{"uid":"cap_3VDR8TbJSUqTJM-92uTNV","slug":"secrets-audit-api-a51346e3","name":"Secrets Audit API","description":"Detect leaked secrets/credentials in code, configs, and text. x402 v2 micropayments on Base.","url":"https://eltociear-secrets-audit.hf.space/audit/url","method":"POST","headers":{},"bodySchema":{"type":"object","title":"AuditRequest","required":["content"],"properties":{"content":{"type":"string","title":"Content"}}},"responseSchema":{"type":"json","example":{"url":"https://example.com/config.env","findings":[],"risk_level":"SAFE","risk_score":0,"total_findings":0}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.03","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"settled","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.03/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_of1BFZzZuUSSBRJWgviYh","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.03","costPer":"request","priority":0,"asset":null,"unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Scans a URL for leaked secrets, credentials, and sensitive data in code, configs, or text files, returning findings and a risk assessment.","exampleAgentPrompt":"Can you scan https://raw.githubusercontent.com/myorg/myrepo/main/config.env for any leaked secrets or exposed credentials and tell me the risk level?","exampleUseCases":null,"resultDescription":"A JSON object containing the scanned URL, an array of findings (each describing a detected secret or credential), a risk_level string (e.g. SAFE, LOW, MEDIUM, HIGH), a numeric risk_score, and a total_findings count.","failureModes":["Inaccessible or non-existent URL returns an error or empty findings","Non-text or binary file content may not be parseable","Rate limiting or payment failure via x402 micropayment returns 402","False negatives on obfuscated or encoded secrets","Large files may time out or be truncated"],"whenToPreferThis":"Use this endpoint when you need to quickly check whether a publicly accessible URL (such as a raw GitHub file, a public config, or a deployment artifact) contains exposed secrets, API keys, or credentials. Ideal for automated security checks in CI/CD pipelines or pre-deployment audits.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T21:27:42.428Z","isFirstParty":false}