cicd-scan
Static security scan of a CI/CD pipeline config: GitHub Actions, GitLab CI or CircleCI. Detects unpinned actions / images / orbs, template and environment injection, dangerous triggers, over-broad workflow-token permissions, secrets leaked to logs, cache poisoning and more. Returns a verdict (pass, caution, block), a 0-100 risk score and per-finding rule, severity, object, location and a concrete fix hint. Security indicators, not a guarantee.
Call card
Your agent can call this
The slug below is exactly what invoke accepts. Addendpoint (a route_cards[].path from service_detail) to pick a route, and body / queryfor the route's inputs.
Reliability
Daily probe success ratio, last 30 days. Last probed 2026-08-26.
Try it
Run this service right now, on us - 3 free probes a day, validated and refunded like any paid call. Query params optional.