{"uid":"cap_bbgW3XCAEuT8aH53JmHml","slug":"pr-verdict-merge-safety-scanner-c99c850c","name":"PR Verdict — Merge-Safety Scanner","description":"One merge-safety verdict for a public GitHub pull request. Fetches the PR diff and runs it through code, secret, CI/CD pipeline and dependency scanners, returning a single verdict (pass, caution, block), a risk score and findings with severity, file, line and a fix hint. One call instead of slicing the diff into several. Security indicators, not a guarantee.","url":"https://payai.agentstools.dev/pr/verdict","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"pr_url":{"type":"string","description":"Public GitHub pull-request URL (github.com/owner/repo/pull/N)"},"max_files":{"type":"integer","description":"Optional cap on files scanned for a large PR"},"dimensions":{"type":"array","items":{"type":"string"},"description":"Optional subset of code, secret, ci, deps (default: all)"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.03","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.03/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_w3-AIrB0Mz9oW9TApWYKJ","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.03","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches a public GitHub pull request diff and runs it through code, secret, CI/CD, and dependency scanners, returning a single pass/caution/block verdict with a risk score and per-finding details.","exampleAgentPrompt":"Can you run a merge-safety check on this PR — https://github.com/acme/backend/pull/412 — and tell me the verdict, the risk score, and any critical findings with fix hints? Scan all dimensions: code, secrets, CI, and deps.","exampleUseCases":[{"title":"Blocking a risky open-source contribution","prompt":"Before I merge this community PR at https://github.com/myorg/myrepo/pull/88, can you scan all dimensions — code, secrets, CI, and deps — and tell me if it's safe, the risk score, and any blocking findings I should fix first?"},{"title":"Automated pre-merge gate in a CI pipeline","prompt":"Run the full merge-safety verdict on https://github.com/acme/api-service/pull/201 and report whether it passes, any cautions or blocks, severity levels, and suggested fixes so I can decide whether to proceed."},{"title":"Auditing a dependency-heavy PR","prompt":"This PR at https://github.com/startup/frontend/pull/55 updates a bunch of packages — can you scan it with a focus on deps and secrets dimensions (max 30 files) and give me the verdict plus a list of risky findings with file and line references?"}],"resultDescription":"Returns a single top-level verdict (pass, caution, or block), a numeric risk score, and a list of findings each containing severity, affected file, line number, a description of the issue, and a fix hint. Covers code quality risks, exposed secrets, CI/CD pipeline manipulation, and vulnerable dependency updates.","failureModes":["Private or non-existent repository URL returns an error — PR must be publicly accessible","Invalid GitHub PR URL format causes a validation error","Very large PRs may hit timeout or file-count limits — use max_files to cap","If the diff is empty or PR is already merged with no diff, scanning may return no findings","Unsupported dimension values in the dimensions array cause parameter errors"],"whenToPreferThis":"Choose this endpoint when you need a single-call, multi-dimensional security assessment of a GitHub PR diff without orchestrating separate secret, code, CI, and dependency scanners yourself. It is ideal for automated pre-merge gates, AI code review agents, or open-source contribution audits where speed and consolidated output matter. Prefer it over manual diff inspection or assembling multiple scanning tools when a consolidated verdict and risk score are the goal.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T13:02:52.230Z","isFirstParty":false}