{"uid":"cap_VXCeHio8Wu_sBiJ-w9122","slug":"payai-iac-inspect-single-resource-misconfiguration-scanner-4394d480","name":"PayAI IaC Inspect — Single Resource Misconfiguration Scanner","description":"Static misconfiguration scan of a SINGLE infrastructure resource or config snippet (Terraform, Kubernetes, Dockerfile, docker-compose or CloudFormation). The lightweight per-resource form of /iac/scan: returns a verdict (pass, caution, block), a risk score and findings with rule, severity, location and fix hint. Security indicators, not a guarantee.","url":"https://payai.agentstools.dev/iac/inspect","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"kind":{"enum":["auto","terraform","terraform-plan","kubernetes","dockerfile","docker-compose","cloudformation"],"type":"string","description":"Config format of the snippet, or auto to detect"},"resource":{"type":"string","description":"A single-resource config snippet to inspect"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.006","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.006/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.006","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.006","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_7FL36R3rtwX3uVFREaBBS","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.006","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Performs a static misconfiguration scan on a single infrastructure resource or config snippet (Terraform, Kubernetes, Dockerfile, docker-compose, or CloudFormation) and returns a verdict, risk score, and actionable findings.","exampleAgentPrompt":"Can you scan this Terraform S3 bucket resource for misconfigurations and tell me if it passes, needs caution, or should be blocked — along with the risk score and any specific fix hints?","exampleUseCases":[{"title":"Pre-deploy Kubernetes security check","prompt":"Before I apply this Kubernetes deployment manifest, scan it for misconfigurations and tell me the verdict, risk score, and what rules it's failing so I can fix them first."},{"title":"Dockerfile hardening review","prompt":"Check this Dockerfile snippet for security misconfigurations — I want to know the severity of any findings and get fix hints so I can harden it before pushing to CI."},{"title":"Terraform resource compliance gate","prompt":"Run a static security scan on this Terraform AWS IAM role resource and tell me whether it passes, needs caution, or should be blocked, along with the specific rules that triggered any findings."}],"resultDescription":"Returns a verdict string (pass, caution, or block), a numeric risk score, and a list of findings each containing the rule ID, severity level, location within the snippet, and a fix hint describing how to remediate the issue. Results are security indicators and not a guarantee of full compliance.","failureModes":["Unsupported config format — only Terraform, Kubernetes, Dockerfile, docker-compose, and CloudFormation are supported","Malformed or unparseable config snippet returns an error","Config snippet too large for single-resource inspection — use /iac/scan for bulk","Missing or empty resource body in request","Payment failure or insufficient USDC balance (x402 protocol)"],"whenToPreferThis":"Choose this endpoint when you need a fast, lightweight security check on a single IaC resource or config snippet during CI/CD pipelines, pre-deployment gates, or developer inner loops. Prefer this over /iac/scan when you have only one resource to inspect and want lower latency and cost. Best suited for agents implementing per-resource security guardrails in DevSecOps workflows.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T19:10:24.972Z","isFirstParty":false}