-stress
List covenant stress rows with screening filters (MPP)
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 9, 06:21 AM UTC
unknownchargeopenapi0.080000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/covenant-stress/%7Bticker%7D
Get covenant stress using the ATLAS Tesla Coil model (MPP)
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
unknownchargeopenapi0.100000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/covenant-stress/natural
Get a Natural Language Covenant Stress brief (MPP)
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 8, 06:28 PM UTC
unknownchargeopenapi1.200000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/daily-changes/evidence
Get paginated raw evidence for a daily SEC change row (MPP)
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 9, 06:24 PM UTC
unknownchargeopenapi0.030000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/daily-changes/latest
Get the compact latest SEC daily-changes monitoring snapshot (MPP)
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 9, 06:23 PM UTC
unknownchargeopenapi0.030000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/market-atlas/perps/calculation-history
Get Coinbase perp market calculation history (MPP)
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 9, 12:21 PM UTC
unknownchargeopenapi0.200000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/market-atlas/perps/constituents/%7Bproduct%7D
Get persisted Coinbase thematic or index perp constituent registries (MPP)
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
unknownchargeopenapi0.080000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/market-atlas/perps/factors/%7Bproduct%7D
Get persisted Coinbase perp factor history for one product (MPP)
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
unknownchargeopenapi0.100000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/market-atlas/perps/rankings
Get Coinbase perp market rankings (MPP)
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 9, 06:21 PM UTC
unknownchargeopenapi0.120000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/market-spectra-field-map/%7Bproduct%7D
Get Coinbase perp market SPECTRA field map (MPP)
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
unknownchargeopenapi0.080000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/morning-brief/natural
Get a Natural Language Morning Brief (MPP)
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 9, 06:21 AM UTC
unknownchargeopenapi0.950000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/peer-ranking/%7Bticker%7D
Get peer covenant ranking with system resonance (MPP)
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
unknownchargeopenapi0.060000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/readiness
Get the latest DeltaSignal covenant stress refresh readiness snapshot (MPP)
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 8, 06:29 PM UTC
unknownchargeopenapi0.040000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/risk-distribution
Get the latest covenant stress risk distribution (MPP)
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Oct 9, 12:23 PM UTC
unknownchargeopenapi0.040000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/spectra-field-map/%7Bticker%7D
Get SPECTRA Historical Field Map (MPP)
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
unknownchargeopenapi0.080000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/synthetic-etf/audit/%7Bproduct%7D
Get DeltaSignal Synthetic ETF audit payload (MPP)
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
unknownchargeopenapi0.200000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/synthetic-etf/audit/%7Bproduct%7D/export
Get DeltaSignal Synthetic ETF audit export (MPP)
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
unknownchargeopenapi0.200000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://api.aitrailblazer.net/mpp/v1/synthetic-etf/audit/%7Bproduct%7D/thresholds
Get DeltaSignal Synthetic ETF audit thresholds (MPP)
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
unknownchargeopenapi0.200000 USD
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · mode
fixed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.

Probe coverage

138 harmless observations

These are bounded unauthenticated requests and scanner-policy stops. A response without MPP evidence remains a discovery result, not a security failure.

GET https://api.aitrailblazer.net/v1/daily-changes/evidence

HTTP 402

1,998 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:24 PM UTC

GET https://api.aitrailblazer.net/mpp/v1/daily-changes/evidence

HTTP 404

19 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:24 PM UTC

GET https://api.aitrailblazer.net/v1/covenant-stress/natural

HTTP 402

1,999 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:24 PM UTC

GET https://api.aitrailblazer.net/v1/alpha-opportunities

HTTP 402

1,995 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:24 PM UTC

GET https://api.aitrailblazer.net/mpp/v1/daily-changes/latest

HTTP 404

19 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:23 PM UTC

GET https://api.aitrailblazer.net/v1/risk/distribution

HTTP 402

1,993 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:22 PM UTC

GET https://api.aitrailblazer.net/v1/alpha-opportunities/audit

HTTP 402

2,001 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:22 PM UTC

GET https://api.aitrailblazer.net/mpp/v1/market-atlas/perps/rankings

HTTP 404

19 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:21 PM UTC

GET https://api.aitrailblazer.net/.well-known/api-catalog

HTTP 404

19 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:19 PM UTC

GET https://api.aitrailblazer.net/v1/covenant-stress

HTTP 402

1,991 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:26 PM UTC

GET https://api.aitrailblazer.net/mpp/v1/top-stressed/natural

HTTP 404

19 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:26 PM UTC

GET https://api.aitrailblazer.net/mpp/v1/alpha-opportunities

HTTP 404

19 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:23 PM UTC

GET https://api.aitrailblazer.net/v1/top-stressed

HTTP 402

1,988 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:23 PM UTC

GET https://api.aitrailblazer.net/v1/daily-changes/latest

HTTP 402

1,996 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:23 PM UTC

GET https://api.aitrailblazer.net/mpp/v1/risk-distribution

HTTP 404

19 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:23 PM UTC

GET https://api.aitrailblazer.net/v1/readiness

HTTP 402

1,985 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:22 PM UTC

GET https://api.aitrailblazer.net/mpp/v1/atlas7/calculation-history

HTTP 404

19 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:21 PM UTC

GET https://api.aitrailblazer.net/mpp/v1/market-atlas/perps/calculation-history

HTTP 404

19 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:21 PM UTC

GET https://api.aitrailblazer.net/v1/market-atlas/perps/rankings

HTTP 402

2,003 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:19 PM UTC

GET https://api.aitrailblazer.net/mpp/v1/covenant-stress

HTTP 404

19 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:21 AM UTC

GET https://api.aitrailblazer.net/mpp/v1/morning-brief/natural

HTTP 404

19 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:21 AM UTC

GET https://api.aitrailblazer.net/v1/morning-brief/natural

HTTP 402

1,997 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:20 AM UTC

GET https://api.aitrailblazer.net/v1/top-stressed/natural

HTTP 402

1,996 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 6:20 AM UTC

GET https://api.aitrailblazer.net/v1/daily-brief/public

HTTP 402

1,994 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:36 AM UTC

GET https://api.aitrailblazer.net/mpp/v1/top-stressed

HTTP 404

19 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:24 AM UTC

GET https://api.aitrailblazer.net/mpp/v1/alpha-opportunities/audit

HTTP 404

19 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:23 AM UTC

GET https://api.aitrailblazer.net/v1/top/stressed

HTTP 402

1,988 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 9, 2026, 12:23 AM UTC

GET https://api.aitrailblazer.net/v1/covenant/stress

HTTP 402

1,991 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 6:29 PM UTC

GET https://api.aitrailblazer.net/mpp/v1/readiness

HTTP 404

19 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 6:29 PM UTC

GET https://api.aitrailblazer.net/mpp/v1/covenant-stress/natural

HTTP 404

19 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 6:28 PM UTC

GET https://api.aitrailblazer.net/v1/atlas7/calculation-history

HTTP 402

2,002 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 6:28 PM UTC

GET https://api.aitrailblazer.net/v1/risk-distribution

HTTP 402

1,993 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 6:28 PM UTC

GET https://api.aitrailblazer.net/v1/market-atlas/perps/calculation-history

HTTP 402

2,014 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 8, 2026, 6:24 PM UTC

GET https://api.aitrailblazer.net/

HTTP 200

585 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 6:20 PM UTC

GET https://api.aitrailblazer.net/openapi.json

HTTP 200

509,040 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 12:20 PM UTC

GET https://api.aitrailblazer.net/.well-known/api-catalog

HTTP 200

585 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Oct 1, 2026, 12:18 AM UTC

GET https://api.aitrailblazer.net/v1/daily-changes/evidence

HTTP 402

1,998 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:23 PM UTC

GET https://api.aitrailblazer.net/mpp/v1/daily-changes/evidence

HTTP 402

183 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:23 PM UTC

GET https://api.aitrailblazer.net/v1/covenant-stress/natural

HTTP 402

1,999 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:23 PM UTC

GET https://api.aitrailblazer.net/v1/alpha-opportunities

HTTP 402

1,995 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:22 PM UTC

GET https://api.aitrailblazer.net/mpp/v1/daily-changes/latest

HTTP 402

159 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:22 PM UTC

GET https://api.aitrailblazer.net/v1/risk/distribution

HTTP 402

1,993 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:22 PM UTC

GET https://api.aitrailblazer.net/v1/alpha-opportunities/audit

HTTP 402

2,001 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:22 PM UTC

GET https://api.aitrailblazer.net/mpp/v1/market-atlas/perps/rankings

HTTP 402

262 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 6:21 PM UTC

GET https://api.aitrailblazer.net/mpp/v1/alpha-opportunities

HTTP 402

174 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 12:22 PM UTC

GET https://api.aitrailblazer.net/v1/daily-changes/latest

HTTP 402

1,996 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 12:22 PM UTC

GET https://api.aitrailblazer.net/v1/top-stressed

HTTP 402

1,988 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 12:22 PM UTC

GET https://api.aitrailblazer.net/mpp/v1/risk-distribution

HTTP 402

159 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 12:22 PM UTC

GET https://api.aitrailblazer.net/v1/covenant-stress

HTTP 402

1,991 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 12:21 PM UTC

GET https://api.aitrailblazer.net/mpp/v1/top-stressed/natural

HTTP 402

178 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation

Sep 30, 2026, 12:21 PM UTC
Showing the latest 50 of 138 observations.

Evidence model

Security properties

Every result names its evidence state. Unknown and not tested never mean secure.

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:24 PM UTC

bounded_response

Tested — pass

1998 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:24 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:24 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:24 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 6:24 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:24 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:24 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:24 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:24 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:24 PM UTC

bounded_response

Tested — pass

19 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:24 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:24 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:24 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 6:24 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:24 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:24 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:24 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:24 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:24 PM UTC

bounded_response

Tested — pass

1999 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:24 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:24 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:24 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 6:24 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:24 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:24 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:24 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:24 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:24 PM UTC

bounded_response

Tested — pass

1995 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:24 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:24 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:24 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 6:24 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:24 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:24 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:24 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:24 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:23 PM UTC

bounded_response

Tested — pass

19 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:23 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:23 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:23 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:23 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:23 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 6:23 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:23 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:23 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:23 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:23 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:23 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:23 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:23 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:22 PM UTC

bounded_response

Tested — pass

1993 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:22 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:22 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 6:22 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:22 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:22 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:22 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:22 PM UTC

bounded_response

Tested — pass

2001 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:22 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:22 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 6:22 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:22 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:22 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:22 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:21 PM UTC

bounded_response

Tested — pass

19 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:21 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 6:21 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:21 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:21 PM UTC

api_catalog_parse

Observed

No RFC 9727 API catalog was available at this URL (HTTP 404); prior advertised links were withdrawn

Basis: RFC 9727 discovery response · Oct 9, 2026, 6:19 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:19 PM UTC

bounded_response

Tested — pass

19 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 6:19 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 6:19 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 6:19 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 6:19 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:19 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 6:19 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 6:19 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 6:19 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 6:19 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 6:19 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 6:19 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:19 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:19 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:26 PM UTC

bounded_response

Tested — pass

1991 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:26 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:26 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:26 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 12:26 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:26 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:26 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:26 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:26 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:26 PM UTC

bounded_response

Tested — pass

19 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:26 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:26 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:26 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 12:26 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:26 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:26 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:26 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:26 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:23 PM UTC

bounded_response

Tested — pass

19 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:23 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 12:23 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:23 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:23 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:23 PM UTC

bounded_response

Tested — pass

1988 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:23 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 12:23 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:23 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:23 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:23 PM UTC

bounded_response

Tested — pass

1996 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:23 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 12:23 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:23 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:23 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:23 PM UTC

bounded_response

Tested — pass

19 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:23 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 12:23 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:23 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:23 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:22 PM UTC

bounded_response

Tested — pass

1985 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:22 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:22 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:22 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 12:22 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:22 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:22 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:22 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:22 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:21 PM UTC

bounded_response

Tested — pass

19 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:21 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:21 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:21 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 12:21 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:21 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Oct 9, 2026, 12:21 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:21 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:21 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:21 PM UTC

bounded_response

Tested — pass

19 bytes within scanner limit

Basis: harmless scanner · Oct 9, 2026, 12:21 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Oct 9, 2026, 12:21 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:21 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Oct 9, 2026, 12:21 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Oct 9, 2026, 12:21 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTC
Showing a bounded 250 of 478 security-property records.

History

Service changes

Showing the latest 50 of 506 changes. Continue in the changes API view.

— probe-observation

content_type: application/problem+json → text/plain; charset=utf-8

Evidence: harmless unauthenticated HTTP observation

— payment-offer-withdrawn

offer-active: 1 → 0

Evidence: challenge source https://api.aitrailblazer.net/mpp/v1/daily-changes/evidence

— probe-observation

last_status: 402 → 404

Evidence: harmless unauthenticated HTTP observation

— security-property-changed

security:economic_exposure_metadata: {"state":"unknown","evidence":"[{\"method\":\"tempo\",\"intent\":\"charge\",\"deposit\":null,\"authorizationWindow\":nu… → {"state":"unknown","evidence":"No current Payment challenge exposes session or authorization inputs","basis":"observabl…

Evidence: Repeated harmless observation changed the modeled property

— probe-observation

challenge_format: mpp-payment-auth

Evidence: harmless unauthenticated HTTP observation

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"183 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"19 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:challenge_parse: {"state":"tested-pass","evidence":"1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validat… → {"state":"unknown","evidence":"No MPP Payment challenge observed","basis":"unauthenticated HTTP response"}

Evidence: Repeated harmless observation changed the modeled property

— endpoint-source-withdrawn

source:challenge: 1 → 0

Evidence: https://api.aitrailblazer.net/mpp/v1/daily-changes/evidence

— security-property-changed

security:challenge_parse: {"state":"tested-pass","evidence":"1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validat… → {"state":"unknown","evidence":"No MPP Payment challenge observed","basis":"unauthenticated HTTP response"}

Evidence: Repeated harmless observation changed the modeled property

— probe-observation

content_type: application/problem+json → text/plain; charset=utf-8

Evidence: harmless unauthenticated HTTP observation

— security-property-changed

security:economic_exposure_metadata: {"state":"unknown","evidence":"[{\"method\":\"tempo\",\"intent\":\"charge\",\"deposit\":null,\"authorizationWindow\":nu… → {"state":"unknown","evidence":"No current Payment challenge exposes session or authorization inputs","basis":"observabl…

Evidence: Repeated harmless observation changed the modeled property

— probe-observation

challenge_format: mpp-payment-auth

Evidence: harmless unauthenticated HTTP observation

— payment-offer-withdrawn

offer-active: 1 → 0

Evidence: challenge source https://api.aitrailblazer.net/mpp/v1/daily-changes/latest

— probe-observation

last_status: 402 → 404

Evidence: harmless unauthenticated HTTP observation

— endpoint-source-withdrawn

source:challenge: 1 → 0

Evidence: https://api.aitrailblazer.net/mpp/v1/daily-changes/latest

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"159 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"19 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:bounded_response: {"state":"tested-pass","evidence":"262 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"19 bytes within scanner limit","basis":"harmless scanner"}

Evidence: Repeated harmless observation changed the modeled property

— endpoint-source-withdrawn

source:challenge: 1 → 0

Evidence: https://api.aitrailblazer.net/mpp/v1/market-atlas/perps/rankings

— security-property-changed

security:challenge_parse: {"state":"tested-pass","evidence":"1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validat… → {"state":"unknown","evidence":"No MPP Payment challenge observed","basis":"unauthenticated HTTP response"}

Evidence: Repeated harmless observation changed the modeled property

— payment-offer-withdrawn

offer-active: 1 → 0

Evidence: challenge source https://api.aitrailblazer.net/mpp/v1/market-atlas/perps/rankings

— probe-observation

challenge_format: mpp-payment-auth

Evidence: harmless unauthenticated HTTP observation

— probe-observation

last_status: 402 → 404

Evidence: harmless unauthenticated HTTP observation

— probe-observation

content_type: application/problem+json → text/plain; charset=utf-8

Evidence: harmless unauthenticated HTTP observation

— security-property-changed

security:economic_exposure_metadata: {"state":"unknown","evidence":"[{\"method\":\"tempo\",\"intent\":\"charge\",\"deposit\":null,\"authorizationWindow\":nu… → {"state":"unknown","evidence":"No current Payment challenge exposes session or authorization inputs","basis":"observabl…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:api_catalog_parse: {"state":"observed","evidence":"RFC 9727 well-known path returned 200 text/html; charset=utf-8; no API catalog was esta… → {"state":"observed","evidence":"No RFC 9727 API catalog was available at this URL (HTTP 404); prior advertised links we…

Evidence: Repeated harmless observation changed the modeled property