Security policy readback
Turn a rough SECURITY.md into private reporting guidance, safe-harbor wording, response targets and scoped vulnerability examples.
Useful first, commercial second: I open a small proof PR, then offer a fixed-scope packet when the project wants the full version.
Turn a rough SECURITY.md into private reporting guidance, safe-harbor wording, response targets and scoped vulnerability examples.
Vendor-ready scope matrix, reward rubric, disclosure SLA, report template, launch checklist and announcement copy.
Stale spec links, facilitator references, payment examples, agent spending controls and copy/paste smoke-test gaps.
Buyer-specific threat-model and module-readiness packet for Guardian#252: hook lifecycle, policy gates, receipt contract, mocked tests, and fail-closed rollout plan.
Buyer-specific listing-readiness packet for chatmcp/mcpso#2471: package-name drift, service-count consistency, API-key vs x402 default mode, and no-spend MCP acceptance checks.
Buyer-specific follow-on for pmxt-dev/pmxt#436 after merged PR #460: V2 contract domains, pUSD wrap/cache-sync flow, approval/trading failure matrix and regression checks.
Buyer-specific follow-on for MicroAI-Paygate#163 after merged PR #170: verified/missing/invalid receipt fixtures, buyer-agent trust contract and no-spend browser screenshots.
Buyer-specific follow-on for Mosss-OS/healthchain#24 after merged PR #51: wallet state matrix, allowance/approval receipt fixtures, transfer receipt checks and safe retry copy.
Manifest, no-payment 402, browser-agent CORS, price consistency and receipt-shape pass for sellers trying to get listed.
Buyer-specific no-spend packet for BankrBot/skills#395: HTTP 500 before 402, browser preflight status, challenge contract, and regression checks for listed x402 skills.
Fresh no-wallet x402 transcript for bytes32 nonce parsing, payTo drift, and payment challenge header gaps.
Focused pre-release pass for x402 CLI, SDK or docs changes: observed output, timeout/error paths, release-note wording and small docs-gap table.
Obol/Spark2 release pass for selected-token wording, Permit2 metadata, 402 challenge shape, facilitator assumptions and safe external-endpoint smoke instructions.
Diagnostic packet for routes that settle through CDP/facilitators but still fail discovery indexing: 402 challenge, Bazaar metadata, payTo search and escalation appendix.
Route-level pass for 402 challenge headers, CORS preflight, facilitator verify/settle and payment response visibility before browser agents hit it.
Frontend pass for catching 402s, wallet approval/signing states, retry-with-proof behavior, receipt rendering and browser-agent UX gaps.
Ready-to-post bounty specs for pay-per-query data agents: DFW permit trends, contractor pricing comparison, and paid-data MCP/x402 wrapper with proof/verification rules.
Buyer-specific packet for stablecoin bounty support: USDC payout states, claim wording, public receipts, and duplicate-solver controls before issue threads become payment negotiations.
Buyer-specific readback for NEXUS arb/check: free endpoint, 402 challenge, CORS, Bazaar status and a safe paid-settle approval boundary.
Buyer-specific implementation map for happyvertical/sdk#1029: Base USDC watch path, x402 proof boundary, deterministic address fixtures, refund seams and mocked-first tests.
Buyer-specific readiness packet for open-creator-rails.sdk#28: ocr-permit-v1 payloads, subscriber namespace, facilitator clients, idempotency risks and mocked-first tests.
Buyer-specific sales packet for remote water monitoring: grant qualification, ROI proof, uptime demo scripts, and farmer/advisor follow-up copy.
Buyer-specific mock-first scaffold for BeLorenzo/Game4Blockchain#3: payable agent-action discovery, explicit wallet boundary, receipt table, and frontend/CLI state checks.
Buyer-specific no-payment readback for solsentry/solsentry-app#2: fail-closed 402 behavior, browser CORS header allowlist, receipt exposure, and regression smoke script.
Buyer-specific go-to-market packet for devasign-api#91: first-contributor acquisition loop, issue proof packet, solver-quality filter, bounty receipt template, and 14-day measurement plan.
Buyer-specific spec packet for Aigen-Protocol: signed mission receipts that bind agent, mission, content hash, verifier decision, and settlement proof for third-party bounty verification.
Buyer-specific packet for LangChain paid tool calls: deterministic action refs, pre-payment SpendDecision receipts, simulation mode, and post-settlement audit linkage.
These are public PRs/comments showing the work style before a paid packet is requested.
Reply on the PR/issue or email info@transhumanism.com.au with the package you want.
Confirm scope and payment method: USDC on Base/Polygon or invoice.
Receive the packet as a PR-ready markdown bundle or directly as a follow-up PR.