# code-bundle-security-review-get

> code-bundle-security-review-get is a paid API for AI agents from agente.revenuerecoveryai.app, paid per call via x402, $0.05/call, status unknown (last checked 2026-10-02).

Statically reviews a bundle of code files (Python, web, JSON) for forbidden imports, dangerous calls, unauthorized writes, network access, and hardcoded credentials without executing any code.

## Facts

- Endpoint: GET https://agente.revenuerecoveryai.app/v1/code/review?utm_source=zero.xyz
- Price: $0.05/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/code-bundle-security-review-get-2b1662bb
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_A6pKh_U07pOPS4Dl511IX

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability code-bundle-security-review-get-2b1662bb
```

Example prompt: Can you do a static security review of this Python file called 'data_pipeline.py'? I need to know if it has any forbidden imports, dangerous calls, hardcoded credentials, or unauthorized network or filesystem writes — without actually running the code.

## When to prefer this

Choose this endpoint when you need a fast, safe, no-execution static security gate for Python, web (HTML/JS/CSS), or JSON files — particularly before allowing untrusted or third-party code into an agent pipeline. Prefer it over full sandboxed execution when you want zero side-effects and rapid screening for the most common abuse vectors (credential leaks, forbidden imports, network calls, filesystem writes).

## Known failure modes

- Unknown or unsupported file types are declared unverifiable rather than safe — agents must not treat absence of findings as blanket approval
- Missing required query parameters 'nombre' or 'texto' returns a 400-level error
- Very large code bundles may hit payload size limits
- Non-code binary content submitted as text may produce meaningless output
- Obfuscated code may evade static pattern detection

## How this service works

Revisión de seguridad de un paquete de ficheros (Python, web, JSON) sin ejecutar nada: importaciones y llamadas prohibidas, escritura, red y credenciales. Un tipo de fichero que el gate no sabe leer se declara como no verificable, no como aprobado.

## Output

A structured JSON report listing security findings per file: forbidden imports detected, prohibited function calls, unauthorized filesystem writes, network access violations, hardcoded credentials found, and a verifiability status for each file type (unverifiable file types are flagged as non-verifiable rather than approved).

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET",
      "HEAD",
      "DELETE"
     ],
     "type": "string"
    },
    "queryParams": {
     "type": "object",
     "required": [
      "nombre",
      "texto"
     ],
     "properties": {
      "texto": {
       "type": "string"
      },
      "nombre": {
       "type": "string"
      }
     }
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object"
    }
   }
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/code-bundle-security-review-get-2b1662bb/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from agente.revenuerecoveryai.app](https://www.zero.xyz/host/agente.revenuerecoveryai.app/llms.txt)
