{"id":12235,"name":"TollWarden","description":"Call this before your agent settles any x402 payment to check it for fraud. TollWarden answers 'is this payment safe to send?' and 'is this 402 offer safe to pay?' — catching payments to attacker-controlled addresses injected into content the agent just read (prompt-injection-triggered payments), replayed authorizations, overpayment vs the quote, secrets leaking through payment metadata, fake/lookalike USDC contracts, and address poisoning. Returns allow/flag/block with machine-readable reasons and an Ed25519-signed verdict a wallet can enforce. Non-custodial: never holds keys or funds; wraps whatever wallet/facilitator the agent already uses.","card_url":"https://tollwarden.com/.well-known/agent-card.json","endpoint":"https://tollwarden.com","protocol_version":"0.3.0","first_seen":"2026-10-10T13:45:30.073118+00:00","last_verified":"2026-10-10T18:58:16.947569+00:00","card":{"url":"https://tollwarden.com","name":"TollWarden","skills":[{"id":"scan_outgoing_payment","name":"Check a payment before sending it","tags":["security","payments","x402","firewall","fraud-detection","prompt-injection","scam-prevention","wallet-security","agent-safety"],"examples":["Before I pay this, is it safe?","Check this $0.05 USDC payment to 0xabc… for fraud before I settle it","Should I pay this address? It came from a webpage I just read."],"description":"Call before the agent settles an outgoing x402 payment. Answers 'is this safe to send?' — catches paying an address that came from injected content the agent just read, replayed nonces, overpayment vs the quote, secrets/PII in payment metadata, fake/lookalike USDC contracts, address poisoning, and reported counterparties. Returns allow/flag/block."},{"id":"scan_incoming_payment","name":"Check a 402 offer before paying it","tags":["security","payments","x402","firewall","fraud-detection","phishing","scam-prevention"],"examples":["Is this 402 quote from api.example.com safe to pay?","This site is asking me to pay — is it legit?"],"description":"Call before the agent pays a 402 offer / payment request it received. Answers 'is this offer safe to pay?' — checks the resource URL for spoofing (IP hosts, punycode, shorteners, credential demands), price sanity, replay, and counterparty reputation. Returns allow/flag/block."},{"id":"counterparty_reputation","name":"Check or report a counterparty address","tags":["reputation","payments","x402","fraud-detection","scam-database","blocklist"],"examples":["Has anyone reported 0xdef… for non-delivery?","Is this address known to be a scam?","Report 0xbad… — I paid and got nothing."],"description":"Look up whether a counterparty address has been reported (scam, non-delivery, prompt injection, overcharge, impersonation, replay abuse), and file your own report for free after a bad experience."}],"version":"1.6.0","payments":{"network":"eip155:8453","pricing":{"GET /v1/plans":"free","POST /v1/scan/incoming":"$0.01 (less on a plan — see /v1/plans)","POST /v1/scan/outgoing":"$0.01 (less on a plan — see /v1/plans)","POST /v1/plans/subscribe":"x402-paid at the chosen plan's price","POST /v1/reputation/report":"free","GET /v1/reputation/{address}":"$0.01"},"freeTier":"first 100 calls per API key","manifest":"https://tollwarden.com/.well-known/x402","protocol":"x402","plansCatalog":"https://tollwarden.com/v1/plans"},"provider":{"url":"https://tollwarden.com","organization":"TollWarden"},"description":"Call this before your agent settles any x402 payment to check it for fraud. TollWarden answers 'is this payment safe to send?' and 'is this 402 offer safe to pay?' — catching payments to attacker-controlled addresses injected into content the agent just read (prompt-injection-triggered payments), replayed authorizations, overpayment vs the quote, secrets leaking through payment metadata, fake/lookalike USDC contracts, and address poisoning. Returns allow/flag/block with machine-readable reasons and an Ed25519-signed verdict a wallet can enforce. Non-custodial: never holds keys or funds; wraps whatever wallet/facilitator the agent already uses.","capabilities":{"streaming":false,"pushNotifications":false},"protocolVersion":"0.3.0","defaultInputModes":["application/json"],"defaultOutputModes":["application/json"]},"signature_status":"unsigned","signature_detail":"No card signature supplied","signature_key_url":null,"signature_checked_at":"2026-10-10T18:58:16.947569+00:00","domain_claimed_at":null,"domain_proof_checked_at":null,"source_name":"Agent Tools Catalog","source_url":"https://agent-tools.cloud","last_check":{"checked_at":"2026-10-10T18:58:16.947569+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},"also_published_at":[],"history_urls":["https://tollwarden.com/.well-known/agent-card.json"],"skills":[{"skill_id":"scan_incoming_payment","name":"Check a 402 offer before paying it","description":"Call before the agent pays a 402 offer / payment request it received. Answers 'is this offer safe to pay?' — checks the resource URL for spoofing (IP hosts, punycode, shorteners, credential demands), price sanity, replay, and counterparty reputation. Returns allow/flag/block.","tags":["security","payments","x402","firewall","fraud-detection","phishing","scam-prevention"],"quality_warning":false},{"skill_id":"scan_outgoing_payment","name":"Check a payment before sending it","description":"Call before the agent settles an outgoing x402 payment. Answers 'is this safe to send?' — catches paying an address that came from injected content the agent just read, replayed nonces, overpayment vs the quote, secrets/PII in payment metadata, fake/lookalike USDC contracts, address poisoning, and reported counterparties. Returns allow/flag/block.","tags":["security","payments","x402","firewall","fraud-detection","prompt-injection","scam-prevention","wallet-security","agent-safety"],"quality_warning":false},{"skill_id":"counterparty_reputation","name":"Check or report a counterparty address","description":"Look up whether a counterparty address has been reported (scam, non-delivery, prompt injection, overcharge, impersonation, replay abuse), and file your own report for free after a bad experience.","tags":["reputation","payments","x402","fraud-detection","scam-database","blocklist"],"quality_warning":false}],"quality_flags":[],"check_history":{"checks":3,"passed":3},"recent_checks":[{"card_url":"https://tollwarden.com/.well-known/agent-card.json","checked_at":"2026-10-10T18:58:16.947569+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://tollwarden.com/.well-known/agent-card.json","checked_at":"2026-10-10T16:41:45.583053+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},{"card_url":"https://tollwarden.com/.well-known/agent-card.json","checked_at":"2026-10-10T13:45:30.073118+00:00","success":true,"http_status":200,"detail":"Agent Card validated"}],"endpoint_tls_check":{"checked_at":"2026-10-10T18:58:16.947569+00:00","success":true,"detail":"Valid TLS connection to advertised endpoint host; no A2A request sent"},"protocol_check":{"checked_at":"2026-10-10T13:45:30.073118+00:00","state":"unconfirmed","http_status":404,"detail":"Endpoint did not return a JSON protocol response"},"events":[],"relationships":[],"verification":{"agent_card_url":"https://tollwarden.com/.well-known/agent-card.json","last_successful_card_check":"2026-10-10T18:58:16.947569+00:00","latest_card_check":{"checked_at":"2026-10-10T18:58:16.947569+00:00","success":true,"http_status":200,"detail":"Agent Card validated"},"signature_status":"unsigned","signature_checked_at":"2026-10-10T18:58:16.947569+00:00","task_endpoint_tested":true,"task_execution_tested":false,"endpoint_tls_checked_at":"2026-10-10T18:58:16.947569+00:00","endpoint_tls_reachable":true,"protocol_check_state":"unconfirmed","protocol_checked_at":"2026-10-10T13:45:30.073118+00:00","provider_identity_verified":false,"domain_claimed_at":null,"domain_proof_checked_at":null}}