security $0.0005 / call
Secret Scan
Detect five families of credential patterns with fully masked findings.
security.secret-scansecurity.csp-audit · v1.0.0
Parse a supplied Content Security Policy and flag selected risky or missing directives.
{
"policy": "default-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'"
}{
"directives": [
{
"name": "default-src",
"sources": [
"'self'"
]
},
{
"name": "object-src",
"sources": [
"'none'"
]
},
{
"name": "base-uri",
"sources": [
"'self'"
]
},
{
"name": "frame-ancestors",
"sources": [
"'none'"
]
}
],
"findings": [],
"scope": "Fixed CSP heuristics; does not simulate browser enforcement or certify a site."
}Generated from the actual handler using this example input; this is a preview, not a paid API call. Paid responses wrap the result with a receipt and recovery expiry.
Add credits in the workspace and keep your API key in private environment storage. Use the same request ID and exact body to recover a lost response within ten minutes.
// Node.js 22+. Read the key from your private environment.
const requestId = Date.now() + '_' + crypto.randomUUID();
const response = await fetch('https://agent-utilities.agent-utilities.workers.dev/v1/tools/security.csp-audit', {
method: 'POST',
headers: {
'Content-Type': 'application/json',
'Authorization': 'Bearer ' + process.env.AGENT_UTILITIES_API_KEY,
'Idempotency-Key': requestId
},
body: JSON.stringify({
"policy": "default-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'"
})
});
const data = await response.json();
if (!response.ok) throw new Error(data.error?.message ?? 'Request failed');
console.log(data);
// On response loss, retry this SAME requestId, tool and body.
// Do not rerun the line that generates requestId for a retry.{
"type": "object",
"properties": {
"policy": {
"type": "string",
"maxLength": 16000
}
},
"required": [
"policy"
],
"additionalProperties": false
}{
"type": "object",
"properties": {
"directives": {
"type": "array",
"items": {
"type": "object",
"properties": {
"name": {
"type": "string"
},
"sources": {
"type": "array",
"items": {
"type": "string"
}
}
},
"required": [
"name",
"sources"
],
"additionalProperties": false
}
},
"findings": {
"type": "array",
"items": {
"type": "object",
"properties": {
"rule": {
"type": "string"
},
"severity": {
"type": "string"
},
"message": {
"type": "string"
}
},
"required": [
"rule",
"severity",
"message"
],
"additionalProperties": false
}
},
"scope": {
"type": "string"
}
},
"required": [
"directives",
"findings",
"scope"
],
"additionalProperties": false
}Prices are experimental. The service currently allows 1,000 new calls per day across all accounts. Failed operations return reserved credits. Successful results are encrypted for ten-minute retry recovery. Review data handling and service limits.
security $0.0005 / call
Detect five families of credential patterns with fully masked findings.
security.secret-scansecurity $0.0005 / call
Replace detected credential patterns with redaction markers.
security.secret-redactsecurity $0.0003 / call
Decode untrusted JWT claims and optionally compare timestamps; never verifies a signature.
security.jwt-inspect