GitHub Action v1.0.1
GitHub Action v1.0.1
Agent Commerce Guard provides a free policy-preflight Action and gives every completed run a direct path to the private local package and paid workflow API.
Use The Stable Major Ref
- uses: fxjim/agent-commerce-guard@v1
with:
manifest: agent-actions.json
fail-on: blockedThe Action:
- Reviews AI-agent wallet spend, deployments, destructive commands, token launches, marketplace work, social actions, and credential-sensitive operations.
- Exposes
checkout-urlfor the private local package andx402-evaluate-urlfor the paid workflow API. - Adds the package checkout and paid API to every completed GitHub job summary.
- Rejects secret-key patterns and enforces the five-action / 20 KB hosted-evaluator bound.
- Supports configurable
fail-onbehavior.
Both stable tags point to the tested Action source:
v1->f554834849a3223a24aba117386bd53893841a4bv1.0.1->f554834849a3223a24aba117386bd53893841a4b
Inspect Before Buying
- Interactive package preview: https://fxjim.github.io/agent-commerce-guard/sample/
- Full sample CLI report: https://agent-commerce-guard.vercel.app/sample-report
- Machine-readable sample: https://agent-commerce-guard.vercel.app/sample-report.json
- Package inventory: https://agent-commerce-guard.vercel.app/package-metadata.json
The sample reports 2 allow, 0 review, and 2 deny. Automated tests prove that all 13 advertised buyer-relevant files exist in the paid tarball and that the policy engine, report formatter, and example manifest are byte-identical to the archive copies.
Private Workflow Routes
- Buy the local package for 1 USDC: https://agent-commerce-guard.vercel.app/pay
- Verify payment: https://agent-commerce-guard.vercel.app/verify
- Success handoff:
https://agent-commerce-guard.vercel.app/success?tx={tx} - Paid x402 evaluation:
POST https://agent-commerce-guard.vercel.app/api/x402-evaluate - Paid x402 download:
GET https://agent-commerce-guard.vercel.app/api/x402-download - x402 discovery: https://agent-commerce-guard.vercel.app/.well-known/x402
Current Verification
- Production deployment:
dpl_5NGPaGLkQU8V4rr4S25kVicmEYCD - Public launch commit:
4a40e76a55b7be66da0198e8977eb7a2576bf194 - GitHub Pages workflow:
30061589933succeeded - Product tests: 59/59 passed
- Dependency audit: 0 vulnerabilities
- Buyer preflight: all 6 checks passed
- Paid package SHA-1:
c67fb09bd83da591c58ae5fae002a6a59557fc97 - Paid package size: 122737 bytes
The hosted evaluator receives the submitted manifest. Do not send secrets, private source, credentials, or sensitive customer data. Use the paid local package for private manifests.
Payment completion is recognized only from qualifying onchain Base USDC transfer evidence or the live verifier.