{"uid":"cap_MGZ_MJJJ_biRiMcMR4uss","slug":"profitcollector-repo-risk-due-diligence-report-91340a2a","name":"ProfitCollector Repo Risk Due Diligence Report","description":"Decision-grade security/due-diligence outcome reports ($20-$100) plus deterministic paid utilities ($0.001+) for software agents and automated workflows.","url":"https://api.bakhour.ca/security/repo-risk-report/due-diligence","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"ref":{"type":"string","description":"Optional branch/tag to analyze. Defaults to the repository's default branch."},"repo_url":{"type":"string","description":"Public https://github.com/... or https://gitlab.com/... repository URL."}}},"responseSchema":{"type":"json","example":{"risk":{"severity":"high","risk_score":45},"tier":"due_diligence","repo_url":"https://github.com/pallets/flask","component_count":29,"secret_findings":[],"openssf_scorecard":{"overall_score":7.1,"highlighted_checks":{"Maintained":{"score":10}}},"due_diligence_summary":{"findings":[{"detail":"...","category":"vulnerabilities","priority":"high"}],"overall_recommendation":"proceed_with_caution"},"vulnerability_matches":{}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"100","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$100/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"100","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"100","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_zuAQdV7W0tQk-q_Hyu2Q1","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"100","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Generates a comprehensive security and due-diligence report for a public GitHub or GitLab repository, including vulnerability findings, secret scanning, OpenSSF scorecard, and an overall recommendation.","exampleAgentPrompt":"Can you run a full due diligence security report on https://github.com/pallets/flask — I need to know the risk score, any vulnerabilities, whether secrets were leaked, and whether I should proceed with using it?","exampleUseCases":[{"title":"Vetting a new open source dependency","prompt":"Before we add https://github.com/psf/requests to our project, can you pull a full security due diligence report on it — I want to see the risk score, any CVEs, and whether the project is actively maintained?"},{"title":"Auditing a vendor's public repository","prompt":"We're about to sign a contract with a vendor — can you run a due-diligence security scan on their public repo at https://github.com/some-vendor/some-lib and tell me if there are any high-priority findings I should worry about?"},{"title":"Checking a specific branch before merging","prompt":"Can you analyze the security risk of the release/2.0 branch on https://github.com/expressjs/express and give me the full report including vulnerability matches and overall recommendation?"}],"resultDescription":"A JSON report containing: a risk object with severity level and numeric risk score (0–100), a tier label ('due_diligence'), the analyzed repo URL, a component count, a list of secret findings, an OpenSSF scorecard with overall score and per-check highlights, a due_diligence_summary with categorized findings (each with detail, category, and priority), an overall recommendation (e.g. 'proceed_with_caution'), and a vulnerability matches map.","failureModes":["Invalid or private repository URL returns an error — only public GitHub/GitLab repos are supported","Inaccessible branch or tag reference causes analysis failure — defaults to the repo's default branch if omitted","Payment not completed (HTTP 402) — the $100 USDC payment must be settled via x402 before results are returned","Rate limits or upstream GitHub/GitLab API issues may cause timeouts or partial results","Newly created or empty repositories may yield incomplete component counts or scorecard scores"],"whenToPreferThis":"Choose this endpoint when you need a comprehensive, decision-grade security report on a public repository — not just raw CVE data but a synthesized recommendation with secret scanning, OpenSSF scorecard, and prioritized findings. It is especially valuable for automated procurement, dependency onboarding pipelines, or vendor due diligence workflows where a single authoritative report per repo justifies the $100 cost. Prefer it over lighter-weight scanners when the output needs to be actionable for a go/no-go decision.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:33:28.131Z","isFirstParty":false}