Provided by JACO (seller "JACO Nexus" on Skyfire). Effective 2026-10-03.
For one public GitHub repository URL per order, the service makes a shallow clone of the default branch and produces a report of (a) strings in the current files that match common credential patterns, shown masked, and (b) pinned dependency versions in package-lock.json and requirements.txt that have published advisories in the OSV.dev database. The scan is automated and deterministic. Repositories over 300 MB are refused; files over 1 MB are skipped.
It is not a penetration test, a code review or a guarantee that a repository is secure. Absence of findings does not mean absence of vulnerabilities. Credentials removed in earlier commits and dependencies without a pinned version are not analysed. The report is provided as is, without warranty of any kind.
9 USD per scan. Skyfire: your pay or kya-pay token is charged only after the report has been delivered; a scan that fails is not charged. x402 (USDC on Base): the payment is settled through Coinbase's facilitator when the order is accepted; if the scan then cannot be delivered, the order is kept and reviewed by the operator for a refund or a rerun.
Only public repositories can be scanned; no access tokens are requested or used. The clone is deleted when the scan finishes. The report (with credentials masked) is stored on the service and is available to anyone who has the order's report URL, which is unguessable; share it accordingly. Request metadata (time, path, user agent, country) is logged for operation and abuse prevention.
Scan repositories you own or are allowed to assess. Do not use the service to harvest credentials from third parties. Orders that appear abusive may be refused.
To the extent permitted by law, liability is limited to the price paid for the order concerned.
These terms may change; the version in force when an order is accepted applies to that order.