io.github.vanakenj45/x402-agent-api

Agent Utility Suite (x402)

SEC filings, financials, insider trades; company data; web scraping; OFAC, email; HVAC calcs. x402

1.2.0
Version
remote
Transport
19
Tools

Security review

Review passed

Reviewed 1d ago.

  • tools: 19 tools scanned
  • metadata: scanned

No findings.

Tools (19)

  • sec_list_filings

    Free, no payment needed. Lists a US public company's 10-K (annual), 10-Q (quarterly) and 8-K (material event) filings from SEC EDGAR, newest first: filing date, fiscal year and period, sec.gov link, the sections sec_filing_section can extract from each report (Risk Factors, MD&A, Business, Legal Proceedings, Market Risk, Cybersecurity), and the event items of each 8-K (earnings 2.02, executive changes 5.02, deals 1.01, cybersecurity incidents 1.05, …). Every filing carries `next_call`: the exact paid tool call, with arguments and price, that returns its text. Use it to check what exists before paying, to find a specific year or event, or to track new filings. Filter by form and date (back to 2001); up to 50 filings per call. Look up by stock ticker or CIK. Rate-limited per client.

  • sec_filing_section

    Answers questions like "What are Tesla's risk factors?", "What did Apple's MD&A say about margins?" or "How has Microsoft's cybersecurity disclosure changed since 2023?". Returns exactly one section of a US public company's 10-K (annual) or 10-Q (quarterly) report from SEC EDGAR as clean text, ready for an LLM: Risk Factors (Item 1A), Management's Discussion and Analysis (MD&A), Business, Legal Proceedings, Market Risk, or Cybersecurity. Look up by stock ticker or CIK. Defaults to the latest filing; pass `fiscal_year` (2001 on) for an earlier year's report, or `accession_number` for an exact filing (the free sec_list_filings tool lists them, with the sections each one has). For several sections of one filing use sec_filing_sections; for what changed since last year, sec_section_changes. The table of contents, page numbers, hidden XBRL data and HTML are removed; tables are kept as readable rows. Includes the filing date, fiscal period, accession number and sec.gov link for citation. Use

  • sec_filing_sections

    Answers several questions about one report at once, e.g. "What are Nvidia's risks, and what does management say about results?". Returns 2 or 3 sections of the same 10-K or 10-Q from SEC EDGAR as clean text, in one call: Risk Factors, MD&A, Business, Legal Proceedings, Market Risk, Cybersecurity. Same inputs and output per section as sec_filing_section (latest filing, a `fiscal_year` since 2001, or an exact `accession_number`; by ticker, CIK or company name), at $0.015 for up to three sections instead of $0.01 each. Sections the filing does not contain are listed in `not_found`; if none can be read you get 404, free. You are only charged when a result is returned: invalid input (400) and upstream failures (4xx/5xx) are not settled. Costs $0.015 USDC per call via x402. Paid per call with x402 inside MCP (see the server instructions).

  • sec_section_changes

    Answers "What changed in Tesla's risk factors this year?", "Which new risks did Apple add?" or "How did Microsoft's MD&A change since 2022?". Compares one section of a company's 10-K with the same section of an earlier 10-K from SEC EDGAR, paragraph by paragraph: paragraphs added (new risk factors appear here), removed, and edited, each edit with a word-level diff marking deletions [-like this-] and insertions {+like this+}, plus a summary (counts and the share of text unchanged). Moved but identical paragraphs count as unchanged. Defaults to the latest 10-K against the one before it; pass `fiscal_year` or `accession_number` for the newer report and `compare_to_fiscal_year` for the older one (2001 on). Sections: Risk Factors, MD&A, Business, Legal Proceedings, Market Risk, Cybersecurity (filed from late 2023 on). By ticker, CIK or company name, with sec.gov links for both filings. Use it for risk monitoring, due diligence and investment research without reading two 100-page filings. If

  • sec_recent_events

    Answers "What happened at this company lately?": did the CEO or CFO leave, what were the latest earnings, was there an acquisition, major contract or cyber incident. Returns a US public company's most recent 8-K filings from SEC EDGAR, newest first: the material events companies must report within four business days, such as earnings releases (Item 2.02), CEO, CFO and director changes (5.02), material agreements and acquisitions (1.01, 2.01), cybersecurity incidents (1.05), impairments, auditor changes and shareholder votes. Each event has its item codes with official titles, the 8-K text as clean prose, and the text of its press-release exhibits (EX-99), e.g. the full earnings release. Filter by item codes and filing date, or ask for one exact 8-K by `accession_number` (the free sec_list_filings tool lists them); up to 10 events per call. Look up by stock ticker or CIK. Use it for event monitoring, news and earnings agents, due diligence or trading research, with sec.gov links for cit

  • sec_financials

    Answers "What were Apple's revenue and net income over the last five years?", "Is Tesla's free cash flow positive?" or "How fast is Nvidia growing quarter over quarter?". Returns a US public company's key financial-statement figures for its latest fiscal years (annual, from 10-Ks) or single quarters (quarterly), newest first, from the XBRL data companies file with the SEC: income statement (revenue, cost of revenue, gross profit, R&D, SG&A, operating income, pretax income, tax, net income, basic and diluted EPS, diluted shares), balance sheet (cash, current and total assets and liabilities, long-term debt, equity) and cash flow (operating cash flow, capex, free cash flow, dividends, buybacks), plus gross, operating and net margins and year-over-year revenue growth. Fourth quarters and single-quarter cash flows, which companies only report as full-year or year-to-date totals, are derived and flagged in `derived`. Each period cites the latest filing that reports it, so restated figures r

  • sec_insider_trades

    Answers "Are Nvidia's executives selling?", "Did any Intel insider buy shares on the open market this year?" or "What did Tesla's CFO do with his vested stock?". Returns a US public company's latest Form 4 filings from SEC EDGAR, the reports officers, directors and 10% owners must file within two business days of trading its stock: who traded (name, role, title), each transaction with its date, code and plain-English meaning, shares, price, dollar value, holdings after, and direct or indirect ownership, plus footnotes. A summary totals open-market purchases and sales (shares, dollars, which insiders) and separates sales under pre-arranged Rule 10b5-1 plans and sales that only cover taxes on vesting stock, which say little about insiders' views. Filter by filing date or transaction code (e.g. ["P"] for open-market purchases), optionally with option and RSU transactions; up to 40 filings per call. By ticker, CIK or company name. If nothing matches you get 404, free. You are only charged

  • sec_full_text_search

    Answers "Which companies disclosed a material weakness this year?", "Who mentions tariffs in their 10-Q risk factors?", "Which filings name this executive, product or supplier?" or "Has this company ever mentioned a going-concern doubt?". Searches the full text of SEC EDGAR filings and their exhibits since 2001 (EDGAR Full-Text Search): put exact phrases in double quotes. Filter by form (10-K, 10-Q, 8-K, S-1, DEF 14A, ...), by company (ticker, CIK or name) and by filing date. Each hit gives the company, ticker, CIK, form, document type (e.g. EX-99.1), filing date, period, accession number, document and filing-index links, 8-K items, location, and `next_call`: the paid call that reads it (a 10-K/10-Q section, the 8-K event, or the document as Markdown). Also returns the total hit count and the companies and forms with the most hits across all pages. Up to 50 results per call; page with `offset`. No match is a 404, free. You are only charged when a result is returned: invalid input (400)

  • company_profile

    Answers "Who is behind stripe.com?", "What does this company do, where is it based and who runs it?" or "Is it public, and what is its ticker?". Give a website domain (or any URL), a company name, a ticker or a CIK. Returns one profile combining: SEC EDGAR for public companies (legal name, tickers, exchanges, CIK, SIC industry, state of incorporation, fiscal year end, business address, phone, filer category, former names), Wikidata (founded, founders, CEO, headquarters, country, employees with date, industries, official website), a short Wikipedia description (with its URL for attribution), and the domain's email provider (from MX records) and registration date and registrar (RDAP). Works for private companies too (Wikidata and the domain). `sources` says which sources answered. For public companies, next_calls lead to their financials, 8-K events and insider trades. A name matching several SEC registrants returns the candidates, free; no company found is a 404, free. You are only char

  • scrape_markdown

    Use it when an agent needs to read a web page, article, documentation, PDF, blog post, product or pricing page, news story or RSS feed. Returns the main content as clean Markdown ready for an LLM: navigation, ads, footers and sidebars removed (or `mode: "full"` for the whole page), real tables as Markdown tables, code blocks with their language, math as TeX, the real (not lazy-loaded placeholder) images, absolute links without same-page anchors, and no needless escaping. Also returns metadata from meta tags and JSON-LD (description, author, published and modified time, language, site name, canonical URL, image, schema.org type), the HTTP status, word and token counts, and optionally the page's links. PDFs come back as text by page (up to 100 pages, 15 MB; no OCR), RSS/Atom feeds as item lists, JSON pretty-printed, and JavaScript-built pages that embed their content as data (JSON-LD articleBody, Next.js) are read from it. Long pages are returned in parts of up to 100,000 characters: pas

  • scrape_batch

    Use it when an agent needs to read several web pages at once: compare competitors' pricing pages, read the top search results, or the pages a site_map call found. Reads 2-5 public URLs in one paid call (one payment round trip instead of five), each exactly like scrape_markdown: the main content as clean Markdown (or `mode: "full"`), real tables, code blocks, metadata from meta tags and JSON-LD (author, dates, language, canonical URL), PDFs as text by page, RSS feeds as item lists, optionally each page's links. Results come back in request order, each either `ok: true` with the page or `ok: false` with an error code and message (bot check, unreachable, unsupported content), so one bad URL does not spoil the batch. Each page is cut at `max_chars_per_page` (default 20,000); next_calls continue a long page with scrape_markdown. If no page at all can be read, the call fails and is not charged. JavaScript is not executed. No account or API key. Costs $0.008 USDC per call via x402 ($0.002 per

  • site_map

    Use it when an agent needs to know what pages a website has before reading them: where is the pricing page, which docs pages exist, what did the blog publish lately, which product or careers pages are there. Give any URL on the site; returns the site's page URLs with their last-modified dates, like Firecrawl's /map. Reads the sitemaps named in robots.txt, else /sitemap.xml and /sitemap_index.xml, following sitemap indexes (up to 10 child sitemaps, 20,000 URLs) and gzip (.xml.gz) sitemaps; a site with no sitemap is mapped from its home page's links on the same host. Filter with `search` (every word must appear in the URL, title or date, e.g. "pricing" or "blog 2026") and `path_prefix` (e.g. "/docs/"); `limit` up to 1,000 (default 200). next_calls read the first matches with scrape_batch. When the site cannot be reached (502) or no page matches (404), you are not charged. No account or API key. Costs $0.002 USDC per call via x402. Paid per call with x402 inside MCP (see the server instru

  • domain_enrich

    Answers "Who hosts this company's email, and is it configured properly?" and "Which SaaS tools does this company use?". Profiles a domain from live DNS and its website: MX records and the inferred email provider (Google Workspace, Microsoft 365, …), SPF and DMARC configuration and policy, services the domain has verified ownership with (from TXT records: Google, Microsoft, Stripe, Atlassian, …), whether the website is reachable over HTTPS, and stack and security headers (Server, X-Powered-By, HSTS, CSP). Use it for lead enrichment, email deliverability checks, vendor due diligence or security reviews. You are only charged when a result is returned: invalid input (400) and upstream failures (4xx/5xx) are not settled. Costs $0.004 USDC per call via x402. Paid per call with x402 inside MCP (see the server instructions).

  • email_verify

    Answers "Is this email address valid?", "Will mail to it bounce?" and "Is it a throwaway, a shared inbox or a typo?" before an agent sends mail or saves a lead. Checks, without sending mail: syntax, whether the domain accepts email (MX records, an A/AAAA record as implicit MX, or a null MX that refuses all mail), disposable/temporary providers (a maintained list of thousands of domains), free webmail (Gmail, Outlook, Yahoo, ...), role accounts (info@, support@, noreply@), likely misspellings of big providers with a corrected suggestion (gmial.com → gmail.com), and the domain's SPF and DMARC records and email provider. Returns a verdict (deliverable, risky, undeliverable), a 0-100 score and the reasons. The mailbox itself is not probed (no SMTP), so a catch-all domain accepts any name. An invalid address is still an answer (undeliverable); only a DNS failure is an error, not charged. You are only charged when a result is returned: invalid input (400) and upstream failures (4xx/5xx) are

  • sanctions_screen

    Answers "Is this company or person sanctioned by the US?" and "Is this crypto wallet on OFAC's list?" for KYC, vendor onboarding, payments and compliance checks. Screens a name against the US Treasury OFAC Specially Designated Nationals (SDN) list and the Consolidated (non-SDN) sanctions lists, primary names and aliases, tolerant of word order ("PUTIN, Vladimir"), accents, punctuation, honorifics, legal suffixes and small typos; and a cryptocurrency address against the addresses OFAC lists (exact match). Each match has a 0-100 score, the name it matched (primary or a.k.a.), and the listing: OFAC ID, type, programs, title, aliases, addresses, date of birth, nationality, crypto addresses and remarks. Filter by type and country; set the score threshold. `clear` is true when nothing matched. Lists are refreshed from OFAC every 12 hours. A screening aid, not legal advice. You are only charged when a result is returned: invalid input (400) and upstream failures (4xx/5xx) are not settled. Cos

  • economic_indicators

    Answers "What is the 10-year Treasury yield?", "Is the yield curve inverted?", "What is inflation now?", "What is the unemployment rate?" and "Where is the fed funds rate?". Returns a snapshot of key US macro indicators from official public-domain sources: the U.S. Treasury's daily par yield curve (1 month to 30 years, 10y-2y spread, inversion), the Bureau of Labor Statistics' CPI and core CPI (year-over-year %), unemployment rate and nonfarm payrolls (level and monthly change), and the New York Fed's effective federal funds rate and target range. Optionally up to 24 months of monthly history. Choose indicators to keep the answer short. Sources are cached (yields and fed funds 1 hour, BLS 12 hours); a source that does not answer is listed in `unavailable`. If none answers, you are not charged. You are only charged when a result is returned: invalid input (400) and upstream failures (4xx/5xx) are not settled. Costs $0.003 USDC per call via x402. Paid per call with x402 inside MCP (see t

  • hvac_psychrometrics

    Answers "What is the dew point / enthalpy / humidity ratio of 95 °F air at 75 °F wet bulb?" and "What RH is 75 °F air with a 55 °F dew point in Denver?" for HVAC design, commissioning, energy and comfort work. From any two of dry bulb, wet bulb, dew point, relative humidity, humidity ratio, enthalpy or grains, returns the full state point: all seven plus specific volume, density and vapor pressure, at any site elevation (atmospheric pressure), in IP (°F, BTU/lb, gr/lb) or SI (°C, kJ/kg, g/kg). Uses the ASHRAE Handbook—Fundamentals (2021) Ch. 1 equations (Hyland-Wexler saturation pressure, ice below freezing) and is cross-checked against PsychroLib to within 0.02 °F. Every result includes `steps`: each equation with the numbers put into it and its ASHRAE reference, so the work can be checked or pasted into a calc package. Impossible states (wet bulb above dry bulb, RH over 100%) are errors and are not charged. You are only charged when a result is returned: invalid input (400) and upstr

  • hvac_coil_load

    Answers "What is the cooling coil load for 10,000 CFM from 80/67 °F to 55/54 °F?", "What leaves a coil that removes 270 MBH sensible and 60 MBH latent?" and "What is the mixed air with 20% outdoor air?" for AHU and RTU selection, coil schedules and design checks. Give the airflow and either the entering and leaving air (any two properties each) to get the sensible, latent and total loads, tons, sensible heat ratio, condensate rate and both full state points; or one state plus the loads to solve the other (cooling or heating). The entering air can be mixed from outdoor and return air states with an outdoor air % or airflow; or, given the mixed air, the outdoor air % is back-calculated. Standard-air equations (Qs = 1.08·CFM·ΔT, Ql = 4840·CFM·ΔW, Qt = 4.5·CFM·Δh as a cross-check), ASHRAE psychrometrics at the site elevation, IP (CFM, MBH) or SI (L/s, kW). Flags impossible (supersaturated) results. Every result includes `steps` with the equations and numbers. You are only charged when a re

  • hvac_duct_size

    Answers "What size duct for 1,000 CFM at 0.08 in. w.g./100 ft?", "What is the velocity and friction in a 24×12 duct at 2,000 CFM?" and "What height do I need with a 10 in depth limit?" for duct design and checking. Give any two of a duct size (round diameter, or rectangular width × height), airflow, velocity and friction rate (equal-friction sizing); a single width or height is held as a fixed side. Returns the exact round diameter and a rectangular equivalent (ASHRAE/Huebscher equivalent diameter for equal friction, or equal area for a velocity design), the nearest standard round and rectangular sizes with the velocity and friction of each, the friction loss per 100 ft (Darcy-Weisbach with Colebrook-White, galvanized steel, standard air), velocity pressure, Reynolds number, and design checks for velocity, friction and aspect ratio. IP (in, CFM, FPM) or SI (mm, L/s, m/s, Pa/m, metric sizes). Every result includes `steps` with the equations and numbers. You are only charged when a resul