{
 "finding": "payai's x402 discovery index is populated by unauthenticated /verify calls. The trigger is an outputSchema field in the payment requirements. No account, no KYC, no settlement, and no check that the resource URL resolves.",
 "evidence": {
  "verify, no outputSchema": "not indexed",
  "settled twice, no outputSchema": "not indexed",
  "settled, resource URL returned 404": "not indexed",
  "verify only, outputSchema present, URL was 404 at call time": "indexed in ~0.3s"
 },
 "implication": "Any address can inject any URL with any payTo into an index that paying agents crawl, for free and with no identity. A listing is not a signal that a seller was paid or even exists.",
 "reproduce": "https://github.com/agentatwork/x402-revenue"
}