Skip to content
onelayer.
All tools

Tool detail

code-scan

Statically scans source code or a git diff for CWE Top-25 issues (injection, SSRF, path traversal, weak crypto and more) and returns a go/no-go verdict with per-finding CWE, severity, file and line.

Categories: Security

Use when

  • scan a git diff for security vulnerabilities before merging
  • check source files for SQL injection or XSS risks

Not for

  • not a guarantee of security -- static indicators only
  • not dynamic/runtime testing

Inputs

POST JSON body: diff (string, unified git diff) or files (array of {path, content, language?}) -- neither marked required

Inputs undocumented: open object without declared properties

Endpoint

Method
POST
URL
https://api.agentstools.dev/code/scan

Payment

Protocol
x402
Listed price
0.02 USDC per call on Base
Payment method
exact
Network
eip155:8453
Asset
0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913

Listed terms are catalog metadata. The caller supplies inputs and calls the tool outside Onelayer. If payment is required, the caller uses a compatible wallet to pay.

Source

Record
POST https://api.agentstools.dev/code/scan
Retrieved
2026-09-30T20:37:07.382Z
Catalog file SHA-256
6837ccddf886f0007cf3727ea9d27faaa5047b51b4f425345c554ce1c271a524
Catalog built
2026-09-30T22:31:58.034Z