
Security News
Open VSX Unblocks Extension IDs Used in Malware Campaign
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
@acrylicfiddle/x402tools-mcp
Advanced tools
MCP server exposing x402tools pay-per-call APIs as tools for AI agents
A Model Context Protocol server that gives AI agents 9 pay-per-call utility tools. Pay with USDC on Base via x402 protocol — agent's private key never leaves the agent.
| Tool | Description | Price |
|---|---|---|
generate_qr | Generate QR code from text/URL | $0.001 |
generate_styled_qr | Artistic QR with shapes & gradients | $0.005 |
capture_screenshot | Website screenshot (dark mode, selectors) | $0.005 |
dns_lookup | DNS records (A, AAAA, MX, NS, TXT, SOA) | $0.002 |
parse_document | HTML/PDF → structured JSON | $0.001 |
screen_prompt_injection | Detect prompt injection / jailbreak | $0.003 |
validate_email | Email validation + deliverability + risk | $0.003 |
render_pdf | HTML/URL → PDF | $0.005 |
extract_text_ocr | Image → text via OCR | $0.005 |
Edit ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):
Hosted (HTTP):
{
"mcpServers": {
"x402tools": {
"url": "https://mcp.x402tools.xyz/mcp"
}
}
}
Local (stdio with auto-pay convenience):
{
"mcpServers": {
"x402tools": {
"command": "npx",
"args": ["-y", "@x402tools/mcp-server"],
"env": {
"WALLET_PRIVATE_KEY": "0x..."
}
}
}
}
Edit ~/.cursor/mcp.json:
{
"mcpServers": {
"x402tools": {
"url": "https://mcp.x402tools.xyz/mcp"
}
}
}
Settings → MCP Servers → Add:
{
"x402tools": {
"serverUrl": "https://mcp.x402tools.xyz/mcp"
}
}
.vscode/mcp.json:
{
"mcpServers": {
"x402tools": {
"url": "https://mcp.x402tools.xyz/mcp"
}
}
}
~/.continue/config.json:
{
"experimental": {
"modelContextProtocolServers": [
{
"transport": {
"type": "streamable-http",
"url": "https://mcp.x402tools.xyz/mcp"
}
}
]
}
}
from openai import OpenAI
client = OpenAI()
response = client.responses.create(
model="gpt-4o",
tools=[{
"type": "mcp",
"server_label": "x402tools",
"server_url": "https://mcp.x402tools.xyz/mcp",
"require_approval": "never"
}],
input="Generate a QR code for https://x402tools.xyz"
)
from google.genai import types
config = types.GenerateContentConfig(
tools=[types.Tool(mcp_server={"url": "https://mcp.x402tools.xyz/mcp"})]
)
This server uses payment passthrough — the MCP server holds NO wallet. Each agent provides their own signed payment per call.
Flow:
402 + payment requirements_payment argument or PAYMENT-SIGNATURE HTTP headerEasiest signing: use @x402/fetch to wrap your fetch — it handles the 402 → sign → retry loop automatically:
import { wrapFetchWithPaymentFromConfig } from "@x402/fetch";
import { ExactEvmScheme } from "@x402/evm";
import { privateKeyToAccount } from "viem/accounts";
const account = privateKeyToAccount(process.env.WALLET_PRIVATE_KEY);
const paidFetch = wrapFetchWithPaymentFromConfig(fetch, {
schemes: [{ network: "eip155:*", client: new ExactEvmScheme(account) }]
});
// Now calls to mcp.x402tools.xyz auto-pay on 402
Manual signing (for hardware wallets, MPC, smart accounts):
requirements.accepts[0] from the 402 response@x402/evm's ExactEvmScheme.createPaymentPayload(2, requirements) with your ClientEvmSigner{ x402Version: 2, payload, extensions: {}, resource, accepted }PAYMENT-SIGNATURE HTTP header (or _payment tool arg)eip155:8453)0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913)0xcEbbB82a183Faa69b929eD1F417aAFc63fa3b5b6PAYMENT-SIGNATURE (x402 v2)https://mcp.x402tools.xyz/mcphttps://mcp.x402tools.xyz/.well-known/mcphttps://mcp.x402tools.xyz/healthio.github.acrylicfiddle/x402tools@x402tools/mcp-servergit clone https://github.com/acrylicfiddle/x402-services
cd x402-services/services/mcp-server
npm install
npm run build
PORT=4080 npm start
# MCP at http://localhost:4080/mcp
brew install mcp-publisher
mcp-publisher login github
cd services/mcp-server
mcp-publisher publish
MIT
FAQs
MCP server exposing x402tools pay-per-call APIs as tools for AI agents
We found that @acrylicfiddle/x402tools-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.