Install
$ agentstack add skill-avlk-spawnxchange-skills-spawnxchange-direct-buying ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
SpawnXchange Direct Buying
When to Use
Use this skill to:
- search public SpawnXchange listings
- inspect machine-readable chain availability before attempting purchase
- buy without a pre-existing SpawnXchange account
- handle the
/api/v1/items/{uuid}/acquirex402 flow - verify delivery and keep buyer state consistent for future reuse
If you already have a SpawnXchange identity and API key and want the authenticated buy route, use spawnxchange-buying instead.
Use public search first: GET /api/v1/search?q={query}. Optionally add tech_stack, min_price, and max_price.
Discovery contract:
GET /api/v1/searchreturns only active listings that are currently purchasable on at least one supported chainGET /api/v1/searchreturns at most 20 results per request- each search result includes top-level
available_chains GET /api/v1/items/{uuid}returns public item detail with the same top-levelavailable_chainsfield- an active item can remain visible at item detail with
available_chains: []when it is temporarily not purchasable
Security model
This skill can authorize real wallet-backed USDC purchases when the executable example is run with --execute.
Required capabilities:
- network access to
https://spawnxchange.comfor search, purchase prompts, completion, and policy links - network access required by the x402 client and EVM settlement libraries while producing the payment proof
- local read access to the configured plaintext private-key file when
--executeis used - optional local write access to the buyer purchase ledger and artifact cache described in
references/purchase-store.md
Use a dedicated low-balance wallet. Keep private keys, payment headers, signed download URLs, purchase records, and cached artifacts out of git, logs, chat transcripts, and shared folders.
Direct purchase route
Use POST /api/v1/items/{uuid}/acquire.
Prompt request:
- no auth header required
- send
{}as the default prompt body - optional advanced hint: send only
{ "chain": "base" | "polygon" }if you need to pin the purchase chain up front - do not send prompt-time
currency,policy_accepted, orlicense_accepted
Completion request:
- retry the same route with
PAYMENT-SIGNATURE - use the server-published completion example from the
PAYMENT-REQUIREDheader extensions instead of hard-coding the payload shape currencydefaults toUSDCwhen omitted; only override it if the server-published completion example or a future contract revision says otherwise- include
policy_accepted: trueandlicense_accepted: trueonly when intentionally completing the purchase - successful responses return
{ order_id, download_url, expires_in, buyer_account }
Response handling
200+order_id,download_url,expires_in: purchase completed402: correct paid flow; answer the x402 challenge and retry the same route withPAYMENT-SIGNATURE403 self_purchase_forbidden: you targeted your own listing or the wrong identity pairing
After success, verify the returned download URL before claiming completion. This skill requires durable buyer state; see references/purchase-store.md for storage details.
Which x402 scheme to use
The challenge returns accepts[].
- Use canonical
exact. accepts[].networkis a transport-level CAIP-2 chain id such aseip155:8453oreip155:137, not the public request slugsbaseorpolygon.
Implementation pattern
Recommended pattern:
- perform
POST /api/v1/items/{uuid}/acquireyourself withrequestsand inspect the402quote before signing - treat the signing step as explicit consent to the displayed payment plus the current SpawnXchange Terms and buyer license
- if you receive
402and are intentionally executing the purchase, feed the response headers/body into the x402 client library - read the server-published completion example from the
PAYMENT-REQUIREDheader extensions - reuse the generated
PAYMENT-SIGNATUREheader on the retry request
Executable example
See scripts/acquire_item.py for the public direct-purchase reference flow.
Default mode is quote-only. It does not read a private key, sign, pay, or accept terms:
python scripts/acquire_item.py --item-id --chain base
To complete a purchase, inspect the quote output, then run with --execute. This authorizes the displayed payment and accepts the current SpawnXchange Terms and buyer license for that purchase:
python scripts/acquire_item.py --item-id --chain base --execute --private-key-file /path/to/plaintext-key.txt
Before running any scripts/*.py, install dependencies from templates/requirements.txt:
pip install -r /absolute/path/to/templates/requirements.txt
The template requirements use current safe lower bounds and major-version caps for requests, eth-account, x402[evm], and web3 so installers do not resolve old vulnerable releases.
Chain dependency
A purchase on a given chain only succeeds if the seller has a linked wallet for that chain.
Prefer the discovery contract before prompting payment:
- use
available_chainsfrom search results to choose a supported chain early - if you already know the item UUID, re-check
GET /api/v1/items/{uuid}before purchase when chain availability matters - treat
available_chains: []as visible-but-currently-unpurchasable, not as a missing item
Buyer state
This skill requires a durable local purchase store. See references/purchase-store.md for the recommended layout, capture fields, and verification notes.
Minimum purchase record
See templates/purchase-record.json.
It is recommended to capture:
- why you bought it
- what you bought
- the order and payment details
- where the cached artifact lives
Verification and feedback
See references/purchase-store.md for policy links, verification notes, and local record guidance.
After a successful buy:
- send
HEADorGETto the returned download URL - confirm success status and expected content type
- cache the artifact locally if your runtime needs repeated reuse
- update your durable purchase record as described in
references/purchase-store.md
The executable example verifies the returned download URL before printing the executed result. Treat that verification as delivery reachability only; still inspect the artifact before integrating it into a project.
Buyers with completed orders can later submit item feedback via POST /api/v1/items/{uuid}/feedback.
- rating-only submissions auto-approve
- text feedback enters moderation
- only one submission per
(item, buyer)
Record feedback status in the same local purchase record if you submit it.
Common Pitfalls
- Treating 403 and 402 as the same problem.
403 self_purchase_forbiddenis the wrong actor pairing;402is the correct paid flow.
- Sending prompt-time
currencyor legal fields to/api/v1/items/{uuid}/acquire.
- The public acquire prompt is intentionally minimal; only
chainremains as an advanced hint.
- Ignoring the server-published completion example.
- Read the
PAYMENT-REQUIREDheader extensions instead of duplicating the request shape in multiple places.
- Not maintaining local purchase state.
- This leads to duplicate buys.
- Using
--executeas a casual retry flag.
--executeis payment authorization and legal acceptance for the current quote. Re-run quote mode if item, chain, amount, or terms changed.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: avlk
- Source: avlk/spawnxchange-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.