{"uid":"cap_aoR6j1Updq0CBtjotvZv1","slug":"vuln-surface-scan-1e6effd6","name":"Vuln Surface Scan","description":"Scan a public domain with nuclei (OSS) for exposed vulnerabilities and get a prioritized report: findings by severity, top matches, and a verdict an agent can act on. Runs as a governed on-demand docker job (one at a time, memory-capped).","url":"https://k2so.wrong.systems/api/services/vuln-surface-scan","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"type":"object","properties":{"meta":{"enum":["0","1"],"type":"string","description":"Set to 1 for free metadata JSON (no payment required)"},"domain":{"type":"string","description":"Composite input parameter"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object","title":"Vuln Surface Scan paid response","$schema":"https://json-schema.org/draft/2020-12/schema","required":["ok","paid","service","provider","result"],"properties":{"ok":{"type":"boolean"},"paid":{"type":"boolean"},"result":{"type":"object","required":["ok","service"],"properties":{"ok":{"type":"boolean","description":"Handler success"},"score":{"type":"number"},"service":{"type":"string","description":"Service slug"},"summary":{"type":"string"},"evidence":{"type":"object"},"strengths":{"type":"array","items":{"type":"string"}},"confidence":{"type":"string"},"generatedAt":{"type":"string","description":"ISO-8601 timestamp"},"riskFactors":{"type":"array","items":{"type":"string"}}}},"payment":{"type":"object","properties":{"code":{"type":"string"},"payer":{"type":"string"},"detail":{"type":"string"},"selfPay":{"type":"boolean"},"transaction":{"type":"string"}}},"service":{"type":"string"},"provider":{"type":"string","const":"K-2SO"}}}}}}},"responseSchema":{"type":"json","example":{"ok":true,"paid":true,"result":{"ok":true,"service":"vuln-surface-scan"},"service":"vuln-surface-scan","provider":"K-2SO"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_aaz0juR9FyuCrP_QjzyBA","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.1","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Scans a public domain using Nuclei (OSS) to identify exposed vulnerabilities and returns a prioritized severity report with findings, top matches, and an actionable verdict.","exampleAgentPrompt":"Can you run a nuclei vulnerability surface scan on example.com and give me a prioritized report of any exposed security issues, including severity levels and what I should act on first?","exampleUseCases":[{"title":"Pre-launch security check for SaaS","prompt":"Before we go live, can you scan staging.myapp.io for any exposed vulnerabilities and tell me if there's anything critical we need to fix first?"},{"title":"Third-party vendor security assessment","prompt":"I need to assess the attack surface of a vendor we're onboarding — can you run a vulnerability scan on vendor-portal.acme.com and give me a severity breakdown and verdict?"},{"title":"Routine domain security audit","prompt":"Run a nuclei scan on mybusiness.com and give me the top vulnerability findings sorted by severity so I know what our biggest risks are right now."}],"resultDescription":"Returns a JSON object with: a boolean success flag, payment confirmation, a numeric risk score, a natural-language summary verdict, a confidence level, an evidence object with detailed findings, an array of identified risk factors, an array of strengths, and an ISO-8601 timestamp of when the report was generated.","failureModes":["Invalid or non-public domain returns an error or empty findings","Domain unreachable or rate-limited results in scan failure","Only one scan job runs at a time — concurrent requests may be queued or rejected","Memory cap exceeded for very large or complex targets may cause job termination","Payment not processed or insufficient USDC balance returns 402 with no results"],"whenToPreferThis":"Choose this endpoint when you need a fast, on-demand, automated vulnerability surface scan of a public domain using the Nuclei OSS scanner without setting up your own infrastructure. Ideal for agents performing security assessments, pre-launch checks, or third-party vendor reviews that need a structured, machine-readable severity report they can act on directly. Not suitable for internal/private hosts, authenticated deep-scan penetration testing, or continuous monitoring workloads.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T12:27:07.751Z","isFirstParty":false}