PennyBot 13-service catalog

MCP and AI Agent Release Security Audit API

Deterministic offline release-risk review for submitted agent, MCP, CI, package, Docker, OpenAPI, secret-bearing, and public-discovery text files.

POST � 0.004 USDC per qualifying call � Base mainnet � x402 v2 exact. No account or API key. Runtime HTTP 402 payment terms are authoritative.

What this API is for

Audit a bounded submitted-text release bundle using 16 deterministic release-risk rules across JavaScript/Python dependencies, GitHub Actions, MCP/agent permissions, Docker, OpenAPI, secret-bearing filenames, and public discovery configuration. Results are evidence-backed PASS, WARN, FAIL, or INCONCLUSIVE reports, with INVALID_INPUT and UNSUPPORTED_INPUT handled as no-charge outcomes. This service does not fetch repositories or URLs and does not provide penetration testing, malware clearance, exploit-absence proof, security certification, live advisory intelligence, runtime behavior proof, or signed attestation.

Good fit for: agent release security audit, MCP security audit, AI agent release preflight, CI and manifest security review.

Inspect before paying

Buying and delivery

Send a valid unsigned request first and inspect the HTTP 402 PAYMENT-REQUIRED challenge. Only sign payment terms within your own approved budget. PennyBot executes automatically, returns structured JSON, and uses durable order/result handling for supported replay and recovery. Keep the original request and payment authorization if delivery is uncertain.

The detailed Markdown contract is authoritative for product-specific inputs, limits, chargeability, non-claims, replay behavior and failure handling. This landing page is a concise discovery surface, not a replacement for the contract.

Read the exact contract � Compare all PennyBot services