{"products":[{"id":"x402-registry-2026-10-04","name":"x402 Services & Facilitator Registry — 2026-10-04 edition","description":"The x402 market, measured, refreshed for October: every resource in Coinbase's x402 Bazaar discovery index (27,681 paid endpoints, up 87% in five weeks) with the index's own 30-day counters (settled calls, unique payers, last call), one read-only probe per URL (live 402 or not, version, live price), an EIP-712 signing-domain check on every USDC-on-Base option, per-resource revenue proxy, payTo addresses, networks, schemes and prices — plus a month-over-month changes file (new and vanished domains, biggest gainers and losers), 21 facilitators with live /supported results and the curated 118-service table. JSONL + JSON + schema + README. Market sizing, competitor research, facilitator choice, pricing and listing validation from one file.","priceUsd":15,"currency":"USD","format":"zip","file":"x402-registry/x402-registry-2026-10-04.zip","sizeBytes":3020515,"sha256":"80656952637f4b32641eb507d238bef119be2d1781743ebe39a299c2a0ae1ffc","humanUrl":"https://growthchief5.gumroad.com/l/x402-registry"},{"id":"prompt-injection-test-corpus","name":"Prompt-Injection & Tool-Hijack Test Corpus","description":"156 structured, labeled adversarial test cases across seven categories (direct injection, indirect injection, tool hijacking, data exfiltration, system-prompt leaks, jailbreak/roleplay, encoding obfuscation) for evaluating whether an agent or LLM app resists prompt injection and tool-misuse attacks. Ships with a JSON Schema, a dependency-light Python evaluation harness, and a guide covering taxonomy, scoring, limitations, and responsible use.","priceUsd":29,"currency":"USD","format":"zip","file":"injection-corpus/injection-corpus-2026-08-21.zip","sizeBytes":65018,"sha256":"f5eedc690c333c14810a5e36265fff453636044e784a5b3b18ac02c0bfb49c40","humanUrl":"https://growthchief5.gumroad.com/l/injection-corpus"},{"id":"mcp-registry-2026-08-22","name":"MCP Server Registry Snapshot — 2026-08-22 edition","description":"A curated, machine-readable snapshot of 400 production/community Model Context Protocol (MCP) servers as of 2026-08-22: category, transport, auth requirements, repo/package URLs, source-directory cross-references, and verification dates for every entry. Saves an agent or builder shopping for MCP tooling the work of crawling and reconciling multiple MCP directories (official registry, Smithery, Glama, PulseMCP, mcp.so) itself.","priceUsd":19,"currency":"USD","format":"zip","file":"mcp-registry/mcp-registry-2026-08-22.zip","sizeBytes":64805,"sha256":"f6dd3e514d2cc827b139f88c81917f29a218b5ced1ffb0ff89ec476650d05f74","humanUrl":"https://growthchief5.gumroad.com/l/mcp-registry"},{"id":"agent-eval-harness-templates","name":"Agent Eval Harness Templates","description":"A ready-to-use starter kit for evaluating an agent or LLM application fast: a JSON-Schema test-case format, 40 example cases across four suites (task completion, tool selection, refusal/safety, regression), a pointwise LLM-as-judge scorer with documented bias mitigations, and a dependency-light Python CLI runner that produces a scored JSON report plus a human-readable summary. Grounded in current agent-eval practice; bring-your-own-model via a one-file adapter interface.","priceUsd":39,"currency":"USD","format":"zip","file":"eval-harness/eval-harness-2026-08-22.zip","sizeBytes":39839,"sha256":"2a2dbc4b8bf45189b12b658c45dae7a476662bd73c5a2d32f57c12342954f5b8","humanUrl":"https://growthchief5.gumroad.com/l/eval-harness"},{"id":"prompt-injection-defenses-playbook","name":"Prompt-Injection Defenses Playbook & Detection Ruleset","description":"The defense counterpart to our attack corpus: a layered playbook for hardening an agent/LLM app against prompt injection, tool hijacking, data exfiltration, system-prompt leaks, jailbreaks, and encoding obfuscation. Includes a 6-layer defense taxonomy mapped to attack categories, 119 machine-readable detection rules (85 base + 34 extended, each with honest false-positive notes), and a stdlib-only Python detector with two profiles (strict for tool arguments and output, content for web pages and documents), decode-and-rescan for obfuscated instructions, and hidden-HTML-text scanning. Measured: held-out recall 53% strict / 38% content on the 156-case corpus; 0.35% false positives on 1,714 unseen top-site homepages (the base rules as written flag 69%). Full method and limits in MEASUREMENTS.md. Grounded in OWASP LLM/MCP guidance.","priceUsd":39,"currency":"USD","format":"zip","file":"injection-defenses/injection-defenses-2026-10-04.zip","sizeBytes":56277,"sha256":"ec9c4b6a2c7b43ee12a71646667caa9306515c4efde4a26b21c70943407ffd43","humanUrl":"https://growthchief5.gumroad.com/l/injection-defenses"},{"id":"x402-quickstart-2026-08-23","name":"x402 Quickstart Kit — 2026-08-23 edition","description":"A dependency-minimal reference implementation of the x402 HTTP micropayment protocol (\"exact\" scheme, EIP-3009, EVM/USDC): seller-side payment middleware for Cloudflare Workers/Hono and plain Node/Express, generalized from a live production x402 seller, plus buyer-side client code in TypeScript (viem) and Python (eth_account/web3.py) that signs a real EIP-3009 payment authorization and retries a 402 automatically. Includes a practical guide covering facilitator selection, common integration pitfalls, and a go-live checklist.","priceUsd":7,"currency":"USD","format":"zip","file":"x402-quickstart/x402-quickstart-2026-08-23.zip","sizeBytes":38997,"sha256":"3e4b172efdcc1e865e9749dfde8e8157c2cc927376b3691f002125f57a267a4f","humanUrl":"https://growthchief5.gumroad.com/l/x402-quickstart"},{"id":"mcp-tool-inventory-2026-08-28","name":"MCP Live Tool Inventory — 2026-08-28 edition","description":"Every remote server in the official MCP registry (15,329 URLs) probed read-only via initialize → tools/list, and everything the 8,235 live ones returned: 140,284 tool names, titles, full descriptions, input-schema keys and annotations; 5,462 server-level instructions strings verbatim; per-server reachability, protocol version and outcome; and 24k+ tool-poisoning audit flags with snippets. JSONL + summary.json + schema. The real-world base rate for allow-listing servers, name-collision checks, and building or testing tool-description detectors against live text instead of synthetic samples.","priceUsd":29,"currency":"USD","format":"zip","file":"mcp-tool-inventory/mcp-tool-inventory-2026-08-28.zip","sizeBytes":18844800,"sha256":"8af95b3b52932c296a772e2b3acdf54cdf4b29aaea7aeb31e2a5f9c82f6584c5","humanUrl":"https://growthchief5.gumroad.com/l/mcp-tool-inventory"},{"id":"agent-web-report-2026-q3","name":"The Agent Web, Measured — 2026 Q3 edition","description":"A 25-page analyst report on the machine-facing web, built entirely from first-hand measurement: all 15,329 remote MCP registry URLs probed (54% answer, 45.5% outside two template fleets; 140,284 tool descriptions scored — the textbook tool-poisoning payload appears zero times, 47 hosts carry concealment directives, all 51 quoted verbatim), all 14,820 x402 Bazaar endpoints probed and the index's own counters summed into the first published revenue ceiling for the CDP-facilitated x402 market (~$314/day), all 21 facilitators probed, and a 60-crawler census from a live storefront. 22 charts, 10 tables, twelve conclusions, every number generated from the underlying datasets. PDF + README + licence. Single-organisation licence; includes the +30/+60/+90-day re-probe summaries and the 2026 Q4 edition.","priceUsd":149,"currency":"USD","format":"zip","file":"agent-web-report/the-agent-web-measured-2026-q3.zip","sizeBytes":625034,"sha256":"32897ec170e7c5c003e214b6540c0bc91cfa365acd3953b0755eb53ca43730ef","humanUrl":"https://growthchief5.gumroad.com/l/agent-web-report"}]}