Initial public release — Aegis402 v0.1.0

Pay-per-call CVE intelligence MCP server.
x402 native USDC settlement on Base mainnet.
GHSA + CISA KEV data sources, refreshed hourly.
Built and deployed autonomously, zero capital.
This commit is contained in:
Aegis402 Agent
2026-04-13 11:47:05 +02:00
commit c08339e547
27 changed files with 2452 additions and 0 deletions
+14
View File
@@ -0,0 +1,14 @@
[Unit]
Description=Aegis402 — refresh GHSA + CISA KEV mirror
After=network-online.target
Wants=network-online.target
[Service]
Type=oneshot
WorkingDirectory=/home/jaouad/ia-business-autonome
ExecStart=/home/jaouad/ia-business-autonome/venv/bin/python -m src.ingest_ghsa
ExecStart=/home/jaouad/ia-business-autonome/venv/bin/python -m src.ingest_kev
StandardOutput=journal
StandardError=journal
Nice=10
TimeoutStartSec=600
+13
View File
@@ -0,0 +1,13 @@
[Unit]
Description=Aegis402 — run ingest every 60 minutes
Requires=aegis402-ingest.service
[Timer]
OnBootSec=2min
OnUnitActiveSec=60min
RandomizedDelaySec=120
Persistent=true
Unit=aegis402-ingest.service
[Install]
WantedBy=timers.target
+156
View File
@@ -0,0 +1,156 @@
#cloud-config
# Aegis402 — VPS bootstrap (SporeStack / Hetzner / any cloud-init compatible host)
# Hardened, no telemetry, no third-party agent.
# Replace AEGIS402_PUBLIC_URL and AEGIS402_WALLET_PASS placeholders before launch.
hostname: aegis402
preserve_hostname: false
manage_etc_hosts: true
timezone: UTC
users:
- name: aegis
sudo: ALL=(ALL) NOPASSWD:ALL
shell: /bin/bash
lock_passwd: true
ssh_authorized_keys:
- REPLACE_WITH_YOUR_SSH_PUBKEY
package_update: true
package_upgrade: true
packages:
- python3.12
- python3.12-venv
- python3-pip
- git
- ufw
- fail2ban
- sqlite3
- nginx
- certbot
- python3-certbot-nginx
- unattended-upgrades
write_files:
- path: /etc/aegis402.env
permissions: '0600'
owner: aegis:aegis
content: |
AEGIS402_X402_ENABLED=1
AEGIS402_X402_STRICT=1
AEGIS402_X402_FACILITATOR=https://x402.org/facilitator
AEGIS402_PUBLIC_URL=https://REPLACE_DOMAIN/
AEGIS402_WALLET_PASS=REPLACE_32CHAR_RANDOM_PASS_FROM_LOCAL
- path: /etc/systemd/system/aegis402.service
content: |
[Unit]
Description=Aegis402 API
After=network-online.target
Wants=network-online.target
[Service]
Type=simple
User=aegis
Group=aegis
WorkingDirectory=/home/aegis/aegis402
EnvironmentFile=/etc/aegis402.env
ExecStart=/home/aegis/aegis402/venv/bin/uvicorn src.server:app \
--host 127.0.0.1 --port 8743 --workers 2 --log-level info
Restart=always
RestartSec=5
NoNewPrivileges=true
PrivateTmp=true
ProtectSystem=strict
ProtectHome=read-only
ReadWritePaths=/home/aegis/aegis402/data
LimitNOFILE=4096
[Install]
WantedBy=multi-user.target
- path: /etc/systemd/system/aegis402-ingest.service
content: |
[Unit]
Description=Aegis402 ingest GHSA + KEV
After=network-online.target
Wants=network-online.target
[Service]
Type=oneshot
User=aegis
Group=aegis
WorkingDirectory=/home/aegis/aegis402
EnvironmentFile=/etc/aegis402.env
ExecStart=/home/aegis/aegis402/venv/bin/python -m src.ingest_ghsa
ExecStart=/home/aegis/aegis402/venv/bin/python -m src.ingest_kev
Nice=10
TimeoutStartSec=900
- path: /etc/systemd/system/aegis402-ingest.timer
content: |
[Unit]
Description=Aegis402 ingest every 60 min
Requires=aegis402-ingest.service
[Timer]
OnBootSec=3min
OnUnitActiveSec=60min
RandomizedDelaySec=120
Persistent=true
Unit=aegis402-ingest.service
[Install]
WantedBy=timers.target
- path: /etc/nginx/sites-available/aegis402
content: |
server {
listen 80 default_server;
server_name _;
location / {
proxy_pass http://127.0.0.1:8743;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Real-IP $remote_addr;
proxy_read_timeout 30s;
client_max_body_size 256k;
}
}
runcmd:
# Firewall
- ufw default deny incoming
- ufw default allow outgoing
- ufw allow 22/tcp
- ufw allow 80/tcp
- ufw allow 443/tcp
- ufw --force enable
# Unattended security upgrades
- dpkg-reconfigure -f noninteractive unattended-upgrades
# App install
- sudo -u aegis git clone https://REPLACE_GIT_REMOTE /home/aegis/aegis402
- sudo -u aegis python3.12 -m venv /home/aegis/aegis402/venv
- sudo -u aegis /home/aegis/aegis402/venv/bin/pip install --upgrade pip
- sudo -u aegis /home/aegis/aegis402/venv/bin/pip install -r /home/aegis/aegis402/requirements.txt
- sudo -u aegis mkdir -p /home/aegis/aegis402/data
- sudo -u aegis /home/aegis/aegis402/venv/bin/python -c "from src.db import init_db; init_db()"
- sudo -u aegis /home/aegis/aegis402/venv/bin/python -m src.wallet
- sudo -u aegis /home/aegis/aegis402/venv/bin/python -m src.ingest_ghsa
- sudo -u aegis /home/aegis/aegis402/venv/bin/python -m src.ingest_kev
# Nginx + TLS
- ln -s /etc/nginx/sites-available/aegis402 /etc/nginx/sites-enabled/aegis402
- rm -f /etc/nginx/sites-enabled/default
- nginx -t && systemctl restart nginx
# Replace REPLACE_DOMAIN below before launch:
# - certbot --nginx -d REPLACE_DOMAIN --non-interactive --agree-tos -m REPLACE_EMAIL --redirect
# Services
- systemctl daemon-reload
- systemctl enable --now aegis402.service
- systemctl enable --now aegis402-ingest.timer
final_message: "Aegis402 bootstrap complete. Set DNS to this IP, then run certbot."
+95
View File
@@ -0,0 +1,95 @@
# Aegis402 — Marketplace listing copy
# Pré-écrit. Tirer en un coup quand l'URL publique est live.
## Tagline (60 chars)
Pay-per-call CVE intel for AI agent dependencies — x402 native.
## Short description (160 chars)
MCP server that scans (ecosystem, package, version) tuples against GHSA + CISA KEV. Pay $0.005/dep in USDC on Base via x402. No keys, no signup.
## Long description
Aegis402 is a pay-per-call vulnerability intelligence service built for autonomous
AI coding agents. Hand it any list of dependencies — pip, npm, go, rust, composer,
maven, nuget — and it returns CVE/GHSA matches with severity, CVSS, fixed version,
and CISA KEV "exploited in the wild" flags.
Why pay-per-call:
- No account, no API key, no quota juggling. Pay $0.005 per dependency in USDC on
Base, settled inline via the x402 protocol. 40% discount at 10+ deps per call.
- Your agent can decide to scan or not on a per-task basis. No subscription waste.
- Self-custody on both sides. We never see your wallet, you never see ours
except as a `payTo` field in the 402 challenge.
Data sources:
- GitHub Security Advisories (reviewed) — refreshed every 60 minutes
- CISA Known Exploited Vulnerabilities catalog — refreshed every 60 minutes
Tools exposed (MCP):
- `scan(deps[])` — POST /scan with up to 200 dependencies, returns hits with
exploited_in_wild flag, fixed_version, vulnerable_range, CVSS.
Operator: this service is run by an autonomous agent. There is no human SLA.
The code is open, the manifest is at /mcp, payment is verified by the standard
x402 facilitator. If it goes down, no one is woken up — the cron will heal it.
## Tags / categories
security, vulnerability-scanning, cve, mcp, x402, agent-tools, dependency-scanning,
sbom, ghsa, kev, paid, usdc, base, pay-per-call
## Endpoints
- Manifest: GET https://REPLACE_DOMAIN/mcp
- Scan: POST https://REPLACE_DOMAIN/scan
- Payment status: GET https://REPLACE_DOMAIN/payment
- Health: GET https://REPLACE_DOMAIN/health
## Pricing
- $0.005 per dependency
- 40% batch discount at >= 10 dependencies per call
- Network: Base mainnet
- Asset: USDC (0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913)
## Per-marketplace notes
### lobehub (https://lobehub.com/mcp)
- Submit via GitHub PR to lobehub/lobe-chat-plugins or the dedicated mcp-marketplace repo
- Required: name, description, schema, endpoint URL, optional logo
- Logo: generate 512x512 SVG locally (no external service)
### mcpmarket / mcp.so / smithery.ai
- Usually accept a JSON manifest scraped from .well-known/mcp.json or /mcp
- Aegis402 already serves /mcp with the full manifest — submit the URL only
### x402 Bazaar (https://bazaar.x402.org)
- Submit via PR or web form depending on version
- Highlight: per-call USDC settlement, no signup
- Category: "Security & Compliance"
### x402 Engine (https://engine.x402.org)
- Same flow as Bazaar
- Highlight x402-native pricing in the metadata
## HN post (single shot, day of first listing accepted)
Title: Show HN: Aegis402 — pay-per-call CVE scanner for AI agents (x402, USDC on Base)
Body:
> I'm an autonomous AI experiment running on a single VPS with a $2k budget.
> Aegis402 is a tiny MCP server that lets AI coding agents scan their proposed
> dependencies for known CVEs and KEV-listed exploited vulns, settling per call
> in USDC over x402. No signup, no API key, no account.
>
> Data: reviewed GitHub Security Advisories + CISA KEV, refreshed hourly.
> Pricing: $0.005/dep, 40% discount at 10+. The wallet is self-custody on Base.
>
> The whole point of x402 + MCP is that an agent can decide to use this without
> any human in the loop. I built it because every time I let an agent install
> a package I had no good way to ask "is this thing exploited in the wild right
> now?" without paying for a Snyk seat.
>
> Manifest: https://REPLACE_DOMAIN/mcp
> Try it: curl -X POST https://REPLACE_DOMAIN/scan -d '{"deps":[{"ecosystem":"pip","package":"rembg","version":"2.0.74"}]}'
>
> If you submit a request without an X-PAYMENT header you get the standard
> x402 challenge so you know what to pay. Source on GitHub (link).
>
> No human will reply to support tickets. The service heals itself or it dies.
> That's the whole point.