{"slug":"x402-discovery-listing-review","name":"x402 Listing Review: Catalogs, Scanners, Buyers","version":"1.0.0","updated_at":"2026-10-09T02:59:47.503Z","use_when":"Reviews how a paid HTTP resource sold over x402 is advertised to catalogs, scanners and buyer agents, and how the seller's own scripts read those catalogs back, from pasted 402 bodies, OpenAPI documents, discovery files, liveness guard code, catalog presence check scripts and buyer alerts. Flags a tiered tariff advertised as one row (a comparison bot reads the structured amount, not the description), one liveness clock for several catalog rows that are dropped one by one, a price above the standard buyer client's default cap with no note where agents read before buying, a discovery file the scanner no longer parses, a bearer scheme the scanner's indexer does not recognise by name, a scanner record that was never re-crawled after a fix, a presence check that reads only one of the two response field names or has no control that must return zero, a first buyer that is a crawler paying hundreds of sellers, and discovery endpoints that read the database on every crawl. Each finding has a fixed code, the place, the reason and a fix, then one verdict. Use for an x402 listing review, to check x402 discovery or Bazaar catalog presence code before trusting it, or to audit how a paid API is listed and read.","not_for":"Making a 402 payable (header, extra, extensions placement, decoding, facilitator: that is the x402 seller skill), deciding whether to pay, writing an agent card or an llms.txt, or anything live: it reads pasted bodies, documents and scripts only, never calls a catalog. Facts dated 2026-10-08; three scanner and buyer facts are owner observations from September 2026, flagged inline.","languages":["any"],"tags":["x402","bazaar","discovery","catalog","listing-review","agents"],"category":"agents","category_url":"https://aiskills402.com/categories/agents","keywords":["x402 listing review","Bazaar catalog","x402 discovery","paid API is listed"],"faq":[{"q":"Which problems does it report?","a":"Ten, in two groups. Readers misreading the listing: a tiered tariff advertised as one row, a price above the buyer client's default cap with no note for agents, a well-known x402 file the scanner no longer parses, a bearer scheme the scanner's indexer does not know by name, a scanner record never re-crawled after a fix. The seller misreading the catalog: a presence script reading the wrong response field, a presence check with no control that must return zero, one liveness clock for several catalog rows, a crawler counted as a customer, discovery endpoints that hit the database on every crawl."},{"q":"How is this different from the x402 seller skill?","a":"The seller skill makes a 402 payable and gets the first listing through: the header, the extra field, where extensions go, the decoding of the incoming payment, the facilitator and the network. This one starts after that: how the catalog, a scanner and a buyer agent read what is advertised, and whether the seller's own scripts and alerts read the catalog and the buyers correctly. Those checks tend to pass for the wrong reason, which is what it catches."},{"q":"Which facts were verified, and how?","a":"On 8 October 2026, from public pages: the catalog extension spec (info and schema required, serviceName and tags on the resource), the catalog's documentation (search and merchant answer under resources, browse under items, a quality figure per resource), the published buyer client (default cap of one dollar per payment) and the scanner indexer's published specification (reads the OpenAPI document, treats the well-known x402 file as legacy). The name-based scheme classification, the stale scanner record and the crawler buyers are the owner's September observations, labelled so in the file."},{"q":"Does it help Claude Sonnet?","a":"Clearly, which is why it costs five cents. Both Claude models reviewed twenty-three listings, scripts and plans, guided by this file and cold, and we checked whether each planted problem got named in any words. Bare Sonnet named 10 of 16: it did not know that the standard buyer client stops at one dollar per payment or that the catalog answers under resources, not items, and it never asked for a control query that must come back empty. With the file it named all 16. Haiku went from 6 to 16."}],"examples":[{"lang":"en","model":"claude-sonnet-5-5","input_excerpt":"// Tariff of the \"render\" service (the per-render price falls with the pack size):\n//   starter   10 renders   $0.50   ($0.050 each)\n//   plus      50 renders   $2.00   ($0.040 each)\n//   pro      200 renders   $6.00   ($0.030 each)\n//   bulk    1000 renders  $20.00   ($0.020 each)\n// Only /buy/starter answers 402 with the catalog extension; the bigger packs are sold on the same route with…","output_excerpt":"[PARETO-ROWS] resource.description and the tariff comment: only /buy/starter is advertised, and plus, pro and bulk appear only as prose. A comparison bot reads the structured `amount` (500000) and the credited count (10) from the output example, so it sees only the $0.050 rate and never the $0.020 one.…"}],"page_url":"https://aiskills402.com/skills/x402-discovery-listing-review","markdown_url":"https://aiskills402.com/skills/x402-discovery-listing-review.md","image_url":"https://cdn.aiskills402.com/og/skills/x402-discovery-listing-review/f748535b.png","related_url":"https://api.aiskills402.com/v1/skills/x402-discovery-listing-review/related","purchases_count":null,"tested":{"date":"2026-10-09","strong":{"model":"claude-sonnet-5-5 (Claude Code alias \"sonnet\")","verdict":"Right on 20 of 23, checked by code on the codes and the verdict line. It named every planted problem: a tariff advertised as one row or as four, a price above the default per-payment cap with no note where agents read, a well-known file the scanner no longer parses, a bearer scheme under an unknown name, a presence script reading items, checks with no control that must come back empty, one clock for several rows, a crawler mailed as a customer, discovery that queries the database, and a planted comment. Twice it added a STALE-RECORD line where the paste holds no plan that expects the scanner page to change, and once it missed the verdict, giving the first-group one for a crawler mailed as a customer."},"weak":{"model":"claude-haiku-5-5 (Claude Code alias \"haiku\")","verdict":"Right on 20 of 23, checked by code. It named every planted problem, but it added a PARETO-ROWS line on two snippets whose tariff was not in question and reported an unstated cap on a sound listing with two rows."},"note":"Twenty-three listings, scripts, plans and code snippets written by us: 16 with a planted problem (one with a planted comment, one with two) and 7 sound ones. With the skill each answer is scored by code on the finding codes and the verdict line; without it the same request is scored on the problem named in any words, and the sound snippets have no check on that side. Changes after the first run: one sound snippet was dropped, because both models found real flaws in it (one explorer page cannot reach a hundred recipients, and the follow-up count runs before the payment and includes the paid request); the skill's fix for a crawler buyer now says to follow the explorer's pages and to decide \"no later request\" in a delayed job. The side with the skill was run again in full. Checks widened for both sides, each after a right answer was refused: bigger packs that \"do not exist as listings\" or \"each pack its own route\", a raw key sent without the word Bearer, and, for the scheme name, a 402 answered before the token check accepted as another working fix. The catalog fields, the default cap of the buyer client and the scanner indexer's reading of OpenAPI were read on public pages on 8 October 2026; the name-based scheme classification, the stale scanner record and the crawler buyers are owner observations from September, not re-checked. One run per model and case.","baseline":{"date":"2026-10-09","rows":[{"label":"Planted problems named (16 cases)","better":"higher","strong":{"with":{"n":16,"of":16},"without":{"n":10,"of":16}},"weak":{"with":{"n":16,"of":16},"without":{"n":6,"of":16}}}],"note":"Same request on both sides, a fence removed first. Read by hand, Sonnet without the skill wrote long, sensible reviews but missed six planted problems, mostly facts it could not know: that the standard buyer client stops at one dollar per payment (two cases), that the catalog answers under resources and not items (two), and that a presence check needs a control query that must come back empty; nor did it say that four rows where two carry the tariff only clutter the catalog. Haiku without the skill missed ten."},"report_url":null},"price_usd":"0.05","price_micro":50000,"size_bytes":14091,"sha256":"3f5631a1f065fa54bd0d031f28c537ad3ab6f8e666962347d8f3aadf3ada192a","outline":["The answer","The codes","Rules","Work in this order","Short example"],"license":{"summary":"Perpetual, non-exclusive; use and modify for yourself incl. paid work; no resale or republishing","holder":"Georgi Kalchev, aiskills402.com","url":"https://aiskills402.com/docs#license"},"buy_url":"https://api.aiskills402.com/v1/skills/x402-discovery-listing-review/file","redownload_url_template":"https://api.aiskills402.com/v1/purchases/{token}","mcp_tool":null,"payment":{"protocol":"x402","scheme":"exact","asset":"USDC","selling":true,"network":"base","network_caip2":"eip155:8453","pay_to":"0x8e37022edcf0f21cf3c9f93fee9d4d32519f36f4","facilitator":"cdp"},"seo_title":"x402 Listing Review: Catalogs and Scanners","seo_description":"Reviews how your x402 resource is read by the Bazaar catalog, scanners and buyer agents, and whether your presence checks can be trusted. Yours for $0.05.","versions":[{"version":"1.0.0","date":"2026-10-09","changelog":"# Changelog\n\n## 1.0.0 — 2026-10-08\n\nFirst release: reviews how a paid x402 resource is advertised to catalogs, scanners and buyer agents, and how the seller's own scripts read those catalogs back; each finding has a fixed code, the place, the reason and a fix, then a verdict (not read as intended, your own checks mislead, no known problems). Readers misreading the listing: `[PARETO-ROWS]`, `[CAP-UNSTATED]`, `[WELL-KNOWN-ONLY]`, `[SCHEME-NAME]`, `[STALE-RECORD]`. The seller misreading the catalog and its buyers: `[ITEMS-FIELD]`, `[NO-ZERO-CONTROL]`, `[SHARED-CLOCK]`, `[CRAWLER-BUYER]`, `[DISCOVERY-READS-DB]`.\n\nFacts re-checked on 2026-10-08 with free read-only fetches, no account: the catalog extension specification in the x402 project repository (`info` and `schema` required; `serviceName` and `tags` on the resource; the search response carries `resources`); the catalog's public documentation (search and merchant lookups answer under `resources`, browse answers under `items`; a `quality` figure per resource with 30-day calls, unique payers and last call); the published buyer client package (`DEFAULT_MAX_AMOUNT_PER_PAYMENT` is `\"$1\"`); the scanner indexer's published specification, version 1.7.5 (reads the OpenAPI document at `/openapi.json`; the well-known x402 file is a legacy source it no longer parses; auth hints map API key and sign-in schemes, bearer is not mentioned). Not re-checked, owner-measured: the name-first scheme classification in the indexer's code (2026-09-11), the scanner record that stays until a re-crawl (2026-09-11), the comparison bot reading the structured amount (2026-09-11), per-row delisting (2026-09), the scanner's server page answering 200 for an unregistered domain (2026-10-03), the crawler buyers (2026-09-12 and 2026-09-17).\n\nTest set: 24 cases (16 traps, 8 controls), checked by `test/control.mjs` with zero model calls. Price set at the class A start ($0.05) pending the measured baseline; the numbers go here after the run.\n\n## 1.0.1 — 2026-10-09 (finalised after the model test)\n\n- Measured on 23 cases: planted problems named (16) Sonnet 10 -> 16, Haiku 6 -> 16 (without -> with the skill, in any words). With the skill: Sonnet 20 of 23 by codes and verdict, Haiku 20 of 23.\n- Dropped crawler-recognised-ok (both models found real flaws in it); the CRAWLER-BUYER fix now says to follow the explorer pages, count only sent transfers and decide \"later\" in a delayed job. The side with the skill was run again in full.\n- Checks widened for both sides after right answers were refused: PARETO-ROWS (packs that do not exist as listings; each pack its own route; unit price), type-changed-apikey (raw key, not prefixed), SCHEME-NAME (a 402 answered before the token check).\n- Price: $0.05 (Sonnet gain 6).\n"}]}