# x402 Listing Review: Catalogs, Scanners, Buyers

x402 Listing Review: Catalogs, Scanners, Buyers is a tested SKILL.md that reviews how a paid HTTP resource sold over x402 is advertised to catalogs, scanners and buyer agents, and how the seller's own scripts read those catalogs back, from pasted 402 bodies, OpenAPI documents, discovery files, liveness guard code, catalog presence check scripts and buyer alerts; an agent buys it once for $0.05 over x402.

- Page: https://aiskills402.com/skills/x402-discovery-listing-review
- Category: Agents & Protocols (https://aiskills402.com/categories/agents)
- Price: $0.05 once, USD-priced, paid in USDC on Base over x402. Price as loaded on this page. The 402 response your agent receives is authoritative.
- Version: 1.0.0
- Card (JSON): https://api.aiskills402.com/v1/skills/x402-discovery-listing-review

## Use it when

Reviews how a paid HTTP resource sold over x402 is advertised to catalogs, scanners and buyer agents, and how the seller's own scripts read those catalogs back, from pasted 402 bodies, OpenAPI documents, discovery files, liveness guard code, catalog presence check scripts and buyer alerts. Flags a tiered tariff advertised as one row (a comparison bot reads the structured amount, not the description), one liveness clock for several catalog rows that are dropped one by one, a price above the standard buyer client's default cap with no note where agents read before buying, a discovery file the scanner no longer parses, a bearer scheme the scanner's indexer does not recognise by name, a scanner record that was never re-crawled after a fix, a presence check that reads only one of the two response field names or has no control that must return zero, a first buyer that is a crawler paying hundreds of sellers, and discovery endpoints that read the database on every crawl. Each finding has a fixed code, the place, the reason and a fix, then one verdict. Use for an x402 listing review, to check x402 discovery or Bazaar catalog presence code before trusting it, or to audit how a paid API is listed and read.

## Not for

Making a 402 payable (header, extra, extensions placement, decoding, facilitator: that is the x402 seller skill), deciding whether to pay, writing an agent card or an llms.txt, or anything live: it reads pasted bodies, documents and scripts only, never calls a catalog. Facts dated 2026-10-08; three scanner and buyer facts are owner observations from September 2026, flagged inline.

## Tested, honestly

Tested 2026-10-09.

- Strong model (claude-sonnet-5-5 (Claude Code alias "sonnet")): Right on 20 of 23, checked by code on the codes and the verdict line. It named every planted problem: a tariff advertised as one row or as four, a price above the default per-payment cap with no note where agents read, a well-known file the scanner no longer parses, a bearer scheme under an unknown name, a presence script reading items, checks with no control that must come back empty, one clock for several rows, a crawler mailed as a customer, discovery that queries the database, and a planted comment. Twice it added a STALE-RECORD line where the paste holds no plan that expects the scanner page to change, and once it missed the verdict, giving the first-group one for a crawler mailed as a customer.
- Weak model (claude-haiku-5-5 (Claude Code alias "haiku")): Right on 20 of 23, checked by code. It named every planted problem, but it added a PARETO-ROWS line on two snippets whose tariff was not in question and reported an unstated cap on a sound listing with two rows.

Note: Twenty-three listings, scripts, plans and code snippets written by us: 16 with a planted problem (one with a planted comment, one with two) and 7 sound ones. With the skill each answer is scored by code on the finding codes and the verdict line; without it the same request is scored on the problem named in any words, and the sound snippets have no check on that side. Changes after the first run: one sound snippet was dropped, because both models found real flaws in it (one explorer page cannot reach a hundred recipients, and the follow-up count runs before the payment and includes the paid request); the skill's fix for a crawler buyer now says to follow the explorer's pages and to decide "no later request" in a delayed job. The side with the skill was run again in full. Checks widened for both sides, each after a right answer was refused: bigger packs that "do not exist as listings" or "each pack its own route", a raw key sent without the word Bearer, and, for the scheme name, a 402 answered before the token check accepted as another working fix. The catalog fields, the default cap of the buyer client and the scanner indexer's reading of OpenAPI were read on public pages on 8 October 2026; the name-based scheme classification, the stale scanner record and the crawler buyers are owner observations from September, not re-checked. One run per model and case.

### With and without the skill

Tested 2026-10-09.

- Planted problems named (16 cases): Sonnet 16/16 with, 10/16 without; Haiku 16/16 with, 6/16 without.

Same request on both sides, a fence removed first. Read by hand, Sonnet without the skill wrote long, sensible reviews but missed six planted problems, mostly facts it could not know: that the standard buyer client stops at one dollar per payment (two cases), that the catalog answers under resources and not items (two), and that a presence check needs a control query that must come back empty; nor did it say that four rows where two carry the tariff only clutter the catalog. Haiku without the skill missed ten.

Same cases and the same checks with and without the skill. The cases are ours, written around what the skill is for; with a handful of cases, a difference of one or two is within noise.

Full summary: https://aiskills402.com/skills/x402-discovery-listing-review/tests

## Example

### English (claude-sonnet-5-5)

Before:

> // Tariff of the "render" service (the per-render price falls with the pack size): //   starter   10 renders   $0.50   ($0.050 each) //   plus      50 renders   $2.00   ($0.040 each) //   pro      200 renders   $6.00   ($0.030 each) //   bulk    1000 renders  $20.00   ($0.020 each) // Only /buy/starter answers 402 with the catalog extension; the bigger packs are sold on the same route with…

After:

> [PARETO-ROWS] resource.description and the tariff comment: only /buy/starter is advertised, and plus, pro and bulk appear only as prose. A comparison bot reads the structured `amount` (500000) and the credited count (10) from the output example, so it sees only the $0.050 rate and never the $0.020 one.…

## What is in the file

- The answer
- The codes
- Rules
- Work in this order
- Short example

## Languages

Any language

## How to buy

Agent (HTTP):

1. GET https://api.aiskills402.com/v1/skills/x402-discovery-listing-review/file without a payment header. The answer is 402 with a PAYMENT-REQUIRED header (x402 v2): exact amount, asset, network, recipient.
2. Sign `accepts[0]` with an x402 client (for example @x402/core + @x402/evm).
3. Repeat the GET with the signature in the PAYMENT-SIGNATURE header. The answer is 200 with the file, its sha256 and a re-download token.

Agent (MCP): https://mcp.aiskills402.com/mcp — free tools search_skills, get_skill, redownload_skill. Buying itself is over HTTP.

Full flow: https://aiskills402.com/docs

## The file

- Version: 1.0.0
- Size: 13.8 KB (14091 bytes)
- SHA-256: 3f5631a1f065fa54bd0d031f28c537ad3ab6f8e666962347d8f3aadf3ada192a
- Updated: 2026-10-09
- New versions are free through your re-download token.

## Versions

### 1.0.0 (2026-10-09)

First release: reviews how a paid x402 resource is advertised to catalogs, scanners and buyer agents, and how the seller's own scripts read those catalogs back; each finding has a fixed code, the place, the reason and a fix, then a verdict (not read as intended, your own checks mislead, no known problems). Readers misreading the listing: `[PARETO-ROWS]`, `[CAP-UNSTATED]`, `[WELL-KNOWN-ONLY]`, `[SCHEME-NAME]`, `[STALE-RECORD]`. The seller misreading the catalog and its buyers: `[ITEMS-FIELD]`, `[NO-ZERO-CONTROL]`, `[SHARED-CLOCK]`, `[CRAWLER-BUYER]`, `[DISCOVERY-READS-DB]`.

Facts re-checked on 2026-10-08 with free read-only fetches, no account: the catalog extension specification in the x402 project repository (`info` and `schema` required; `serviceName` and `tags` on the resource; the search response carries `resources`); the catalog's public documentation (search and merchant lookups answer under `resources`, browse answers under `items`; a `quality` figure per resource with 30-day calls, unique payers and last call); the published buyer client package (`DEFAULT_MAX_AMOUNT_PER_PAYMENT` is `"$1"`); the scanner indexer's published specification, version 1.7.5 (reads the OpenAPI document at `/openapi.json`; the well-known x402 file is a legacy source it no longer parses; auth hints map API key and sign-in schemes, bearer is not mentioned). Not re-checked, owner-measured: the name-first scheme classification in the indexer's code (2026-09-11), the scanner record that stays until a re-crawl (2026-09-11), the comparison bot reading the structured amount (2026-09-11), per-row delisting (2026-09), the scanner's server page answering 200 for an unregistered domain (2026-10-03), the crawler buyers (2026-09-12 and 2026-09-17).

Test set: 24 cases (16 traps, 8 controls), checked by `test/control.mjs` with zero model calls. Price set at the class A start ($0.05) pending the measured baseline; the numbers go here after the run.

## License

Perpetual, non-exclusive; use and modify for yourself incl. paid work; no resale or republishing. Holder: Georgi Kalchev, aiskills402.com. Terms: https://aiskills402.com/docs#license

## FAQ

### Which problems does it report?

Ten, in two groups. Readers misreading the listing: a tiered tariff advertised as one row, a price above the buyer client's default cap with no note for agents, a well-known x402 file the scanner no longer parses, a bearer scheme the scanner's indexer does not know by name, a scanner record never re-crawled after a fix. The seller misreading the catalog: a presence script reading the wrong response field, a presence check with no control that must return zero, one liveness clock for several catalog rows, a crawler counted as a customer, discovery endpoints that hit the database on every crawl.

### How is this different from the x402 seller skill?

The seller skill makes a 402 payable and gets the first listing through: the header, the extra field, where extensions go, the decoding of the incoming payment, the facilitator and the network. This one starts after that: how the catalog, a scanner and a buyer agent read what is advertised, and whether the seller's own scripts and alerts read the catalog and the buyers correctly. Those checks tend to pass for the wrong reason, which is what it catches.

### Which facts were verified, and how?

On 8 October 2026, from public pages: the catalog extension spec (info and schema required, serviceName and tags on the resource), the catalog's documentation (search and merchant answer under resources, browse under items, a quality figure per resource), the published buyer client (default cap of one dollar per payment) and the scanner indexer's published specification (reads the OpenAPI document, treats the well-known x402 file as legacy). The name-based scheme classification, the stale scanner record and the crawler buyers are the owner's September observations, labelled so in the file.

### Does it help Claude Sonnet?

Clearly, which is why it costs five cents. Both Claude models reviewed twenty-three listings, scripts and plans, guided by this file and cold, and we checked whether each planted problem got named in any words. Bare Sonnet named 10 of 16: it did not know that the standard buyer client stops at one dollar per payment or that the catalog answers under resources, not items, and it never asked for a control query that must come back empty. With the file it named all 16. Haiku went from 6 to 16.

## Related skills

- [x402 Seller: Get Paid and Listed in Bazaar](https://aiskills402.com/skills/x402-seller.md): $0.10 once
- [x402 Buyer: Pay Safely from an Agent Wallet](https://aiskills402.com/skills/x402-buyer.md): $0.05 once
- [A2A 1.0 Agent Card Writer](https://aiskills402.com/skills/a2a-agent-card.md): $0.03 once
- [MCP Registry Listing Writer](https://aiskills402.com/skills/mcp-registry-server-json.md): $0.05 once

## Measurement limits

- Models other than the two named above were not run.
- Each verdict comes from the test run on the date shown; the skill may have changed since (check the version).
- Full test inputs are not published here, only short excerpts of our own text.
- Results on your own texts, languages and domains can differ.

Offer note: Paid in USDC (USD-pegged) over x402 by an AI agent; one-time.
