{"x402Version":2,"service":"HALOWERK sicherwerk","version":"1.0.0","network":"eip155:8453","network_name":"Base Mainnet","chain_id":8453,"recipient":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","asset":{"symbol":"USDC","address":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","decimals":6},"facilitators":["CDP","https://facilitator.xpay.sh"],"payment_headers":{"primary":"PAYMENT-SIGNATURE","accepted":["PAYMENT-SIGNATURE","X-Payment","PAYMENT"],"challenge":["PAYMENT-REQUIRED"],"response":["PAYMENT-RESPONSE"]},"resources":[{"url":"https://sicher.halowerk.com/v1/cve-check","method":"POST","name":"cve_check","description":"Queries OSV.dev for a list of packages with versions across npm, PyPI, Go, Maven, crates.io, NuGet, RubyGems, Packagist and the Linux distributions. For each package it returns the vulnerabilities found with their identifiers, severity and summary, and the single figure that decides what to do next: the lowest version that fixes all of them, derived from the fixed-version events in the affected ranges. Findings are counted by severity and the whole list gets one worst-case verdict so a pipeline can gate on it. Severity is read from several places because databases disagree on where they put it, and the source of the rating is reported. OSV records what is published — a package with no finding is not proven safe, only unreported, and an internal or vendored package is invisible here.","summary":"Check a package list against known vulnerabilities and get, per package, the severity breakdown and the lowest version that closes every finding.","inputSchema":{"type":"object","required":["packages"],"additionalProperties":false,"properties":{"packages":{"type":"array","minItems":1,"maxItems":100,"description":"The packages to check.","items":{"type":"object","required":["name","version"],"additionalProperties":false,"properties":{"name":{"type":"string","minLength":1,"maxLength":200,"description":"Package name as the ecosystem spells it."},"version":{"type":"string","minLength":1,"maxLength":60,"description":"Exact installed version."},"ecosystem":{"type":"string","maxLength":30,"description":"Ecosystem, e.g. npm, PyPI, Go. Defaults to the top-level value."}}}},"ecosystem":{"type":"string","maxLength":30,"default":"npm","description":"Default ecosystem for entries that do not name one."},"min_severity":{"type":"string","enum":["low","medium","high","critical"],"description":"Only report findings at or above this severity."},"include_details":{"type":"boolean","default":true,"description":"Fetch summary and severity per finding. Off is faster but returns ids only."}}},"mimeType":"application/json","accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","price":{"amount":"5000","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"asset":"USDC","network_name":"Base Mainnet","name":"USD Coin","version":"2","assetTransferMethod":"eip3009","eip712Domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}}},"maxTimeoutSeconds":300}]},{"url":"https://sicher.halowerk.com/v1/sbom","method":"POST","name":"sbom_build","description":"Parses package-lock.json, package.json, requirements.txt, go.mod and Cargo.lock and emits a bill of materials in CycloneDX 1.5 or SPDX 2.3, with a package URL per component. The distinction that decides whether the document is worth anything is made explicit: a lockfile names the versions actually installed, a manifest only names ranges, and a bill of materials built from ranges describes what might be installed rather than what is. Files parsed from ranges are marked and the components carry the range alongside the resolved value. Direct and transitive dependencies are separated where the format allows, development-only entries are flagged, and duplicate name-version pairs are collapsed. Everything runs locally on the text you pass — nothing is fetched and no registry is consulted, so the result reflects your files and not the current state of any registry.","summary":"Build a CycloneDX or SPDX software bill of materials from package manifests or lockfiles, and say whether the versions are exact enough to be evidence.","inputSchema":{"type":"object","required":["files"],"additionalProperties":false,"properties":{"files":{"type":"array","minItems":1,"maxItems":10,"description":"The manifest or lock files.","items":{"type":"object","required":["content"],"additionalProperties":false,"properties":{"filename":{"type":"string","maxLength":300,"description":"File name; the type is detected from content if absent."},"content":{"type":"string","maxLength":4194304,"description":"File contents as text."}}}},"format":{"type":"string","enum":["cyclonedx","spdx","plain"],"default":"cyclonedx","description":"Output format."},"include_dev":{"type":"boolean","default":false,"description":"Include development-only dependencies."},"project_name":{"type":"string","maxLength":200,"default":"unnamed-project","description":"Name for the document metadata."}}},"mimeType":"application/json","accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","price":{"amount":"5000","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"asset":"USDC","network_name":"Base Mainnet","name":"USD Coin","version":"2","assetTransferMethod":"eip3009","eip712Domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}}},"maxTimeoutSeconds":300}]},{"url":"https://sicher.halowerk.com/v1/license-check","method":"POST","name":"license_check","description":"Looks up the declared licence of each package through deps.dev and sorts the result by the only question that matters for a closed, sold product: what does this licence demand. Permissive licences need attribution. Weak copyleft affects changes to the library itself. Strong copyleft can force disclosure of the whole work on distribution. Network copyleft such as AGPL and SSPL bites on operating the software as a service, which is the sharpest case for a paid API. Multi-licence expressions are handled by their operator — with OR the mildest applies because you may choose, with AND the strictest does. Packages whose licence is undeclared or outside the table are reported as unknown instead of assumed harmless. This is a classification to triage with, not legal advice, and the licence deps.dev records is what the package declared, which is not always what its files say.","summary":"Resolve package licences and classify them for commercial use: which force disclosure, which only need attribution, and which are unknown.","inputSchema":{"type":"object","required":["packages"],"additionalProperties":false,"properties":{"packages":{"type":"array","minItems":1,"maxItems":80,"description":"Packages to check.","items":{"type":"object","required":["name"],"additionalProperties":false,"properties":{"name":{"type":"string","minLength":1,"maxLength":200},"version":{"type":"string","maxLength":60,"description":"Exact version. The default version is used if omitted."},"ecosystem":{"type":"string","maxLength":30}}}},"ecosystem":{"type":"string","maxLength":30,"default":"npm","description":"Default ecosystem."},"usage":{"type":"string","enum":["saas","distributed","internal"],"default":"saas","description":"How you use the code. saas = operated as a network service, which is what triggers AGPL."}}},"mimeType":"application/json","accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","price":{"amount":"2000","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"asset":"USDC","network_name":"Base Mainnet","name":"USD Coin","version":"2","assetTransferMethod":"eip3009","eip712Domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}}},"maxTimeoutSeconds":300}]},{"url":"https://sicher.halowerk.com/v1/container-inspect","method":"POST","name":"container_inspect","description":"Reads the manifest and config of an OCI or Docker image straight from the registry — a few kilobytes, never the layers, and the image is never run. Returns the digest, the platforms a multi-arch index covers, every layer with its size and the command that produced it, and the runtime configuration: entrypoint, command, working directory, exposed ports, volumes and environment variable names. Security-relevant findings are called out: an image configured to run as root, an image whose build date is far in the past and therefore missing every base-image patch since, and a tag rather than a digest being used, which is mutable and can point somewhere else tomorrow. Works with Docker Hub, GitHub Container Registry, Quay and registry.k8s.io for public images. Environment values are not returned, only names — a build that baked a secret into a layer would otherwise leak it here.","summary":"Inspect a container image without pulling it: manifest, layers with sizes, architectures, entrypoint, user, exposed ports and image age.","inputSchema":{"type":"object","required":["image"],"additionalProperties":false,"properties":{"image":{"type":"string","maxLength":400,"description":"Image reference, e.g. alpine:3.19, ghcr.io/owner/app:v1 or repo@sha256:…"},"platform":{"type":"string","maxLength":40,"default":"linux/amd64","description":"Which platform to resolve from a multi-arch index."},"stale_days":{"type":"integer","minimum":1,"maximum":3650,"default":180,"description":"Warn when the image was built more than this many days ago."}}},"mimeType":"application/json","accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","price":{"amount":"5000","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"asset":"USDC","network_name":"Base Mainnet","name":"USD Coin","version":"2","assetTransferMethod":"eip3009","eip712Domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}}},"maxTimeoutSeconds":300}]},{"url":"https://sicher.halowerk.com/v1/tls-chain","method":"POST","name":"tls_chain","description":"Opens a TLS connection and reports the chain the server presents. Per certificate: subject and issuer, validity window with days remaining, serial, SHA-256 fingerprint, key type and size, and the subject alternative names. Above that it answers the questions a monitor asks: is the requested hostname covered by the leaf certificate including wildcard rules, how many days until the nearest expiry, is any certificate self-signed or signed with a weak algorithm, does the server send its intermediates or leave the client to find them — a chain that validates in a browser can still fail in a language runtime that does not fetch missing intermediates. The negotiated protocol version and cipher are reported. It connects to the host itself, so there is no third-party dependency and no rate limit.","summary":"Read the TLS certificate chain of a host: every certificate with its names, validity, key type and signature, plus expiry warnings and whether the hostname is actually covered.","inputSchema":{"type":"object","required":["host"],"additionalProperties":false,"properties":{"host":{"type":"string","maxLength":255,"description":"Hostname or https URL, e.g. example.com."},"port":{"type":"integer","minimum":1,"maximum":65535,"default":443,"description":"TLS port."},"servername":{"type":"string","maxLength":255,"description":"SNI name if it differs from host."},"warn_days":{"type":"integer","minimum":1,"maximum":365,"default":30,"description":"Warn when a certificate expires within this many days."}}},"mimeType":"application/json","accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","price":{"amount":"2000","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"asset":"USDC","network_name":"Base Mainnet","name":"USD Coin","version":"2","assetTransferMethod":"eip3009","eip712Domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}}},"maxTimeoutSeconds":300}]},{"url":"https://sicher.halowerk.com/v1/jwt-verify","method":"POST","name":"jwt_verify","description":"Decodes a JWT and checks it in two layers. Structure and claims: expiry, not-before and issued-at against the current time with the clock skew you allow, issuer and audience against the values you expect, and the token lifetime. Signature: HMAC with a shared secret, or RSA, RSA-PSS and ECDSA against a PEM key or a JWKS you point at, with the kid matched to the right key. On top of that it names the attacks that live in this exact spot: alg set to none, an HMAC algorithm where an asymmetric key is expected which is the classic key-confusion path, a token with no expiry at all, and an audience that does not name you. Without a key or secret the token is decoded and its claims judged, and the signature is reported as unverified rather than assumed good. The published example uses a public synthetic test key and a deliberately expired token: its signature is valid, but its claims must be rejected.","summary":"Verify a JWT signature and claims, and name the classic token attacks explicitly: alg none, HMAC confusion, unbounded lifetime, missing audience.","inputSchema":{"type":"object","required":["token"],"additionalProperties":false,"properties":{"token":{"type":"string","minLength":10,"maxLength":20000,"description":"The JWT in compact form."},"secret":{"type":"string","maxLength":2000,"description":"Shared secret for HS256/384/512."},"public_key_pem":{"type":"string","maxLength":8000,"description":"PEM public key for RS/PS/ES algorithms."},"jwks_url":{"type":"string","maxLength":2000,"description":"JWKS endpoint; the key is picked by kid."},"expected_issuer":{"type":"string","maxLength":500,"description":"Issuer the token must carry."},"expected_audience":{"type":"string","maxLength":500,"description":"Audience the token must name."},"clock_skew_seconds":{"type":"integer","minimum":0,"maximum":3600,"default":60,"description":"Tolerance for exp and nbf."},"max_lifetime_seconds":{"type":"integer","minimum":1,"description":"Flag tokens valid for longer than this."}}},"mimeType":"application/json","accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","price":{"amount":"2000","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"asset":"USDC","network_name":"Base Mainnet","name":"USD Coin","version":"2","assetTransferMethod":"eip3009","eip712Domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}}},"maxTimeoutSeconds":300}]},{"url":"https://sicher.halowerk.com/v1/webhook-signature","method":"POST","name":"webhook_signature","description":"Providers each build their signing string differently — some sign only the body, others prepend a timestamp, an id, or a version marker in a fixed order — and getting that order wrong produces a mismatch that looks exactly like an attack. This checks the signature the way the named provider actually specifies, with constant-time comparison, and returns the string that was signed so a mismatch can be debugged instead of guessed at. Where the provider signs a timestamp, it is checked against a tolerance window, because a signature valid forever lets any captured delivery be replayed. The body must be passed exactly as received, byte for byte: a re-serialised JSON payload has different bytes and will never match, which is the single most common cause of a failed check and is called out when the body looks reformatted. The published example uses a public synthetic test key and a synthetic body; these values must never be used for real webhook authentication.","summary":"Verify a signed webhook from GitHub, Stripe, Shopify, Slack, Svix or a plain HMAC scheme, with the timestamp window checked where the provider signs one.","inputSchema":{"type":"object","required":["provider","body","secret"],"additionalProperties":false,"properties":{"provider":{"type":"string","enum":["github","stripe","shopify","slack","svix","generic_hmac"],"description":"Which provider signed the request."},"body":{"type":"string","maxLength":200000,"description":"The raw request body exactly as received, not re-serialised."},"secret":{"type":"string","minLength":1,"maxLength":2000,"description":"The signing secret."},"signature":{"type":"string","maxLength":2000,"description":"The signature header value. Required unless headers is given."},"headers":{"type":"object","description":"All request headers; the right one is picked by provider."},"timestamp":{"type":"string","maxLength":40,"description":"Timestamp, if the provider signs one and it is not in the headers."},"message_id":{"type":"string","maxLength":200,"description":"Message id for schemes that sign one, e.g. Svix."},"tolerance_seconds":{"type":"integer","minimum":1,"maximum":86400,"default":300,"description":"How old a signed timestamp may be."}}},"mimeType":"application/json","accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","price":{"amount":"2000","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"asset":"USDC","network_name":"Base Mainnet","name":"USD Coin","version":"2","assetTransferMethod":"eip3009","eip712Domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}}},"maxTimeoutSeconds":300}]},{"url":"https://sicher.halowerk.com/v1/provenance-verify","method":"POST","name":"provenance_verify","description":"Searches the Sigstore Rekor log for entries matching an artefact hash and returns what a provenance claim is actually worth: the log index and inclusion time, the signing identity from the certificate, and where available the source repository and workflow reference that produced it. Several entries for one hash are all returned, because a rebuild or a second signer is a fact worth seeing rather than collapsing. The search is by hash only: the artefact itself is never uploaded, so a hash can be checked without handing the file to anyone. An entry in the log proves that someone signed this hash at that time and that the record is publicly auditable — it does not prove the artefact is safe, that the signer is who you want, or that the build was honest. Absence is likewise not evidence of tampering; most software is simply never signed.","summary":"Look up an artefact hash in the Sigstore transparency log and report who signed it, from which repository and workflow, and when.","inputSchema":{"type":"object","additionalProperties":false,"properties":{"sha256":{"type":"string","minLength":64,"maxLength":71,"description":"Artefact SHA-256, with or without the sha256: prefix."},"log_index":{"type":"integer","minimum":0,"description":"Fetch one specific log entry instead of searching."},"email":{"type":"string","maxLength":200,"description":"Search by signer email instead of by hash."},"limit":{"type":"integer","minimum":1,"maximum":20,"default":5,"description":"How many entries to detail."}}},"mimeType":"application/json","accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","price":{"amount":"5000","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"asset":"USDC","network_name":"Base Mainnet","name":"USD Coin","version":"2","assetTransferMethod":"eip3009","eip712Domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}}},"maxTimeoutSeconds":300}]},{"url":"https://sicher.halowerk.com/v1/hash-reputation","method":"POST","name":"hash_reputation","description":"Queries three abuse.ch metadata services for an MD5, SHA-1 or SHA-256 value. It reports known malware metadata, associated ThreatFox indicators, and URLhaus payload provenance, then derives a conservative known-malicious or unknown verdict. No endpoint for sample retrieval is called and no binary is downloaded. A missing record means unknown to these sources, not proven benign. VirusTotal is deliberately not used because its public terms do not permit redistribution in this paid product.","summary":"Check a file hash against MalwareBazaar, ThreatFox and URLhaus and return reputation metadata and linked indicators without downloading any sample.","inputSchema":{"type":"object","required":["hash"],"additionalProperties":false,"properties":{"hash":{"type":"string","minLength":32,"maxLength":64,"pattern":"^[A-Fa-f0-9]+$","description":"MD5, SHA-1 or SHA-256 digest."}}},"mimeType":"application/json","accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","price":{"amount":"5000","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"asset":"USDC","network_name":"Base Mainnet","name":"USD Coin","version":"2","assetTransferMethod":"eip3009","eip712Domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}}},"maxTimeoutSeconds":300}]},{"url":"https://sicher.halowerk.com/v1/log-chain-verify","method":"POST","name":"log_chain_verify","description":"Recomputes every record hash from a canonical JSON representation of id, sequence, timestamp, previous_hash and payload, then checks that each record points to the hash of the record before it. If a root_hash is supplied, the same computed record hashes are folded into a deterministic binary Merkle tree with the last leaf duplicated on odd levels. The result names the first broken position, separates hash mismatches from broken links, and reports enough computed values to repair the log producer without guessing. It does not fetch external transparency logs, does not store the trail, and does not prove the events are true; it proves only whether the supplied chain is internally consistent.","summary":"Verify an audit log hash chain, identify the first broken record, and optionally compare a Merkle root over the same entries.","inputSchema":{"type":"object","required":["records"],"additionalProperties":false,"properties":{"records":{"type":"array","minItems":1,"maxItems":500,"description":"Audit records in chain order.","items":{"type":"object","required":["id","sequence","timestamp","previous_hash","payload","hash"],"additionalProperties":false,"properties":{"id":{"type":"string","minLength":1,"maxLength":160,"description":"Stable event id."},"sequence":{"type":"integer","minimum":0,"maximum":1000000000,"description":"Monotonic event position."},"timestamp":{"type":"string","minLength":1,"maxLength":80,"description":"Event time as supplied by the log producer."},"previous_hash":{"anyOf":[{"type":"string","minLength":64,"maxLength":71},{"type":"null"}],"description":"Hash of the previous record, or null for the first record."},"payload":{"description":"Event payload to include in the record hash."},"hash":{"type":"string","minLength":64,"maxLength":71,"description":"Claimed SHA-256 hash of this record."}}}},"root_hash":{"type":"string","minLength":64,"maxLength":71,"description":"Optional claimed Merkle root over the computed record hashes."},"require_monotonic_sequence":{"type":"boolean","default":true,"description":"Require sequence numbers to increase by one."}}},"mimeType":"application/json","accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","price":{"amount":"5000","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"asset":"USDC","network_name":"Base Mainnet","name":"USD Coin","version":"2","assetTransferMethod":"eip3009","eip712Domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}}},"maxTimeoutSeconds":300}]},{"url":"https://sicher.halowerk.com/v1/oss-openssl-csr-self-signature-audit","method":"POST","name":"oss_openssl_csr_self_signature_audit","description":"Runs the pinned OpenSSL build against a submitted certificate request and answers two questions a registration authority has to settle before it signs anything: does the request carry a valid self-signature over its own body, and what exactly is being requested. The reply names the subject, the public key parameters and every requested extension as OpenSSL parses them, so a policy check compares against the parsed request rather than the text an applicant supplied. It proves possession of the matching private key at signing time and nothing else: it does not check the applicant's identity, does not consult any CA policy, does not verify that the requested names are controlled by the applicant, and it never signs or issues a certificate.","summary":"Verify the proof-of-possession signature on a PKCS#10 certificate request and read back the subject, key and extensions it actually asks for.","inputSchema":{"type":"object","additionalProperties":false,"required":["csr_pem"],"properties":{"csr_pem":{"type":"string","maxLength":262144,"minLength":1}}},"mimeType":"application/json","accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","price":{"amount":"2000","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"asset":"USDC","network_name":"Base Mainnet","name":"USD Coin","version":"2","assetTransferMethod":"eip3009","eip712Domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}}},"maxTimeoutSeconds":300}]},{"url":"https://sicher.halowerk.com/v1/oss-openssl-public-key-math-audit","method":"POST","name":"oss_openssl_public_key_math_audit","description":"Takes a public key in SubjectPublicKeyInfo PEM form and runs the pinned OpenSSL build's own consistency checks over it, then reports the algorithm, the key size in bits and the parameters it found. This catches keys that parse but are structurally unusable: a modulus that is not a valid product, curve parameters that do not match a known group, a size that no longer meets the build's security level. The reported bit count comes from the key itself, not from the label a producer attached. It is a mathematical audit only: it says nothing about who holds the private key, whether the key has been revoked, whether it appears in a certificate, or whether any given protocol will accept it.","summary":"Check whether a SubjectPublicKeyInfo public key is mathematically sound and report its algorithm, size and parameters as the pinned OpenSSL build reads them.","inputSchema":{"type":"object","additionalProperties":false,"required":["public_key_pem"],"properties":{"public_key_pem":{"type":"string","maxLength":262144,"minLength":1}}},"mimeType":"application/json","accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","price":{"amount":"2000","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"asset":"USDC","network_name":"Base Mainnet","name":"USD Coin","version":"2","assetTransferMethod":"eip3009","eip712Domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}}},"maxTimeoutSeconds":300}]},{"url":"https://sicher.halowerk.com/v1/oss-openssl-certificate-bundle-normalize","method":"POST","name":"oss_openssl_certificate_bundle_normalize","description":"Accepts up to sixteen certificates in any PEM shape and returns a single normalized bundle. Duplicates are identified by their canonical DER encoding, not by the PEM text, so the same certificate supplied twice with different line wrapping, different header text or trailing whitespace collapses into one entry. The reply gives the input count, the unique count and the resulting bundle, which makes it usable as a preparation step before a trust store is built or shipped. It does not build a chain, does not order the certificates into an issuing path, does not check validity dates or signatures, and does not decide whether any of the certificates should be trusted.","summary":"Turn a pile of PEM certificates into one deduplicated bundle, comparing canonical DER encodings so cosmetic differences do not count as distinct certificates.","inputSchema":{"type":"object","additionalProperties":false,"required":["certificates_pem"],"properties":{"certificates_pem":{"type":"array","maxItems":16,"items":{"type":"string","maxLength":262144,"minLength":1},"minItems":1}}},"mimeType":"application/json","accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","price":{"amount":"2000","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"asset":"USDC","network_name":"Base Mainnet","name":"USD Coin","version":"2","assetTransferMethod":"eip3009","eip712Domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}}},"maxTimeoutSeconds":300}]},{"url":"https://sicher.halowerk.com/v1/oss-openssl-rfc3161-request-build","method":"POST","name":"oss_openssl_rfc3161_request_build","description":"Produces a ready-to-post RFC 3161 TimeStampReq for a SHA-256 digest you already computed. The pinned OpenSSL build encodes the message imprint, adds a fresh nonce so a replayed response can be detected, and sets the flag that asks the timestamp authority to include its signing certificate in the reply. The result is returned as a binary artifact together with the imprint it was built around, so the caller can check that the request really covers the intended digest. Only the request is built here: nothing is sent, no timestamp authority is contacted, no response is parsed or verified, and the returned artifact carries no evidentiary value until a TSA has signed over it.","summary":"Build a binary RFC 3161 timestamp request around a supplied SHA-256 digest, with a fresh nonce and the certificate-request flag set.","inputSchema":{"type":"object","additionalProperties":false,"required":["sha256"],"properties":{"sha256":{"type":"string","pattern":"^[a-fA-F0-9]{64}$"}}},"mimeType":"application/json","accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","price":{"amount":"1000","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"asset":"USDC","network_name":"Base Mainnet","name":"USD Coin","version":"2","assetTransferMethod":"eip3009","eip712Domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}}},"maxTimeoutSeconds":300}]},{"url":"https://sicher.halowerk.com/v1/oss-openssl-cms-envelope-encrypt","method":"POST","name":"oss_openssl_cms_envelope_encrypt","description":"Wraps the supplied bytes in a CMS EnvelopedData envelope using the pinned OpenSSL build, addressed to every recipient certificate you pass in. A single content-encryption key protects the payload and is itself encrypted once per recipient, so any one holder of a matching private key can decrypt, and nobody else can. The reply names the cipher actually used and the recipient count, so an agent can record what it produced rather than assume it. Confidentiality only: the envelope is not signed, so it carries no proof of who created it and no integrity guarantee against a party who can re-encrypt. No recipient certificate is validated for trust, expiry or revocation before use.","summary":"Encrypt supplied bytes into a CMS EnvelopedData structure for up to sixteen recipient certificates, so only the matching private keys can open it.","inputSchema":{"type":"object","additionalProperties":false,"required":["data_base64","recipients_pem"],"properties":{"data_base64":{"type":"string","maxLength":262144,"minLength":1},"recipients_pem":{"type":"array","maxItems":16,"items":{"type":"string","maxLength":262144,"minLength":1},"minItems":1}}},"mimeType":"application/json","accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","price":{"amount":"2000","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"asset":"USDC","network_name":"Base Mainnet","name":"USD Coin","version":"2","assetTransferMethod":"eip3009","eip712Domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}}},"maxTimeoutSeconds":300}]},{"url":"https://sicher.halowerk.com/v1/oss-openssl-pkcs12-certificate-store-build","method":"POST","name":"oss_openssl_pkcs12_certificate_store_build","description":"Builds a PKCS#12 container holding certificates only, for the common case where a runtime insists on PKCS#12 as its trust store format. The password is explicitly empty and reported back as such, so nothing depends on an undocumented default, and the reply states outright that the store contains no private keys. That matters: a PKCS#12 file is the usual carrier for a key, and a consumer must be able to tell a trust store from an identity store without opening it. No private key is ever accepted, generated or embedded. The certificates are not validated, not chained, and not checked for expiry or revocation before packaging.","summary":"Package up to sixteen certificates into an interoperable certificate-only PKCS#12 store with an explicitly empty password and no private key inside.","inputSchema":{"type":"object","additionalProperties":false,"required":["certificates_pem"],"properties":{"certificates_pem":{"type":"array","maxItems":16,"items":{"type":"string","maxLength":262144,"minLength":1},"minItems":1}}},"mimeType":"application/json","accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","price":{"amount":"2000","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"asset":"USDC","network_name":"Base Mainnet","name":"USD Coin","version":"2","assetTransferMethod":"eip3009","eip712Domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}}},"maxTimeoutSeconds":300}]},{"url":"https://sicher.halowerk.com/v1/oss-openssl-dh-group-check","method":"POST","name":"oss_openssl_dh_group_check","description":"Runs the pinned OpenSSL build's parameter checks over a supplied finite-field Diffie-Hellman group and reports whether it passes, along with the detail output that says why. The point is to catch parameters that are syntactically fine but cryptographically unsafe before they reach a handshake: a non-prime modulus, a generator of small order, a group below the build's security level. The check runs under a hard CPU deadline, so a deliberately expensive artifact is rejected rather than allowed to occupy the server. No private exponent is generated and no shared secret is computed. A pass means the parameters are well formed by these rules, not that the group is appropriate for your threat model.","summary":"Validate supplied finite-field Diffie-Hellman parameters against the pinned OpenSSL build's own checks, under a strict CPU deadline.","inputSchema":{"type":"object","additionalProperties":false,"required":["parameters_pem"],"properties":{"parameters_pem":{"type":"string","maxLength":262144,"minLength":1}}},"mimeType":"application/json","accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","price":{"amount":"3000","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"asset":"USDC","network_name":"Base Mainnet","name":"USD Coin","version":"2","assetTransferMethod":"eip3009","eip712Domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}}},"maxTimeoutSeconds":300}]},{"url":"https://sicher.halowerk.com/v1/oss-openssl-tls12-cipher-policy-expand","method":"POST","name":"oss_openssl_tls12_cipher_policy_expand","description":"Takes a cipher policy in OpenSSL syntax and resolves it into the concrete list of TLS 1.2 cipher suites that the pinned build would actually offer, in the order it would offer them. This closes the gap between a policy string in a configuration file and what a server ends up negotiating: aliases expand, exclusions apply, and suites below the build's security level drop out silently in normal operation. Here they simply do not appear in the list, and the count says how many survived. The answer is specific to this pinned OpenSSL build and its security level, and it covers TLS 1.2 only. TLS 1.3 suites are negotiated separately and are not part of this expansion.","summary":"Compile an OpenSSL cipher policy string into the effective TLS 1.2 suite list, in preference order, under the pinned build's security level.","inputSchema":{"type":"object","additionalProperties":false,"required":["cipher_rule"],"properties":{"cipher_rule":{"type":"string","pattern":"^[A-Za-z0-9_:@!+.,=\\-]{1,256}$"}}},"mimeType":"application/json","accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","price":{"amount":"1000","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"asset":"USDC","network_name":"Base Mainnet","name":"USD Coin","version":"2","assetTransferMethod":"eip3009","eip712Domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}}},"maxTimeoutSeconds":300}]},{"url":"https://sicher.halowerk.com/v1/oss-openssl-x509-purpose-evaluate","method":"POST","name":"oss_openssl_x509_purpose_evaluate","description":"Reads the constraints inside a single certificate — basic constraints, key usage, extended key usage — and reports, per role, whether the certificate permits being used that way under the pinned OpenSSL build's rules. Roles covered are TLS client, TLS server, S/MIME signing and encryption, and timestamp signing. This answers the frequent confusion where a certificate is deployed for a purpose its own extensions forbid, and the failure only shows up as an opaque handshake error later. The evaluation looks at this certificate alone: it builds no chain, contacts no issuer, checks no revocation status, and does not decide whether the certificate is trusted or currently valid.","summary":"Evaluate which roles a certificate's own constraints permit — TLS client, TLS server, S/MIME and timestamp signing — under the pinned OpenSSL rules.","inputSchema":{"type":"object","additionalProperties":false,"required":["certificate_pem"],"properties":{"certificate_pem":{"type":"string","maxLength":262144,"minLength":1}}},"mimeType":"application/json","accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","price":{"amount":"1000","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"asset":"USDC","network_name":"Base Mainnet","name":"USD Coin","version":"2","assetTransferMethod":"eip3009","eip712Domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}}},"maxTimeoutSeconds":300}]},{"url":"https://sicher.halowerk.com/v1/oss-openssl-asn1-structure-diagnose","method":"POST","name":"oss_openssl_asn1_structure_diagnose","description":"Parses a definite-length binary artifact and returns every ASN.1 object it contains with its byte offset, nesting depth, header and content lengths, whether it is constructed, and the type as OpenSSL names it. This is the tool for the moment a certificate, key or signature is rejected with an unhelpful parse error and the question is which byte is wrong. Because offsets are exact, a diff against a known-good artifact localises the difference instead of describing it. Indefinite-length BER encodings are rejected rather than guessed at. Structural parsing is not schema validation: a clean map does not mean the artifact is a valid certificate, nor that it is canonically DER encoded.","summary":"Map the ASN.1 objects inside a binary artifact by offset, depth and encoded length, so a malformed structure can be located at the exact byte.","inputSchema":{"type":"object","additionalProperties":false,"required":["der_base64"],"properties":{"der_base64":{"type":"string","maxLength":262144,"minLength":1}}},"mimeType":"application/json","accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","price":{"amount":"1000","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"asset":"USDC","network_name":"Base Mainnet","name":"USD Coin","version":"2","assetTransferMethod":"eip3009","eip712Domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}}},"maxTimeoutSeconds":300}]},{"url":"https://sicher.halowerk.com/v1/oss-gnupg-detached-signature-verify","method":"POST","name":"oss_gnupg_detached_signature_verify","description":"Checks a detached OpenPGP signature against the bytes it claims to cover, using the pinned GnuPG build and nothing else. What comes back is the verdict in GnuPG's own terms, the fingerprint that actually signed, the signature timestamp, the algorithms used, and whether the key is expired or revoked. A wrong key, a tampered byte or a signature made by someone else each produce a distinct verdict rather than a bare false. No keyserver is contacted and no key is fetched: the only key considered is the one you supply, which is why the answer is reproducible. A valid signature proves the bytes match that key, not that the key belongs to whoever you think it does; that limit is stated in every response. The keyring exists only for the request and is removed when it ends.","summary":"Verify a detached OpenPGP signature over supplied bytes against a supplied public key, and get the verdict, signing fingerprint and signature time.","inputSchema":{"type":"object","additionalProperties":false,"required":["public_key_armored","signature_armored","signed_data_base64"],"properties":{"public_key_armored":{"type":"string","minLength":1,"maxLength":262144},"signature_armored":{"type":"string","minLength":1,"maxLength":262144},"signed_data_base64":{"type":"string","minLength":1,"maxLength":349528}}},"mimeType":"application/json","accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","price":{"amount":"2000","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"asset":"USDC","network_name":"Base Mainnet","name":"USD Coin","version":"2","assetTransferMethod":"eip3009","eip712Domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}}},"maxTimeoutSeconds":300}]},{"url":"https://sicher.halowerk.com/v1/oss-sqlite-database-integrity-audit","method":"POST","name":"oss_sqlite_database_integrity_audit","description":"Opens a supplied SQLite database read-only with the pinned engine and asks it the two questions it answers about itself: whether the file structure is intact, and whether any row points at a parent that is not there. What comes back is the engine's own integrity messages, each foreign-key violation with its table and rowid, the inventory of tables and indexes, and the page geometry and text encoding. The point is to tell a corrupt file apart from a merely inconvenient one before you build on it, and to find referential damage that no constraint was enforcing at write time. The file is never modified: it is opened read-only, no extension is loaded, and it is removed when the job ends. A clean result vouches for the file structure, not for whether the data is correct.","summary":"Audit a SQLite file with the pinned engine itself: structural integrity, broken foreign keys, schema inventory and page geometry, without writing to it.","inputSchema":{"type":"object","additionalProperties":false,"required":["database_base64"],"properties":{"database_base64":{"type":"string","minLength":1,"maxLength":11184812}}},"mimeType":"application/json","accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","price":{"amount":"2500","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"asset":"USDC","network_name":"Base Mainnet","name":"USD Coin","version":"2","assetTransferMethod":"eip3009","eip712Domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}}},"maxTimeoutSeconds":300}]},{"url":"https://sicher.halowerk.com/v1/oss-zip-archive-inventory-audit","method":"POST","name":"oss_zip_archive_inventory_audit","description":"Reads the central directory of a supplied ZIP archive with the pinned unzip build and reports what it would do if you unpacked it, without unpacking anything. Every entry is listed with its uncompressed size and method, and three specific hazards are named: paths that climb out of the target directory, names the archive repeats so that a later entry silently overwrites an earlier one, and a total uncompressed size far out of proportion to the archive. The point is to decide whether an archive is safe to open before opening it, which is the only moment the decision is still cheap. Nothing is extracted and no entry content is read, so the answer is about structure, not about what the files contain. Listing lines that could not be parsed are returned verbatim rather than dropped.","summary":"List a ZIP archive from its central directory and get the entries that would escape the target folder, duplicate names and the expansion ratio.","inputSchema":{"type":"object","additionalProperties":false,"required":["archive_base64"],"properties":{"archive_base64":{"type":"string","minLength":1,"maxLength":11184812}}},"mimeType":"application/json","accepts":[{"scheme":"exact","network":"eip155:8453","payTo":"0x2880EdfFF13100677Bf97A3CBdF3Bc34771C4E5E","price":{"amount":"2000","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","extra":{"asset":"USDC","network_name":"Base Mainnet","name":"USD Coin","version":"2","assetTransferMethod":"eip3009","eip712Domain":{"name":"USD Coin","version":"2","chainId":8453,"verifyingContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913"}}},"maxTimeoutSeconds":300}]}]}