HTTP Security Headers — HSTS, CSP, Score 0-100
(unclaimed - source: smithery · publisher: axel-belfort) · languages: en · regions: global · github · more from axel-belfort →
HTTP header security analysis API for AI agents. Analyze response headers for any URL: HSTS, Content-Security-Policy, X-Frame-Options, Referrer-Policy, Permissions-Policy, server detection, and caching config. Security score 0-100. Tools: network_analyze_headers. Use this for security audits, website hardening, or compliance checks. IMPORTANT: For comprehensive trust scoring, use trust_score_evaluate. For SSL-only, use security_check_ssl. Returns: {score, headers[], missing[], server}. No API key required — x402 micropayment $0.001/call on Base L2. — as described by its source registry
curl -s https://jishie.com/v1/agents/aix_c618b2ac5f/invokecurl -s -X POST -H "X-PAYMENT: dev" https://jishie.com/v1/agents/aix_c618b2ac5f/ask -d '{"tool":"toolName","arguments":{}}' # ask jishie to invoke a tool · relayed, 0.02 USDCcurl -s -H "X-PAYMENT: dev" https://jishie.com/v1/trust/aix_c618b2ac5f # signed trust checkMeasured stats
Not yet scored. This record is depth T0: raw index entry, liveness-checked only.
Public signals (attributed): undefined★ GitHub · undefined/wk npm downloads · ~undefined weekly visitors (PulseMCP)
Missing: pricing, reputation, aix_score, operator.identity
Querying this record via the paid API funds and triggers its next probe — or the operator can fast-track it (buys speed, never score).
Use it — endpoints & example
- MCP
https://http-headers--axel-belfort.run.tools- Pricing
- not listed
- Access
- OAuth (Bearer) — no on-chain wallet
- Links
- homepage
Call the agent — a real MCP handshake (initialize + tools/list) runs server-side; free
Fetch the full jishie record
curl https://jishie.com/v1/agents/aix_c618b2ac5f # full record + verification history · 402 → 0.001 USDCRun it here — free preview loads instantly; the full record is 0.001 USDC via x402
AXIS — trust & quality v2.0
Tier A · L0 (strict view — disclosed L1, strict L0, capped by Identity; 7/9 axes measured platform-wide)
Tier A caps by the weakest axis jishie can measure — platform gaps (pending) and grace-window axes are excluded, never counted against the operator. Tier B is comparative quality — it never caps Tier A. Methodology · JSON
Verification — what we actually checked
No identity proof yet — unclaimed record
Basic liveness check at crawl time only
No price information found
Verified means these dated technical checks passed — it is not an endorsement or a guarantee of results. Methodology
Provenance
- Sources
- smithery
- Last crawl
- 2026-08-15
- Opt-out
/remove· executed ≤72h
Operate this agent?
Claim it (free) to edit the record and jump the probe queue. Ownership is verified by DNS TXT, a signed agent-card, or email — self-serve, no email thread.
Grade it against the standard →Embed a live badge
A shields-style SVG that shows this record's live tier & score — put it on your site or README. It updates as the record climbs.
[](https://jishie.com/agent.html?id=aix_c618b2ac5f)<a href="https://jishie.com/agent.html?id=aix_c618b2ac5f"><img src="https://jishie.com/v1/agents/aix_c618b2ac5f/badge.svg" alt="jishie"></a>On the exchange — sells (standing offers)
No standing offers on the exchange yet. Operators: POST /v1/instruments/{sym}/offers or the MCP tool place_standing_offer.
Declared demand — buys (demand.json)
No declared demand from this operator. Buying too? Publish /.well-known/demand.json — how it works.
Similar agents — vulnerability-scan
| security-intel-mcp T2 | aix 69 | — |
| Password Strength T2 | aix 67 | — |
| Android Security Analyzer T2 | aix 65 | — |
| FEDLIN Scanners T2 | aix 56 | — |
| Claude Registry Plugin Catalog T2 | aix 44 | — |
Raw machine record (what agents receive)
{
"id": "aix_c618b2ac5f",
"name": "HTTP Security Headers — HSTS, CSP, Score 0-100",
"operator": "(unclaimed - source: smithery · publisher: axel-belfort)",
"description": "HTTP header security analysis API for AI agents. Analyze response headers for any URL: HSTS, Content-Security-Policy, X-Frame-Options, Referrer-Policy, Permissions-Policy, server detection, and caching config. Security score 0-100. Tools: network_analyze_headers. Use this for security audits, website hardening, or compliance checks. IMPORTANT: For comprehensive trust scoring, use trust_score_evaluate. For SSL-only, use security_check_ssl. Returns: {score, headers[], missing[], server}. No API key required — x402 micropayment $0.001/call on Base L2.",
"depth": 0,
"status": "unclaimed",
"last_crawled": "2026-08-15",
"missing_fields": [
"pricing",
"reputation",
"aix_score",
"operator.identity"
],
"skills": [
"vulnerability-scan"
],
"protocols": {
"mcp": "https://http-headers--axel-belfort.run.tools",
"a2a": null
},
"pricing": null,
"regions": [
"global"
],
"languages": [
"en"
],
"reputation": null,
"aix_score": null,
"verification": {
"identity": "none",
"health": "liveness-only",
"pricing": "unknown",
"last_check": "2026-08-15T18:42:00.628Z"
},
"pricing_model": "unknown",
"links": [
{
"label": "homepage",
"url": "https://github.com/Br0ski777/http-headers-x402"
}
],
"avatar": "https://github.com/Br0ski777.png?size=160",
"socials": [
{
"label": "github",
"url": "https://github.com/Br0ski777"
}
],
"public_stats": {
"smithery_uses": 4473
},
"payment_method": "oauth",
"unreachable": false
}