{"uid":"cap_wtvUiNW0VWCCVcrHvPvjs","slug":"ci-cd-pipeline-security-scanner-d393a43a","name":"CI/CD Pipeline Security Scanner","description":"Static security scan of a CI/CD pipeline config: GitHub Actions, GitLab CI or CircleCI. Detects unpinned actions / images / orbs, template and environment injection, dangerous triggers, over-broad workflow-token permissions, secrets leaked to logs, cache poisoning and more. Returns a verdict (pass, caution, block), a 0-100 risk score and per-finding rule, severity, object, location and a concrete fix hint. Security indicators, not a guarantee.","url":"https://api.agentstools.dev/ci/scan","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"format":{"enum":["auto","github-actions","gitlab-ci","circleci"],"type":"string","description":"CI system, or auto to detect from the content"},"content":{"type":"string","description":"The CI/CD config text to scan (workflow file)"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_ObiU9BG4SUZI-fSUlmaLF","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Statically analyzes GitHub Actions, GitLab CI, or CircleCI pipeline configs for security vulnerabilities and returns a verdict, risk score, and per-finding remediation hints.","exampleAgentPrompt":"Can you scan my GitHub Actions workflow YAML for security issues — I want to know if there are unpinned actions, dangerous triggers, or leaked secrets, and get a pass/caution/block verdict with a risk score?","exampleUseCases":[{"title":"Pre-merge pipeline security gate","prompt":"Before I merge this pull request, scan the GitHub Actions workflow YAML it touches and tell me if it passes, needs caution, or should be blocked — flag any unpinned actions or permission issues with fix hints."},{"title":"Audit existing GitLab CI config","prompt":"Run a security audit on my GitLab CI config file and give me a risk score out of 100, listing every finding with its severity and how to fix it — especially look for secrets leaking to logs or overly broad token permissions."},{"title":"CircleCI orb pinning check","prompt":"Check my CircleCI config YAML for unpinned orbs and any template injection risks, and tell me the overall verdict and what I need to fix to get to a passing score."}],"resultDescription":"Returns a verdict of 'pass', 'caution', or 'block', a numeric risk score from 0 to 100, and a list of per-finding objects each containing the rule name, severity, affected object, location in the file, and a concrete fix hint. Security indicators only, not a guarantee of safety.","failureModes":["Unsupported CI platform type returns an error","Malformed or unparseable YAML returns a parse error","Empty or missing config body results in a validation error","Very large config files may time out","Ambiguous YAML that passes parsing but is semantically invalid may produce incomplete findings"],"whenToPreferThis":"Use this endpoint when you need a fast, structured security verdict on a CI/CD config before merging or deploying — especially when you want per-finding rule citations and actionable fix hints rather than a generic linter output. It is purpose-built for GitHub Actions, GitLab CI, and CircleCI and targets supply-chain-specific risks like unpinned actions, injection, and token over-permissioning that general YAML validators miss.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T01:05:38.612Z","isFirstParty":false}