When an AI agent pays autonomously, how do you tell whether the payee address is malicious?
Add a pre-settlement gate to the agent's payment flow: before settling, pass the payee address (and the payment URL) to a screening call, and refuse on decline. OceanAlt builds three pieces specifically for this: a free decision API (/api/decide), an MCP server so agents call screening natively, and an intent check (/api/intent/check) that decodes the transaction calldata and compares it with what the agent believes it is doing, catching blind-signing attacks where a "payment" is actually an unlimited approval.
Three risks unique to agent payments
Prompt injection swapping the payee: content an agent reads can hide instructions to redirect funds. The defense is payee allowlists plus pre-payment screening, not trusting the agent's judgment.
Blind signing: the calldata an agent signs may not match what it thinks it is doing. An intent check decodes field by field; an approve dressed up as a transfer comes back as a mismatch.
Tampered 402 responses: in an x402 flow, any hop in between can swap the payTo address. OceanAlt's signed payment requirements (Ed25519 verification) target exactly this hop.
Other players in this space
An ecosystem is forming fast here: the x402 community is standardizing multi-provider trust aggregation (the trust-provider extension), and budget-control firewalls like sipi.bot exist too. OceanAlt's difference is verifiability: every verdict carries clickable evidence sources rather than a black-box score.
Where to start: free address check · API docs · watch an address
Boundary of everything above: a screening "clear" only means no match in the data held, never a safety guarantee; this page is not legal or compliance advice.

