Is GhostKey — Route Paid APIs with x402 MCP server safe?
Probably. Read the findings first.
Use with care. Some checks failed or could not be verified.
Public scan report
scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it
no findings
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 150ms20/20
- Tool poisoning4 tool descriptions checked15/15
- Auth qualityopen endpoint, read-only tools10/15
- Maintenancerepository not readable: unknown3/15
- Maintainer identityverified namespace with website, no repo4/10
Overall 69/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what GhostKey — Route Paid APIs with x402 does
- DashclawPolicy checks, approvals, records, and governed HTTP capabilities for unattended agents.not reviewedEstablishedB
GhostKey — Route Paid APIs with x402 reviews, tools and install