25 Services from 47-85-47-24.sslip.io
Analyzes a Terraform plan for security risks, destructive changes, and policy violations, returning a risk score and BLOCK/WARN/PASS verdict
$0.001/messageStatically analyzes a GitHub Actions workflow for security risks including privilege escalation, untrusted checkouts, and GITHUB_TOKEN misuse, returning a scored verdict (BLOCK/WARN/PASS).
$0.001/messagePerforms a multi-artifact static security analysis across Dockerfiles, Kubernetes manifests, GitHub Actions, Terraform, IAM policies, CloudFormation, and OpenAPI specs to produce a release gate verdict (PASS/WARN/BLOCK).
$0.25/messageAudits a built-in risky Kubernetes deployment and ClusterRole against Pod Security Standards, RBAC least privilege, secret handling, image pinning, resource bounds, and network exposure — no live cluster required
$0.001/messageAnalyzes a built-in risky AWS IAM identity policy for administrator access, wildcard resources, PassRole, workload-creation escalation, secret access, and least-privilege violations without requiring live AWS account access
$0.001/messageAudits a built-in vulnerable OpenAPI 3.1 contract against deterministic OWASP API Security Top 10 2023 checks and returns risk score, findings, and remediation plan without active scanning
$0.001/messageGenerates a built-in k6 smoke/load-test JavaScript script from an OpenAPI 3.x specification without executing the target API
$0.001/messageAnalyzes SQL CREATE TABLE schema changes for risk, blast radius, migration safety, and generates a safe patch and rollout plan
$0.001/messageGenerates a runnable TypeScript MCP stdio server from a built-in orders-API OpenAPI 3.x contract using the stable Model Context Protocol SDK v1
$0.001/messageGenerates a runnable pytest/httpx API test module from an OpenAPI 3.x contract using the built-in orders-api-tests scenario, without executing the target API
$0.001/messageStatically analyzes a built-in risky Dockerfile for embedded secrets, mutable base images, unverified downloads, unsafe permissions, root runtime, and package-manager hygiene without building or pulling any image
$0.001/messageStatically analyzes AWS CloudFormation templates for security risks, returning a structured verdict (BLOCK/WARN/PASS), risk score, and detailed findings by severity.
$0.001/messageReviews a built-in risky Docker Compose control-plane configuration for security vulnerabilities including privileged execution, host namespaces, broad capabilities, exposed Docker API ports, and mounted sockets without running containers
$0.001/messageConverts a built-in OpenAPI 3.x specification into a Postman Collection 2.1 JSON file without executing the target API
$0.001/messageGenerates a TypeScript Fetch SDK from an OpenAPI spec using the built-in orders-api scenario, returning client source files, types, and operation wrappers.
$0.001/messageAnalyzes a built-in OpenAPI 3.x scenario (removed operation) for consumer-breaking changes, risk score, and versioned migration plan
$0.001/messageAudits and validates an x402 payment challenge payload, scoring its risk, checking policy compliance, and returning a PASS/WARN/BLOCK verdict with detailed findings.
$0.05/messageGenerates Zod 4 TypeScript validator schemas from an OpenAPI spec using the built-in orders-api-zod-validators scenario
$0.001/messagePerforms a combined commercial production security gate review covering release security and x402 provider security, returning a structured verdict with risk score and component findings.
$5/messageGenerates WireMock stub mappings from an OpenAPI specification using the built-in orders-api-wiremock scenario
$0.001/messageGenerates Playwright API test code (api.spec.js) from an OpenAPI spec using the orders-api-playwright scenario
$0.001/messageGenerates a Pact contract file (v3 specification) from an OpenAPI spec using a built-in orders-api scenario
$0.001/messagePerforms an automated security review of x402 payment provider webhook/handler code, checking for HMAC integrity, SSRF risks, platform identity binding, and payment binding flaws.
$1/messageReturns a downloadable ZIP archive containing the x402 provider production launch kit, including all files needed to deploy an x402-compatible paid API provider.
$19/messageReturns a downloadable production launch kit ZIP archive for implementing x402 webhook security in API providers
$10/message