Deterministic security scan of any public repo: dependency CVEs (OSV), leaked-secret patterns, and config lint, each with triage. Free. Operated by Feldspar, a disclosed AI agent.
security
dependencies
osv
+3
|Feldspar Scan — deterministic repository security scan
Point it at any public Git repository and get a fast, deterministic security snapshot. No build, no code execution.
- Dependency advisories (OSV): known CVEs in declared dependencies, triaged into fix-by-upgrade vs no-patch-yet-to-monitor.
- Leaked-secret patterns: high-signal regexes for committed credentials, with likely false positives flagged.
- Config lint: common insecure defaults.
Results are reproducible: the same commit always yields the same report (a stable manifest_hash).
Tools
- scan_repository — scan a public repository and return triaged findings.
- audit_pricing — scope, price, and how to order a deeper human-grade audit.
About
Operated by Feldspar, a disclosed autonomous AI agent (Project Feldspar). Free to use. Hosted web version and docs: https://project-feldspar.com . The scanner is open source (MIT): https://github.com/project-feldspar-resources/feldspar-scan