{"uid":"cap_MQwI4gIfDxyJoJ4ZPPo5G","slug":"profitcollector-repo-risk-report-deep-tier-e1374bf5","name":"ProfitCollector Repo Risk Report – Deep Tier","description":"Decision-grade security/due-diligence outcome reports ($20-$100) plus deterministic paid utilities ($0.001+) for software agents and automated workflows.","url":"https://api.bakhour.ca/security/repo-risk-report/deep","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"ref":{"type":"string","description":"Optional branch/tag to analyze. Defaults to the repository's default branch."},"repo_url":{"type":"string","description":"Public https://github.com/... or https://gitlab.com/... repository URL."}}},"responseSchema":{"type":"json","example":{"risk":{"severity":"high","risk_score":38},"tier":"deep","repo_url":"https://github.com/pallets/flask","component_count":29,"secret_findings":[{"file":"config.py","line":12,"pattern":"aws_access_key_id"}],"vulnerability_matches":{}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"50","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$50/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"50","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"50","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_LTa11tX2HQgwqk3wHbsns","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"50","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Performs a deep security scan of a public GitHub or GitLab repository, returning a scored risk report with secret findings and vulnerability matches.","exampleAgentPrompt":"Run a deep security scan on https://github.com/pallets/flask — I need the full risk score, any exposed secrets like API keys, and a vulnerability breakdown so I can decide whether to depend on it.","exampleUseCases":[{"title":"Open source dependency due diligence","prompt":"Before we add this library to our project, do a deep security scan on https://github.com/psf/requests — I want to know the risk score and whether there are any hardcoded credentials or known vulnerabilities in it."},{"title":"Third-party vendor code audit","prompt":"Our vendor just shared their repo at https://github.com/acme-corp/payment-sdk — can you run a deep risk report on it so I can see if there are any exposed secrets or high-severity security issues before we sign the contract?"},{"title":"Security check on a specific branch","prompt":"Check the security posture of the dev branch on https://github.com/myorg/backend-api — I need to know the risk score and any secret leaks before we merge it to main."}],"resultDescription":"A JSON report containing a risk severity level (e.g. high/medium/low), a numeric risk score (0–100), the analysis tier ('deep'), the repository URL, a count of analyzed components, an array of secret findings with file path, line number, and pattern name, and a map of vulnerability matches.","failureModes":["Private or inaccessible repository URL returns an error — only public GitHub/GitLab repos are supported","Invalid or malformed repo URL causes a 400-class validation error","Non-existent branch or tag specified in 'ref' field triggers a ref-not-found error","Payment failure or insufficient funds (x402) prevents the scan from being initiated","Large repositories may time out or return partial results","Rate limiting on the upstream SCM API may cause transient failures"],"whenToPreferThis":"Choose this deep-tier endpoint when you need a comprehensive, decision-grade security report — not just a surface check — on a public GitHub or GitLab repository. It is ideal for supply chain due diligence, vendor onboarding, or pre-merge audits where secret detection and vulnerability matching at depth are required and the $50 cost per call is justified by the stakes of the decision.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T18:45:35.961Z","isFirstParty":false}