
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
supership-scan
Advanced tools
Buy any x402 API or data on Base, Solana, or Polygon without a wallet on the seller's chain. Crossing fronts payment for your AI agent, verifies delivery on-chain, and returns the goods. Cross-substrate procurement for AI agents; also scans code.
Cross-substrate procurement for agents. Built by Crest Deployment Systems.
Point Crossing at any x402-priced data feed or service -- on Base, Solana, or Polygon -- and it buys it for you. You hold no wallet on the seller's chain, sign nothing, and bridge nothing. Crossing fronts the payment from its own treasury, verifies delivery on-chain, and hands you the goods.
Published on npm as
supership-scanfor install continuity. The server it ships is Crossing.
npm install -g supership-scan
Requires Node.js 18+.
npx -y -p supership-scan crossing
Starts the Crossing MCP server (stdio) for any MCP client -- Claude Code, Cursor, Windsurf. Or wire it into your client config:
{
"mcpServers": {
"crossing": {
"command": "npx",
"args": ["-y", "-p", "supership-scan", "crossing"]
}
}
}
| Tool | What it does |
|---|---|
procure | Buy any x402 source across any substrate. Pass the URL; get the goods back. First procurements are free. |
list_catalog | Browse sources Crossing can buy: crypto market data, news, on-chain analytics, prices. |
scan_directory | Scan a local directory for security issues before you ship. Free tier returns score + grade; no source stored. |
procure a source URL, or pick one from list_catalog.This is the caravan: one agent that reaches markets you can't, and brings the goods home.
Crossing runs as an x402-native service too.
| Endpoint | Method | Price | Description |
|---|---|---|---|
/catalog | GET | Free | Sources Crossing can procure |
/sample?url= | GET | Free | Procure one source, on the house |
/procure?url= | GET | per-call | Procure any source; Crossing fronts the seller cost and delivers |
/scan/free | POST | Free | Code security score + grade |
API base: https://supership.crestsystems.ai
Discovery: agent.json | llms.txt | OpenAPI
Apache 2.0. See LICENSE.
FAQs
supership indexes the entire x402 economy (52,000 services) so an AI agent can find and buy the right data across Base, Solana, and Polygon -- ranked by real usage, with a signed delivery receipt. No wallet needed on the seller's chain.
The npm package supership-scan receives a total of 39 weekly downloads. As such, supership-scan popularity was classified as not popular.
We found that supership-scan demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.