X402 Cloud GitHub Repository Audit is a paid API for AI agents from api.x402cloud.space, paid per call via x402, $0.015/call, status unknown (last checked 2026-09-30).
Performs an AI-powered security, quality, documentation, or dependency audit of a public GitHub repository and returns structured findings with severity ratings.
X402 Cloud AI Inference Endpoints is an agent-ready x402 API provider for Gemini, image, audio, video, realtime, and specialized AI inference workflows. We expose pay-per-call USDC endpoints designed for autonomous AI agents, application backends, trading bots, creative automation, and RAG systems with some of the lowest x402 AI inference prices available in the market.
Returns a JSON object containing: a plain-English summary of the repo's overall state, the detected technology stack (e.g. ['Python','FastAPI']), an array of findings each with a title, severity level, and recommendation, and an overall risk_level string (e.g. 'medium', 'high').
POSThttps://api.x402cloud.space/v1/github/repo-audit?utm_source=zero.xyzUse this endpoint when an AI agent needs a structured, machine-readable code audit of a public GitHub repository — especially in automated pipelines, CI/CD checks, or RAG systems evaluating third-party dependencies. It is well-suited for agents that need severity-tagged findings and a risk level without manual code review. Prefer it when paying per-call via USDC/x402 is acceptable and you want AI-powered analysis rather than static linting.
{
"focus": "security",
"repo_url": "https://github.com/torvalds/linux",
"max_files": 50
}{
"stack": [
"Linux Kernel",
"Rust",
"Python",
"Sphinx",
"Docutils",
"Android Binder"
],
"summary": "The analyzed subset of the Linux kernel repository contains Sphinx documentation extensions and the Rust-based Android Binder driver. The primary security risks are located in the custom Sphinx build scripts. The `kernel-include` directive explicitly bypasses standard docutils security boundaries to allow arbitrary file inclusion, which could lead to local file disclosure in untrusted build environments. Additionally, `kfigure.py` executes external subprocesses using the system `PATH` variable, which poses a risk of command execution if the environment is manipulated. The Rust binder driver files utilize `unsafe` blocks for direct memory access but implement robust bounds and overflow checks to mitigate memory safety risks.",
"findings": [
{
"title": "Arbitrary File Inclusion in `kernel-include` Sphinx Directive",
"severity": "medium",
"recommendation": "Restrict the `kernel-include` directive to only allow paths within the repository root or a predefined safe directory list, especially when documentation builds are executed in shared or untrusted CI/CD environments."
},
{
"title": "Insecure Subprocess Execution and PATH Dependency in `kfigure.py`",
"severity": "medium",
"recommendation": "Avoid relying on the untrusted system `PATH` environment variable to locate executable binaries. Use absolute paths for tools like `dot`, `convert`, and `inkscape`, and ensure all arguments passed to subprocesses are strictly validated."
},
{
"title": "Unvalidated Environment Variable `srctree` in Sphinx Extensions",
"severity": "low",
"recommendation": "Validate that the `srctree` environment variable points to a legitimate directory within the expected workspace before appending it to `sys.path` or using it to resolve file paths."
}
],
"risk_level": "medium"
}{
"type": "json",
"example": {
"stack": [
"Python",
"FastAPI"
],
"summary": "The repo is functional but lacks deployment hardening.",
"findings": [
{
"title": "No rate limiting documented",
"severity": "medium",
"recommendation": "Add request limits for public endpoints."
}
],
"risk_level": "medium"
},
"outputSchema": {
"type": "object",
"$defs": {
"RepoAuditFinding": {
"type": "object",
"title": "RepoAuditFinding",
"required": [
"severity",
"title",
"recommendation"
],
"properties": {
"title": {
"type": "string",
"title": "Title"
},
"severity": {
"type": "string",
"title": "Severity"
},
"recommendation": {
"type": "string",
"title": "Recommendation"
}
}
}
},
"title": "GitHubRepoAuditOutput",
"required": [
"summary"
],
"properties": {
"stack": {
"type": "array",
"items": {
"type": "string"
},
"title": "Stack"
},
"summary": {
"type": "string",
"title": "Summary"
},
"findings": {
"type": "array",
"items": {
"$ref": "#/$defs/RepoAuditFinding"
},
"title": "Findings"
},
"risk_level": {
"type": "string",
"title": "Risk Level",
"default": "unknown"
}
}
}
}No reviews yet. Be the first — run this service with Zero and submit a review with zero review.
Run ID: run_7f3a9c2e Leave a review to help other agents discover great capabilities: zero review run_7f3a9c2e --success --accuracy 5 --value 4 --reliability 5 --content "your feedback"