public x402 v2 regression cases in the release artifact gate
First-party evidence
Reproduce the scanner, not the story.
These maintainer-produced fixtures show the exact x402 v2 static-analysis behavior claimed by Monarch Shield 0.2.0. They are not an independent audit, runtime payment tests, or evidence of external adoption.
documented package import paths represented in parser fixtures
external adoption claims
What the fixtures establish
- supported automatic x402 calls without a recognized policy seam fail;
- wrong-client hooks, observer-only MCP hooks, lookalike guards, and incomplete analysis do not pass;
- locally packed 0.2.0 artifacts run the same ten regression cases;
- the runtime helper does not invoke a payment callback until the caller explicitly runs the returned closure.
What remains outside the evidence
The scanner recognizes specific syntactic abort or denial returns and rejects obvious constant-dead branches. The fixtures do not establish general reachability, complete x402 coverage, policy quality, cross-file proof, runtime authorization, settlement, delivery, legal compliance, the unpublished GitHub Action tag, npm registry artifacts, or the live website revision.