{"uid":"cap_k1Oo1ahx_gzJ6BE6xogtG","slug":"agentstools-code-security-scanner-204cd45f","name":"AgentsTools Code Security Scanner","description":"Static application-security scan of source code or a git-diff for CWE Top-25 logic bugs: SQL injection, XSS, command injection, code and template injection, SSRF, path traversal, insecure deserialization, weak crypto, insecure randomness, open redirect and XXE across Python, JavaScript, TypeScript, Java and Go. Returns a go/no-go verdict with per-finding CWE, severity, file and line. Static indicators, not a guarantee.","url":"https://api.agentstools.dev/code/scan","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"diff":{"type":"string","description":"A unified git-diff; only added lines are scanned"},"files":{"type":"array","items":{"type":"object"},"description":"Alternatively a batch of objects, each with path, content and optional language"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_hIUlmTjukF-_7KxH9wTZM","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Statically scans source code or a git-diff for CWE Top-25 vulnerabilities across Python, JavaScript, TypeScript, Java, and Go, returning a verdict with per-finding CWE ID, severity, file, and line.","exampleAgentPrompt":"Can you scan this Python function for security vulnerabilities — specifically check for SQL injection, command injection, and path traversal issues, and tell me if it passes or fails with the exact CWE IDs and line numbers?","exampleUseCases":[{"title":"Pre-merge security gate for PR diffs","prompt":"Here's the git-diff from my pull request — scan it for any CWE Top-25 logic bugs like SQL injection or SSRF and tell me if it's safe to merge, with the severity and line numbers of anything you find."},{"title":"Audit legacy Java service for insecure deserialization","prompt":"I have a Java class that handles object deserialization from untrusted input — can you scan it for insecure deserialization, XXE, and weak crypto vulnerabilities and give me a go/no-go verdict with CWE IDs?"},{"title":"CI pipeline security check for TypeScript code","prompt":"Before I deploy, scan this TypeScript file for XSS, open redirect, and template injection vulnerabilities and return a pass/fail result with each finding's CWE number, severity, and exact line."}],"resultDescription":"A go/no-go verdict indicating whether the code passed or failed the security scan, accompanied by a list of per-finding details including the CWE identifier, severity level (e.g. critical/high/medium/low), the affected file name, and the specific line number. Covers CWE Top-25 categories including SQL injection, XSS, command injection, code and template injection, SSRF, path traversal, insecure deserialization, weak crypto, insecure randomness, open redirect, and XXE.","failureModes":["Code too large or exceeds input size limits — truncate or split the file","Unsupported language submitted — only Python, JavaScript, TypeScript, Java, and Go are supported","Malformed or unparseable code snippet returns an error or empty findings","False negatives possible — static analysis cannot catch all runtime vulnerabilities","Network timeout on very large diffs"],"whenToPreferThis":"Choose this endpoint when you need a fast, automated CWE Top-25 security verdict on source code or a git-diff without setting up a local SAST tool. Ideal for CI/CD pipeline gates, pre-merge checks, or agent-driven code review workflows. Covers the most critical logic bug categories across five mainstream languages at low cost per call ($0.02 USDC). Prefer it over general-purpose LLM code review when you need structured, machine-readable findings with CWE IDs and line numbers rather than prose suggestions.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T18:02:27.697Z","isFirstParty":false}