{"uid":"cap_qMk8h1Zwo-j4O77KGFqek","slug":"repo-security-bundle-scan-bb1fd205","name":"Repo Security Bundle Scan","description":"Combined repo security scan — secret scan, GitHub Actions workflow exposure check, and dependency manifest CVE review in one agent call for CI pre-commit and supply-chain triage.","url":"https://x402-hono-api.inraby.workers.dev/api/v1/repo-security-bundle","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"text":{"type":"string","description":"Optional text/config to scan for secrets"},"manifestText":{"type":"string","description":"Optional package.json, lockfile, or yarn.lock contents"},"workflowYaml":{"type":"string","description":"Optional GitHub Actions workflow YAML"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.04","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.04/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.04","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.04","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_Zc0jTY7n7xQm68q2Wgmht","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.04","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Runs a combined repository security scan covering secret detection, GitHub Actions workflow exposure, and dependency manifest CVE review in a single call.","exampleAgentPrompt":"Can you run a full repo security bundle scan on this code — check for hardcoded secrets in the source text, CVE risks in the package.json lockfile, and any dangerous permissions or exposure issues in the GitHub Actions workflow YAML I'm pasting in?","exampleUseCases":[{"title":"Pre-commit CI security gate","prompt":"Before I push this branch, scan the source code for any hardcoded secrets, check my package-lock.json for known CVEs, and review my .github/workflows/deploy.yml for unsafe permissions or exposed environment variables — give me a single combined security report."},{"title":"Supply-chain triage for new dependency","prompt":"I'm adding a new third-party package to my project. Can you scan the updated yarn.lock for CVE risks and also check my GitHub Actions workflow YAML to make sure there's no supply-chain attack surface introduced by the new dependency?"},{"title":"Security audit of open source contribution","prompt":"I just received a pull request that touches the CI workflow and updates several npm packages. Run a bundle security scan on the workflow YAML and the new package.json lockfile to flag any secrets exposure, risky workflow permissions, or vulnerable dependency versions before I merge."}],"resultDescription":"Returns a structured security report combining: (1) detected secrets or sensitive tokens found in the submitted text, (2) GitHub Actions workflow issues such as unsafe permissions, shell injection risks, or exposed secrets, and (3) CVE or vulnerability signals from the dependency manifest — all consolidated into a single severity-annotated bundle.","failureModes":["Empty or missing all three optional input fields may return an empty or minimal result with no findings","Malformed YAML in workflowYaml may cause parsing errors or incomplete workflow analysis","Very large lockfiles or manifests may exceed payload size limits","Ambiguous or minified source text may reduce secret detection accuracy","CVE data may be stale if the underlying vulnerability database has not been recently updated"],"whenToPreferThis":"Choose this endpoint when you need a single-call, multi-vector security scan covering secrets, CI workflow exposure, and dependency CVEs together — ideal for CI pre-commit hooks, PR gating, or rapid supply-chain triage. Prefer it over calling separate secret-scan, CVE-scan, or workflow-review endpoints individually when you want consolidated results in one agent turn. If you only need a focused IAM policy review, Terraform scan, or standalone CVE lookup, the sibling endpoints on the same provider are more targeted.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T18:37:23.723Z","isFirstParty":false}