{"uid":"cap_A6pKh_U07pOPS4Dl511IX","slug":"code-bundle-security-review-get-2b1662bb","name":"code-bundle-security-review-get","description":"Revisión de seguridad de un paquete de ficheros (Python, web, JSON) sin ejecutar nada: importaciones y llamadas prohibidas, escritura, red y credenciales. Un tipo de fichero que el gate no sabe leer se declara como no verificable, no como aprobado.","url":"https://agente.revenuerecoveryai.app/v1/code/review?utm_source=zero.xyz","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"type":"object","required":["nombre","texto"],"properties":{"texto":{"type":"string"},"nombre":{"type":"string"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.05","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.05/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm__P-3BwttwxIrl7PPJDKg6","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.05","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Statically reviews a bundle of code files (Python, web, JSON) for forbidden imports, dangerous calls, unauthorized writes, network access, and hardcoded credentials without executing any code.","exampleAgentPrompt":"Can you do a static security review of this Python file called 'data_pipeline.py'? I need to know if it has any forbidden imports, dangerous calls, hardcoded credentials, or unauthorized network or filesystem writes — without actually running the code.","exampleUseCases":[{"title":"Pre-deployment Python agent safety check","prompt":"Before I deploy this Python agent script called 'agent_runner.py', can you scan it for forbidden imports, dangerous system calls, and any hardcoded API keys or passwords? Don't run it, just analyze it statically."},{"title":"Third-party code bundle vetting","prompt":"I received a code bundle called 'vendor_integration.py' from a third party. Can you review it for any unauthorized network calls, credential leaks, or prohibited function imports without executing anything?"},{"title":"Web asset security audit","prompt":"Can you check this web file bundle named 'frontend_bundle.js' for any security issues like forbidden calls, credential exposure, or unauthorized write operations — I need a static review, no execution."}],"resultDescription":"A structured JSON report listing security findings per file: forbidden imports detected, prohibited function calls, unauthorized filesystem writes, network access violations, hardcoded credentials found, and a verifiability status for each file type (unverifiable file types are flagged as non-verifiable rather than approved).","failureModes":["Unknown or unsupported file types are declared unverifiable rather than safe — agents must not treat absence of findings as blanket approval","Missing required query parameters 'nombre' or 'texto' returns a 400-level error","Very large code bundles may hit payload size limits","Non-code binary content submitted as text may produce meaningless output","Obfuscated code may evade static pattern detection"],"whenToPreferThis":"Choose this endpoint when you need a fast, safe, no-execution static security gate for Python, web (HTML/JS/CSS), or JSON files — particularly before allowing untrusted or third-party code into an agent pipeline. Prefer it over full sandboxed execution when you want zero side-effects and rapid screening for the most common abuse vectors (credential leaks, forbidden imports, network calls, filesystem writes).","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T02:46:53.565Z","isFirstParty":false,"canonicalSlug":"code-bundle-security-review-get-2b1662bb"}