api.zfinia.com

https://api.zfinia.com/x402/v1/github-actions-workflow-audit

Audit one GitHub Actions workflow against a contract the caller states. The finding that needs two parts of the file at once: a privileged trigger such as pull_request_target together with a checkout of the contributor ref, which runs untrusted code with the base repository secrets. Also reports an action pinned to a mutable tag, a secret or author-controlled event field interpolated into a run command, an absent permissions block, and the trigger key read as a boolean.

last updated: Oct 4, 2026 · type: http · x402 v2

Payment Options

NetworkSchemeAmountPay To
Baseexact$0.20 USDC0x25e8...9608

Try It

Resource Activity

via Bazaar · last 30 days
Calls
1
Unique Payers
1
Last Called
Oct 4, 2026