Fast Heuristic Code Security Scan

Scan supplied code with transparent deterministic rules for common secret, injection, shell, weak-hash, and Solidity risks. This is not a professional audit.

0.01 USDC / request POST computed_service Base mainnet x402 v2

Preview request

The preview path is rate-limited and does not charge. It executes the live source and returns the paid response shape while withholding decision-ready values. Production requests use the same parameters and return a standard x402 challenge when no payment signature is present.

curl --request POST \
  "https://ai-data-marketplace-1042299154756.us-central1.run.app/api/v1/code_audit?preview=true" \
  --header "content-type: application/json" \
  --data '{"code":"def get_user(id):\n  return db.execute('SELECT * FROM users WHERE id = ' + id)","language":"python"}'

Input contract

ParameterTypeRequiredDescription
codestringYesThe source code snippet.
languagestringYesProgramming language (python, javascript, go, etc.).

Example deliverable

This is the documented response shape, not a promise that live values will match the example. The paid request returns current or declared-source results using the same contract.

enginelanguagecaveatlines_scannedfindings_countfindings
{
  "success": true,
  "engine": "deterministic_static_rules_v1",
  "language": "python",
  "caveat": "This is a fast heuristic scan, not a professional security audit.",
  "lines_scanned": 2,
  "findings_count": 1,
  "findings": [
    {
      "rule": "sql_string_concatenation",
      "severity": "high",
      "line": 2,
      "evidence": "SELECT * FROM users WHERE id = ' +",
      "recommendation": "Use parameterized database queries."
    }
  ],
  "marketplace_metadata": {
    "data_mode": "computed_service",
    "billable": true,
    "availability": "operational",
    "source": "deterministic static rules"
  }
}

Purchase decision

Buy when: the active task needs this product's structured result, its declared source and freshness are sufficient, and 0.01 USDC is within the buyer's authorized per-request limit.

Skip when: a cached result is sufficient, the source or fields do not satisfy the task, or the buyer has not authorized payment. Do not bypass wallet, budget, or user-approval policy.

Guaranteed response metadata

Every successful product response identifies how the result was produced. Product-specific output fields are documented in the paid OpenAPI contract. The preview proves the live source and field types without returning the paid values.

{
  "marketplace_metadata": {
    "data_mode": "computed_service",
    "billable": true,
    "availability": "operational",
    "source": "deterministic static rules"
  }
}

Agent payment flow

Fast path: install the public MCP package, configure a dedicated low-balance Base buyer wallet and a maximum per-request spend, then call this tool with auto_pay: true. The client handles the challenge, local signature, settlement, and retry in one tool call.

npx -y dopaminedesk-ai-data-marketplace-mcp

X402_AUTO_PAY=true
X402_EVM_PRIVATE_KEY=<dedicated buyer wallet key>
X402_MAX_PAYMENT_USDC=0.25

tool input: { "auto_pay": true }

Manual path: request the product, read the base64 PAYMENT-REQUIRED challenge, sign with any compatible x402 v2 client, and retry with PAYMENT-SIGNATURE. A successful response includes PAYMENT-RESPONSE.