Install
openclaw skills install @xavierleterrible-hub/signallayer-preflightReview x402 payment terms and Base recipient risks before a user-authorized API purchase or wallet interaction. Use for unfamiliar x402 endpoints or Base addresses when an agent needs bounded, evidence-aware preflight signals, not a guarantee of safety. Requires a separately configured x402 V2 payer for paid calls.
openclaw skills install @xavierleterrible-hub/signallayer-preflightUse before paying an unfamiliar x402 resource or interacting with an unfamiliar Base address. The preflight produces machine-readable findings, not a guarantee of recipient legitimacy. Never automatically authorize the subsequent payment based only on these findings.
Do not use as a contract audit, blanket fraud guarantee, personal financial advice, sanctions check, arbitrary web search, or speculative token quote. If uncertain about tool choice, call the free signal_layer_router first; it may return no_match.
| Surface | Address / current fee |
|---|---|
| Paid HTTP preflight | https://signallayer.floot.app/_api/v1/agent/preflight |
| Current preflight fee | 0.01 USDC per paid request (verify live challenge) |
| Network | eip155:8453 — Base Mainnet |
| Asset | Native USDC: 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 |
| Currently verified recipient | 0x60B3C6c053E926460D1E1053c516c859C95365e6 (public payee, not an agent wallet) |
| Free router | https://signallayer.floot.app/_api/v1/router |
| Free catalog | https://signallayer.floot.app/_api/tools |
| MCP server | https://signallayer.floot.app/_api/mcp — Streamable HTTP |
| API spec | https://signallayer.floot.app/openapi.json |
The live x402 challenge is authoritative for proposed payment terms. The agent must compare it with user policy and must reject any unexpected recipient, network, asset or amount. This Skill never overrides wallet-spend approvals.
pay, interact, transfer, unknown), expected network and authorized fee cap.signal_layer_router with the task and target. Stop on no_match or missing mandatory inputs.402. Check offered scheme=exact, network=eip155:8453, expected native USDC address, expected recipient address from a trusted configuration, and amount equal to or below the approved cap (currently 10000 atomic USDC units = $0.01). Do not sign an unexpected offer.decision, evidence, warnings, freshness and nextActions. A low-confidence/unknown result is not a safe approval.curl --get 'https://signallayer.floot.app/_api/v1/agent/preflight' \
--data-urlencode 'target=https://example.com/' \
--data-urlencode 'intent=pay'
An HTTP 402 is the expected unpaid response. It is not a successful risk check and must not be counted as revenue.
curl -X POST 'https://signallayer.floot.app/_api/v1/router' \
-H 'content-type: application/json' \
-d '{"task":"Preflight an unknown x402 endpoint before authorizing a purchase","target":"https://example.com/"}'
If using the MCP tool agent_preflight, use a client that supports x402 for MCP tool calls, not only the HTTP PAYMENT-SIGNATURE header. A previous HTTP settlement does not demonstrate MCP paid interoperability.
If the user has already authorized a funded Coinbase Agentic Wallet (AWAL), Coinbase's maintained CLI can make one x402 V2 HTTP request. After separately inspecting and matching the unsigned challenge's Base Mainnet network, native USDC contract, the known SignalLayer payee and the 0.01 USDC price, and only with explicit authorization to spend that fee, the following is a copyable example:
npx awal@latest x402 pay 'https://signallayer.floot.app/_api/v1/agent/preflight?target=https%3A%2F%2Fexample.com%2F&intent=pay' --max-amount 10000 --json
The command above spends real USDC if executed. This Skill never runs it automatically. Do not infer authorization from installing this Skill, a user allowing a preflight check, or a low fee cap. Never silently authenticate, fund, sign, pay or automatically retry. See README.md for wallet prerequisites and verification. This illustrates HTTP x402 only; MCP-paid settlement remains unverified.
Never paste signatures, seed phrases or private keys into support messages. See README.md for install and testing instructions.