Discovery readback
01Public files and routes such as llms.txt, agents.md, MCP pointers, UCP profiles, manifests, sitemaps, and launch pages.
fixed-scope public proof / 3 business days
For agent-commerce, x402, MCP, UCP, marketplace, and security-tool teams that need a clean external readback before prospects, partners, reviewers, or analysts inspect the surface.
What it buys
The packet is intentionally narrow. It creates buyer-readable evidence without touching private systems or pretending a broad audit happened.
Public files and routes such as llms.txt, agents.md, MCP pointers, UCP profiles, manifests, sitemaps, and launch pages.
What is public, paid, free, gated, browser-readable, cache-safe, signed, replayable, undocumented, or blocked by validation before payment.
A short remediation list ordered by launch risk, with exact commands that reproduce the findings from public surfaces only.
Fit
commerce
Catalogs, product feeds, checkout handoffs, Universal Cart readiness, merchant policy pages, partner demos, and AI-shopping launch claims.
x402
402 challenges, x402 v2 browser preflight, resource binding, no-store cache posture, receipts, retry behavior, and spend-map language.
mcp
MCP server cards, well-known discovery, tool schemas, install docs, public demos, registry claims, support boundaries, and audit language.
security
Runtime security, tool authorization, policy actions, prompt-injection exposure, public docs, evidence packs, and buyer-facing control claims.
Scope boundary
No login, no private endpoint guessing, no customer system probing, no wallet signatures, no real paid calls, no disclosure without sign-off. If the useful work needs private access or implementation, it becomes a separately approved sprint.
send
One URL or repo, the claim that needs proof, the approved public scope, and the deadline.
receive
A private evidence table, command transcript, launch-risk patch order, and short buyer-safe summary.
upgrade
If fixes are needed, implementation help starts at $2,500 and stays scoped to an approved patch list.
Ready
The fastest useful intake is a URL plus the claim that has to survive outside scrutiny.