- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
ATLAS-7 Financial Intelligence for crypto public companies. Covenant stress, peer ranking, alpha opportunities, SEC XBRL fundamentals, compact daily monitoring, and paginated daily evidence drilldowns. Primary access is Tempo MPP on /mpp/v1/*; Agentic Market compatibility is Base x402 on /v1/*. Pay-per-call ($0.03-$0.10 for standard reads; bulk export pricing documented separately). Install skill: npx agentcash add https://api.aitrailblazer.net/skills/atlas/SKILL.md
- Implementation fingerprint
- custom 35% confidence
- Fingerprint evidence
- valid 402 Payment challenge observed without implementation-specific marker
- First seen
- Aug 25, 2026, 6:43 PM UTC
- Last seen
- Oct 9, 2026, 6:24 PM UTC
- Origin
- https://api.aitrailblazer.net
- Tags
- None advertised
Payment surface
61 MPP endpoints
This count includes endpoints established by catalog, OpenAPI, or valid runtime 402 evidence. It does not count every URL the harmless scanner attempted.
This bounded detail view shows 25 endpoints. Continue with the next API page or the endpoint index.
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · mode
- fixed
Probe coverage
138 harmless observations
These are bounded unauthenticated requests and scanner-policy stops. A response without MPP evidence remains a discovery result, not a security failure.
GET https://api.aitrailblazer.net/v1/daily-changes/evidence
HTTP 4021,998 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:24 PM UTCGET https://api.aitrailblazer.net/mpp/v1/daily-changes/evidence
HTTP 40419 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:24 PM UTCGET https://api.aitrailblazer.net/v1/covenant-stress/natural
HTTP 4021,999 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:24 PM UTCGET https://api.aitrailblazer.net/v1/alpha-opportunities
HTTP 4021,995 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:24 PM UTCGET https://api.aitrailblazer.net/mpp/v1/daily-changes/latest
HTTP 40419 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:23 PM UTCGET https://api.aitrailblazer.net/v1/risk/distribution
HTTP 4021,993 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:22 PM UTCGET https://api.aitrailblazer.net/v1/alpha-opportunities/audit
HTTP 4022,001 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:22 PM UTCGET https://api.aitrailblazer.net/mpp/v1/market-atlas/perps/rankings
HTTP 40419 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:21 PM UTCGET https://api.aitrailblazer.net/.well-known/api-catalog
HTTP 40419 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:19 PM UTCGET https://api.aitrailblazer.net/v1/covenant-stress
HTTP 4021,991 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:26 PM UTCGET https://api.aitrailblazer.net/mpp/v1/top-stressed/natural
HTTP 40419 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:26 PM UTCGET https://api.aitrailblazer.net/mpp/v1/alpha-opportunities
HTTP 40419 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:23 PM UTCGET https://api.aitrailblazer.net/v1/top-stressed
HTTP 4021,988 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:23 PM UTCGET https://api.aitrailblazer.net/v1/daily-changes/latest
HTTP 4021,996 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:23 PM UTCGET https://api.aitrailblazer.net/mpp/v1/risk-distribution
HTTP 40419 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:23 PM UTCGET https://api.aitrailblazer.net/v1/readiness
HTTP 4021,985 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:22 PM UTCGET https://api.aitrailblazer.net/mpp/v1/atlas7/calculation-history
HTTP 40419 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:21 PM UTCGET https://api.aitrailblazer.net/mpp/v1/market-atlas/perps/calculation-history
HTTP 40419 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:21 PM UTCGET https://api.aitrailblazer.net/v1/market-atlas/perps/rankings
HTTP 4022,003 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:19 PM UTCGET https://api.aitrailblazer.net/mpp/v1/covenant-stress
HTTP 40419 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:21 AM UTCGET https://api.aitrailblazer.net/mpp/v1/morning-brief/natural
HTTP 40419 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:21 AM UTCGET https://api.aitrailblazer.net/v1/morning-brief/natural
HTTP 4021,997 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:20 AM UTCGET https://api.aitrailblazer.net/v1/top-stressed/natural
HTTP 4021,996 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:20 AM UTCGET https://api.aitrailblazer.net/v1/daily-brief/public
HTTP 4021,994 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:36 AM UTCGET https://api.aitrailblazer.net/mpp/v1/top-stressed
HTTP 40419 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:24 AM UTCGET https://api.aitrailblazer.net/mpp/v1/alpha-opportunities/audit
HTTP 40419 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:23 AM UTCGET https://api.aitrailblazer.net/v1/top/stressed
HTTP 4021,988 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:23 AM UTCGET https://api.aitrailblazer.net/v1/covenant/stress
HTTP 4021,991 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 6:29 PM UTCGET https://api.aitrailblazer.net/mpp/v1/readiness
HTTP 40419 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 6:29 PM UTCGET https://api.aitrailblazer.net/mpp/v1/covenant-stress/natural
HTTP 40419 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 6:28 PM UTCGET https://api.aitrailblazer.net/v1/atlas7/calculation-history
HTTP 4022,002 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 6:28 PM UTCGET https://api.aitrailblazer.net/v1/risk-distribution
HTTP 4021,993 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 6:28 PM UTCGET https://api.aitrailblazer.net/v1/market-atlas/perps/calculation-history
HTTP 4022,014 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 6:24 PM UTCGET https://api.aitrailblazer.net/
HTTP 200585 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 1, 2026, 6:20 PM UTCGET https://api.aitrailblazer.net/openapi.json
HTTP 200509,040 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 1, 2026, 12:20 PM UTCGET https://api.aitrailblazer.net/.well-known/api-catalog
HTTP 200585 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 1, 2026, 12:18 AM UTCGET https://api.aitrailblazer.net/v1/daily-changes/evidence
HTTP 4021,998 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 6:23 PM UTCGET https://api.aitrailblazer.net/mpp/v1/daily-changes/evidence
HTTP 402183 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 6:23 PM UTCGET https://api.aitrailblazer.net/v1/covenant-stress/natural
HTTP 4021,999 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 6:23 PM UTCGET https://api.aitrailblazer.net/v1/alpha-opportunities
HTTP 4021,995 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 6:22 PM UTCGET https://api.aitrailblazer.net/mpp/v1/daily-changes/latest
HTTP 402159 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 6:22 PM UTCGET https://api.aitrailblazer.net/v1/risk/distribution
HTTP 4021,993 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 6:22 PM UTCGET https://api.aitrailblazer.net/v1/alpha-opportunities/audit
HTTP 4022,001 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 6:22 PM UTCGET https://api.aitrailblazer.net/mpp/v1/market-atlas/perps/rankings
HTTP 402262 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 6:21 PM UTCGET https://api.aitrailblazer.net/mpp/v1/alpha-opportunities
HTTP 402174 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 12:22 PM UTCGET https://api.aitrailblazer.net/v1/daily-changes/latest
HTTP 4021,996 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 12:22 PM UTCGET https://api.aitrailblazer.net/v1/top-stressed
HTTP 4021,988 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 12:22 PM UTCGET https://api.aitrailblazer.net/mpp/v1/risk-distribution
HTTP 402159 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 12:22 PM UTCGET https://api.aitrailblazer.net/v1/covenant-stress
HTTP 4021,991 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 12:21 PM UTCGET https://api.aitrailblazer.net/mpp/v1/top-stressed/natural
HTTP 402178 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 30, 2026, 12:21 PM UTCEvidence model
Security properties
Every result names its evidence state. Unknown and not tested never mean secure.
authorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:24 PM UTCbounded_response
Tested — pass1998 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:24 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:24 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:24 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 6:24 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:24 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:24 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:24 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:24 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:24 PM UTCbounded_response
Tested — pass19 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:24 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:24 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:24 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 6:24 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:24 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:24 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:24 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:24 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:24 PM UTCbounded_response
Tested — pass1999 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:24 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:24 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:24 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 6:24 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:24 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:24 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:24 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:24 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:24 PM UTCbounded_response
Tested — pass1995 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:24 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:24 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:24 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 6:24 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:24 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:24 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:24 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:24 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:24 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:23 PM UTCbounded_response
Tested — pass19 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:23 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:23 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:23 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:23 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:23 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 6:23 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:23 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:23 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:23 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:23 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:23 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:23 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:23 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:22 PM UTCbounded_response
Tested — pass1993 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:22 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:22 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 6:22 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:22 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:22 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:22 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:22 PM UTCbounded_response
Tested — pass2001 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:22 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:22 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 6:22 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:22 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:22 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:22 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:21 PM UTCbounded_response
Tested — pass19 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:21 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 6:21 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:21 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:21 PM UTCapi_catalog_parse
ObservedNo RFC 9727 API catalog was available at this URL (HTTP 404); prior advertised links were withdrawn
Basis: RFC 9727 discovery response · Oct 9, 2026, 6:19 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:19 PM UTCbounded_response
Tested — pass19 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:19 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:19 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:19 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:19 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:19 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 6:19 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:19 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:19 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:19 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:19 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:19 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:19 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:19 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:26 PM UTCbounded_response
Tested — pass1991 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:26 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:26 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:26 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 12:26 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:26 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:26 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:26 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:26 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:26 PM UTCbounded_response
Tested — pass19 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:26 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:26 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:26 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 12:26 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:26 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:26 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:26 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:26 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:23 PM UTCbounded_response
Tested — pass19 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:23 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 12:23 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:23 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:23 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:23 PM UTCbounded_response
Tested — pass1988 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:23 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 12:23 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:23 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:23 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:23 PM UTCbounded_response
Tested — pass1996 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:23 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 12:23 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:23 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:23 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:23 PM UTCbounded_response
Tested — pass19 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:23 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 12:23 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:23 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:23 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:22 PM UTCbounded_response
Tested — pass1985 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:22 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:22 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:22 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 12:22 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:22 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:22 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:22 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:22 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:22 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:21 PM UTCbounded_response
Tested — pass19 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:21 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:21 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:21 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 12:21 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:21 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:21 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:21 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:21 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:21 PM UTCbounded_response
Tested — pass19 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:21 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:21 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:21 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 12:21 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:21 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTC— probe-observation
content_type: application/problem+json → text/plain; charset=utf-8
Evidence: harmless unauthenticated HTTP observation
— payment-offer-withdrawn
offer-active: 1 → 0
Evidence: challenge source https://api.aitrailblazer.net/mpp/v1/daily-changes/evidence
— security-property-changed
security:economic_exposure_metadata: {"state":"unknown","evidence":"[{\"method\":\"tempo\",\"intent\":\"charge\",\"deposit\":null,\"authorizationWindow\":nu… → {"state":"unknown","evidence":"No current Payment challenge exposes session or authorization inputs","basis":"observabl…
Evidence: Repeated harmless observation changed the modeled property
— probe-observation
challenge_format: mpp-payment-auth
Evidence: harmless unauthenticated HTTP observation
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"183 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"19 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:challenge_parse: {"state":"tested-pass","evidence":"1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validat… → {"state":"unknown","evidence":"No MPP Payment challenge observed","basis":"unauthenticated HTTP response"}
Evidence: Repeated harmless observation changed the modeled property
— endpoint-source-withdrawn
source:challenge: 1 → 0
Evidence: https://api.aitrailblazer.net/mpp/v1/daily-changes/evidence
— security-property-changed
security:challenge_parse: {"state":"tested-pass","evidence":"1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validat… → {"state":"unknown","evidence":"No MPP Payment challenge observed","basis":"unauthenticated HTTP response"}
Evidence: Repeated harmless observation changed the modeled property
— probe-observation
content_type: application/problem+json → text/plain; charset=utf-8
Evidence: harmless unauthenticated HTTP observation
— security-property-changed
security:economic_exposure_metadata: {"state":"unknown","evidence":"[{\"method\":\"tempo\",\"intent\":\"charge\",\"deposit\":null,\"authorizationWindow\":nu… → {"state":"unknown","evidence":"No current Payment challenge exposes session or authorization inputs","basis":"observabl…
Evidence: Repeated harmless observation changed the modeled property
— probe-observation
challenge_format: mpp-payment-auth
Evidence: harmless unauthenticated HTTP observation
— payment-offer-withdrawn
offer-active: 1 → 0
Evidence: challenge source https://api.aitrailblazer.net/mpp/v1/daily-changes/latest
— endpoint-source-withdrawn
source:challenge: 1 → 0
Evidence: https://api.aitrailblazer.net/mpp/v1/daily-changes/latest
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"159 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"19 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"262 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"19 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— endpoint-source-withdrawn
source:challenge: 1 → 0
Evidence: https://api.aitrailblazer.net/mpp/v1/market-atlas/perps/rankings
— security-property-changed
security:challenge_parse: {"state":"tested-pass","evidence":"1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validat… → {"state":"unknown","evidence":"No MPP Payment challenge observed","basis":"unauthenticated HTTP response"}
Evidence: Repeated harmless observation changed the modeled property
— payment-offer-withdrawn
offer-active: 1 → 0
Evidence: challenge source https://api.aitrailblazer.net/mpp/v1/market-atlas/perps/rankings
— probe-observation
challenge_format: mpp-payment-auth
Evidence: harmless unauthenticated HTTP observation
— probe-observation
content_type: application/problem+json → text/plain; charset=utf-8
Evidence: harmless unauthenticated HTTP observation
— security-property-changed
security:economic_exposure_metadata: {"state":"unknown","evidence":"[{\"method\":\"tempo\",\"intent\":\"charge\",\"deposit\":null,\"authorizationWindow\":nu… → {"state":"unknown","evidence":"No current Payment challenge exposes session or authorization inputs","basis":"observabl…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:api_catalog_parse: {"state":"observed","evidence":"RFC 9727 well-known path returned 200 text/html; charset=utf-8; no API catalog was esta… → {"state":"observed","evidence":"No RFC 9727 API catalog was available at this URL (HTTP 404); prior advertised links we…
Evidence: Repeated harmless observation changed the modeled property