X
Xaish
Multilateral · AI Security + Payments

Built for theagent economy.

125 typed-endpoint tools your AI agents call directly.

50
Cyber
23
Crypto
52
Pay · free
Featured tools

A few from the catalog.

Browse all 125 →
Subscriber tool
Unlock all 74 for $10k/mo
Xaish Forge#22
Subscriber
Threat Modeling Assistant

Paste an architecture / system description (services, data stores, trust boundaries, auth flows, third-party deps, deployment topology) + optional methodology (stride / linddun / pasta / kill_chain) + system_context (sector, headcount, regulatory scope) + scope_focus.

Subscribe to use →
Subscriber tool
Unlock all 74 for $10k/mo
Xaish ChainGuard#53
Subscriber
DeFi Fraud Detection Engine

Paste a DeFi protocol description (token contract + tokenomics + LP / pool stats + recent tx batch + optionally roadmap / team / audit claims) + optionally protocol_class (token / amm_pool / lending / yield_aggregator / launchpad / nft_drop / bridge / cross_chain / staking) + chain_context.

Subscribe to use →
Xaish Nexus#51
Free
Paynnt — AI Payment Gateway

Paste a transaction (or batch) — AI produces a unified payment-intelligence report: fraud signals (velocity / geo / ATO), FX optimization, AML/OFAC heuristics, and a concrete rail recommendation.

Open →
Xaish Nexus#75
Free
Invoice Intelligence

Paste an invoice (PDF text / email body / OCR output) + optional payer_context (historical vendor invoices, contract terms, AP ledger excerpt).

Open →
Xaish Nexus#92
Free
Card Fraud / Chargeback Triage

Paste a chargeback / dispute (reason code + amount + processor + customer claim) + merchant evidence + optional program_context.

Open →
Xaish Nexus#105
Free
Agent Payment Guardrail Proposer

Paste an agent profile + proposed payment + existing_controls + program_context.

Open →
Xaish Nexus#110
Free
Stable-vs-Fiat Rate Drift Monitor

Paste a stablecoin/fiat market snapshot (ticker + spot across N venues + depth + recent volume + oracle price + timestamps) + recent_history + program_context.

Open →
Xaish Nexus#115
Free
Agent Refund Authorizer

Paste an agent profile + proposed refund (order + amount + reason + customer claim) + refund policy.

Open →
Xaish Nexus#124
Free
Paynnt MCP Capability Descriptor Generator

Paste the platform's capabilities (endpoints + scopes + auth + rate limits + payload shapes) + the target agent integration + program_context.

Open →
Xaish Nexus#125
Free
Webhook Delivery Health Diagnoser

Paste a webhook delivery log sample (per-attempt: ts + endpoint + status + latency + retry attempt + signature result) + endpoint_config + program_context (SLA + downstream impact).

Open →
OSS provenance

Real scanners, not just AI.

Every security tool runs an industry-standard OSS scanner first — Trail of Bits, Aqua Security, Microsoft, VirusTotal — then Claude triages the raw output into graded findings with concrete fixes. You see both: the deterministic scanner block and the AI reasoning that sits on top of it. The runtime inventory is observable at /api/diagnostics/scanners.

10
OSS scanners
16
tools backed
Slither
Trail of Bits
Solidity static analyzer (80+ detector classes)
Backs · 7 ChainGuard tools
Solhint
Protofire
Solidity linter / style + best-practice rules
Backs · same seven tools
circomspect
Trail of Bits
Circom ZK circuit static analyzer
Backs · ZK Circuit Reviewer
Trivy
Aqua Security
CVE DB · IaC misconfig · SBOM scan
Backs · Vuln + Firmware + Cloud
Semgrep
r2c
Multi-language source-code static analyzer
Backs · Code Scanner
Bandit
PyCQA
Python-specific security linter
Backs · Code Scanner (Python)
Nmap
Nmap.org
Network scan parsing (libnmap)
Backs · Nmap Analyzer
YARA
VirusTotal
Malware / IOC rule engine
Backs · YARA Scanner
detect-secrets
Yelp
Secret / credential entropy + regex scanner
Backs · Secrets Scanner
Presidio
Microsoft
PII / PHI recognizer (regex + spaCy NER)
Backs · DLP & DSPM AI

Procurement note: every scan returns a scanner_summaries block in the API response, surfaced in the result UI as vendor-attributed chips. The runtime probe at /api/diagnostics/scanners reports per-binary availability — useful for catching degraded deployments and for security-questionnaire evidence.

Free preview · no signup

See the two-stage flow.

A deliberately-vulnerable requirements.txt is preloaded. Click Scan and you'll see Trivy + OSV.dev CVE hits land first as vendor-attributed chips, then Claude triages them into a prioritized upgrade plan with breaking-change notes. Free for anonymous visitors — 3 calls per IP per 24h.

OSS pre-pass · 1/1 rantrivy:fs · 12
Overall riskCRITICAL
CRITICAL · CVE-2022-28347
Django 2.2.0 · SQL injection via QuerySet.explain()
HIGH · CVE-2023-32681
requests 2.20.0 · Proxy-Auth header leakage on redirect
MEDIUM · CVE-2021-33503
urllib3 1.24.1 · ReDoS in URL parsing — upgrade to 1.26.5
* stylized preview · live tool renders the same shape
P

Paynnt

Free for everyoneSolana · USDCOpen 24/7

Access all your payment services in one AI-powered global payment infrastructure platform.

One wallet, one API, one bill. Solana and USDC today; cards and ACH next. 51 AI payment tools included. You pay $0.30 per transaction and $0.50 per other service. No subscription.

Have a look around.

Five tools are open to anyone — no account, no card. Subscribing unlocks the other 69 security tools.