{"uid":"cap_ZrWTKgK6QeyNt556CdXHi","slug":"proof-quickscan-config-security-scanner-9bf27fc8","name":"Proof QuickScan Config Security Scanner","description":"Run a bounded deterministic preflight scan for possible private keys, secret assignments, permissive CORS, debug mode, insecure HTTP, and invalid JSON. Not a comprehensive security audit.","url":"https://qaegxjxaavxdqihfgzhr.supabase.co/functions/v1/proof-quickscan-x402/QUICKSCAN_CONFIG_SCAN","method":"GET","headers":{},"bodySchema":{"type":"object","properties":{"claim":{"type":"string","maxLength":20000},"format":{"type":"string"},"content":{"type":"string","maxLength":200000},"evidence":{},"expected_sha256":{"type":"string"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.03","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.03/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_x7IXm6MOx9a2cHWbXstuY","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.03","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Runs a bounded, deterministic preflight scan of supplied content or configuration for common security issues including private keys, secret assignments, permissive CORS, debug mode, insecure HTTP, and invalid JSON.","exampleAgentPrompt":"Can you do a quick preflight security scan on this config file content and tell me if there are any exposed private keys, hardcoded secrets, permissive CORS settings, debug mode flags, insecure HTTP URLs, or invalid JSON? Here's the content: [paste config here]","exampleUseCases":[{"title":"Pre-commit secrets leak check","prompt":"Before I commit this .env file to our repo, scan it for any exposed private keys, secret assignments, or hardcoded credentials that shouldn't be there."},{"title":"Production config CORS and debug audit","prompt":"Can you scan my nginx and app config for permissive CORS rules and any debug mode settings that might still be turned on before we push to production?"},{"title":"CI pipeline preflight validation","prompt":"Run a security preflight scan on the following JSON config — check for insecure HTTP references, invalid JSON, and any secret-looking assignments so I can block the deploy if anything looks risky."}],"resultDescription":"Returns a structured set of findings from the deterministic scan, indicating which security issues (if any) were detected: presence of private key patterns, secret variable assignments, overly permissive CORS headers, debug mode indicators, insecure HTTP URLs, and JSON validity status. Not a full penetration test or comprehensive audit — results are bounded to the specific checks listed.","failureModes":["Content exceeds 200,000 character limit — scan rejected","Malformed input schema causes 400 error","SHA-256 mismatch if expected_sha256 provided but content differs","Payment of $0.03 USDC not fulfilled — 402 response","Empty or null content field returns no meaningful findings","Ambiguous format field may reduce scan accuracy"],"whenToPreferThis":"Choose this endpoint when you need a fast, cheap, deterministic preflight check for the most common configuration security mistakes — leaked keys, secrets in plaintext, CORS misconfigurations, debug flags, and HTTP-not-HTTPS issues — before deploying or committing. It is not a replacement for a full SAST or penetration test, but is ideal for lightweight CI gates, automated pre-commit hooks, or agent-driven config review workflows where speed and cost matter.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:34:41.764Z","isFirstParty":false}