{"uid":"cap_9IaLj_8N0u0OxEgfdnyrs","slug":"ci-cd-job-security-inspector-single-step-60bdfe86","name":"CI/CD Job Security Inspector (Single Step)","description":"Static security scan of a SINGLE CI/CD job or step snippet (GitHub Actions, GitLab CI or CircleCI). The lightweight per-object form of /ci/scan: returns a verdict (pass, caution, block), a risk score and findings with rule, severity, location and fix hint. Security indicators, not a guarantee.","url":"https://api.agentstools.dev/ci/inspect","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"kind":{"enum":["auto","github-actions","gitlab-ci","circleci"],"type":"string","description":"CI system of the snippet, or auto to detect"},"resource":{"type":"string","description":"A single CI job or step snippet to inspect"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.008","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.008/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.008","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.008","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_oUyYc3JjZUBwCGyfY9nfr","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.008","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Statically scans a single CI/CD job or step snippet (GitHub Actions, GitLab CI, or CircleCI) and returns a security verdict, risk score, and detailed findings with fix hints.","exampleAgentPrompt":"Can you inspect this GitHub Actions job step for security issues and tell me if it's safe to run, the risk score, and any specific fix recommendations?","exampleUseCases":[{"title":"Pre-merge pipeline security gate","prompt":"Before I merge this PR, scan this GitHub Actions deploy job snippet and tell me if it passes, needs caution, or should be blocked — include any findings and how to fix them."},{"title":"Detect secrets in GitLab CI step","prompt":"I want to check this GitLab CI job snippet for accidental secret exposure or hardcoded credentials — give me a verdict and a risk score so I know whether to block it."},{"title":"CircleCI step audit before release","prompt":"Audit this CircleCI run step for dangerous shell commands or security risks and tell me the severity and location of any issues you find, plus hints on how to fix them."}],"resultDescription":"Returns a verdict (pass, caution, or block), a numeric risk score, and a list of findings each containing the triggered rule, severity level, location within the snippet, and a fix hint. These are security indicators, not guarantees.","failureModes":["Malformed or unparseable CI/CD snippet returns a parse error","Unsupported CI platform syntax may yield incomplete findings","Very short or empty snippets may return no findings without indicating safety","Network or service errors return a non-200 status with error detail"],"whenToPreferThis":"Choose this endpoint when you need a fast, per-step security verdict on a single CI/CD job or step snippet rather than scanning an entire pipeline file. It is ideal for pre-merge checks, inline agent workflows, or iterative step-by-step pipeline auditing where you want lightweight, actionable feedback without processing a full config file.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T18:48:56.048Z","isFirstParty":false}