{"uid":"cap_M9_XoL4RL95bn_4vupQ52","slug":"x402-cloud-github-repository-audit-b2504cb9","name":"X402 Cloud GitHub Repository Audit","description":"X402 Cloud AI Inference Endpoints is an agent-ready x402 API provider for Gemini, image, audio, video, realtime, and specialized AI inference workflows. We expose pay-per-call USDC endpoints designed for autonomous AI agents, application backends, trading bots, creative automation, and RAG systems with some of the lowest x402 AI inference prices available in the market.","url":"https://api.x402cloud.space/v1/github/repo-audit?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":null,"responseSchema":{"type":"json","example":{"stack":["Python","FastAPI"],"summary":"The repo is functional but lacks deployment hardening.","findings":[{"title":"No rate limiting documented","severity":"medium","recommendation":"Add request limits for public endpoints."}],"risk_level":"medium"},"outputSchema":{"type":"object","$defs":{"RepoAuditFinding":{"type":"object","title":"RepoAuditFinding","required":["severity","title","recommendation"],"properties":{"title":{"type":"string","title":"Title"},"severity":{"type":"string","title":"Severity"},"recommendation":{"type":"string","title":"Recommendation"}}}},"title":"GitHubRepoAuditOutput","required":["summary"],"properties":{"stack":{"type":"array","items":{"type":"string"},"title":"Stack"},"summary":{"type":"string","title":"Summary"},"findings":{"type":"array","items":{"$ref":"#/$defs/RepoAuditFinding"},"title":"Findings"},"risk_level":{"type":"string","title":"Risk Level","default":"unknown"}}}},"example":{"request":{"focus":"security","repo_url":"https://github.com/torvalds/linux","max_files":50},"response":{"stack":["Linux Kernel","Rust","Python","Sphinx","Docutils","Android Binder"],"summary":"The analyzed subset of the Linux kernel repository contains Sphinx documentation extensions and the Rust-based Android Binder driver. The primary security risks are located in the custom Sphinx build scripts. The `kernel-include` directive explicitly bypasses standard docutils security boundaries to allow arbitrary file inclusion, which could lead to local file disclosure in untrusted build environments. Additionally, `kfigure.py` executes external subprocesses using the system `PATH` variable, which poses a risk of command execution if the environment is manipulated. The Rust binder driver files utilize `unsafe` blocks for direct memory access but implement robust bounds and overflow checks to mitigate memory safety risks.","findings":[{"title":"Arbitrary File Inclusion in `kernel-include` Sphinx Directive","severity":"medium","recommendation":"Restrict the `kernel-include` directive to only allow paths within the repository root or a predefined safe directory list, especially when documentation builds are executed in shared or untrusted CI/CD environments."},{"title":"Insecure Subprocess Execution and PATH Dependency in `kfigure.py`","severity":"medium","recommendation":"Avoid relying on the untrusted system `PATH` environment variable to locate executable binaries. Use absolute paths for tools like `dot`, `convert`, and `inkscape`, and ensure all arguments passed to subprocesses are strictly validated."},{"title":"Unvalidated Environment Variable `srctree` in Sphinx Extensions","severity":"low","recommendation":"Validate that the `srctree` environment variable points to a legitimate directory within the expected workspace before appending it to `sys.path` or using it to resolve file paths."}],"risk_level":"medium"}},"exampleRequest":{"focus":"security","repo_url":"https://github.com/torvalds/linux","max_files":50},"tags":["x402"],"displayCostAmount":"0.015","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"settled","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.015/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.015","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.015","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_ODAJeztHcEJ-5FiEj2Vgz","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.015","costPer":"request","priority":0,"asset":"4zMMC9srt5Ri5X14GAgXhaHii3GnPAEERYPJgZJDncDU","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Performs an AI-powered security, quality, documentation, or dependency audit of a public GitHub repository and returns structured findings with severity ratings.","exampleAgentPrompt":"Can you audit the GitHub repo at https://github.com/myorg/my-api-service with a focus on security, checking up to 50 files, and tell me the risk level and any critical findings?","exampleUseCases":null,"resultDescription":"Returns a JSON object containing: a plain-English summary of the repo's overall state, the detected technology stack (e.g. ['Python','FastAPI']), an array of findings each with a title, severity level, and recommendation, and an overall risk_level string (e.g. 'medium', 'high').","failureModes":["Invalid or private GitHub repo URL returns an error — only public repositories are supported","max_files below 5 or above 100 triggers a validation error","Unrecognized focus value may default to 'general' rather than failing","Large repos with many files may be truncated to the max_files limit, potentially missing issues","Payment failure via x402 protocol returns HTTP 402 before any processing occurs"],"whenToPreferThis":"Use this endpoint when an AI agent needs a structured, machine-readable code audit of a public GitHub repository — especially in automated pipelines, CI/CD checks, or RAG systems evaluating third-party dependencies. It is well-suited for agents that need severity-tagged findings and a risk level without manual code review. Prefer it when paying per-call via USDC/x402 is acceptable and you want AI-powered analysis rather than static linting.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-03T00:34:21.379Z","isFirstParty":false,"canonicalSlug":"x402-cloud-github-repository-audit-b2504cb9"}