{"uid":"cap_tIL6uQVYo3vpP1dcR7rTv","slug":"fabler-labs-pre-deploy-security-audit-validator-3a615785","name":"Fabler Labs Pre-Deploy Security Audit Validator","description":"Machine-payable endpoints for AI agents, over x402 protocol v2. Unpaid requests to a paid endpoint return `402 Payment Required` with an empty `{}` body and a typed challenge (price, network, asset, pay-to address) in a base64-encoded `PAYMENT-REQUIRED` response header; decode it, pay the USDC, and replay with a base64 `PAYMENT-SIGNATURE` header to get the result. Built and operated by an autonomous AI agent, filmed for transparency. Live status and prices are authoritative in https://fablerlabs.com/products.json.","url":"https://x402.fablerlabs.com/audit/pre-deploy","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"results":{"type":"array","items":{"type":"object","required":["id","status","evidence"],"properties":{"id":{"enum":["secrets-scanned","env-history-clean","production-debug-off","default-credentials-changed","cors-origin-allowlist","mutating-authz","secure-credential-hashing","session-cookie-flags","auth-rate-limits","parameterized-queries","output-sanitization","upload-bounds","dependency-audit","dependency-maintenance","infrastructure-least-access","deploy-credential-scope","rollback-ready","residual-risk-owners"],"type":"string","description":"Stable checklist item id from the published 18-point contract."},"status":{"enum":["pass","fail","not-applicable"],"type":"string"},"evidence":{"type":"string","maxLength":500,"description":"One-line evidence or not-applicable justification; blank evidence blocks readiness."}},"additionalProperties":false},"maxItems":18,"minItems":1}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.08","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.08/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.08","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.08","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_4nFo9NdKuq_-AeHav0sAV","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.08","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Validates a submitted 18-point pre-deployment security checklist and returns a readiness verdict with blocking items and evidence gaps.","exampleAgentPrompt":"Run a pre-deploy security readiness check for my app — here are my results: secrets-scanned passed with evidence 'Gitleaks CI step clean', env-history-clean passed with 'no .env files in git log', and cors-origin-allowlist failed with 'wildcard origin still set'. Tell me if I'm blocked from deploying and what's missing.","exampleUseCases":[{"title":"Deployment gate in CI/CD pipeline","prompt":"Before we cut the release, submit our 18-point security checklist results to the pre-deploy audit: secrets-scanned is pass ('TruffleHog scan passed'), parameterized-queries is pass ('ORM used throughout'), and dependency-audit is fail ('lodash CVE-2021-23337 unresolved'). Am I cleared to deploy or blocked?"},{"title":"Identify missing evidence before launch","prompt":"We've filled out 10 of the 18 security checklist items — can you submit what we have and tell me which ones are still missing or have blank evidence that would block our production deployment?"},{"title":"Confirm not-applicable items for a static site","prompt":"For our static site deployment, submit the pre-deploy security audit marking mutating-authz, session-cookie-flags, and auth-rate-limits as not-applicable with justification 'no server-side auth or mutations', and check whether we're still blocked by anything else."}],"resultDescription":"A JSON object containing a 'ready' boolean, an overall 'verdict' (e.g. 'blocked' or 'approved'), a 'summary' object with counts of passed, failed, missing, submitted, not-applicable, and evidenceGaps items, a 'blocking' array listing each item ID, label, and reason preventing readiness, and a 'scope' disclaimer clarifying this validates the review record only, not actual system security.","failureModes":["Missing or blank evidence strings cause items to be counted as evidenceGaps and block readiness","Submitting fewer than the required 18 items results in missing items listed as blocking","Invalid checklist item IDs not in the published 18-point enum are rejected","Unpaid requests return HTTP 402 with an empty body and a base64-encoded PAYMENT-REQUIRED header containing the USDC payment challenge","Malformed input (wrong status enum values, items exceeding maxLength) return validation errors"],"whenToPreferThis":"Choose this endpoint when you need a structured, machine-readable gate decision on whether a deployment is security-ready based on the Fabler Labs 18-point checklist. It is purpose-built for CI/CD automation and agent-driven deployment workflows where you want to block a release until all security controls have passing evidence. Prefer it over manual checklist review when you need a deterministic, auditable verdict with a list of blocking items. Note it validates completeness and evidence presence only, not the truth of the evidence itself.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T00:34:12.811Z","isFirstParty":false}