nittim

Production-safety audits for AI-generated code, with a fix for every finding.

使うべきか

品質と安全性

B
説明の品質
100%
スキーマの完全性
89%
命名の品質
92%
ポイズニングのリスク
0%
権限の一致
100%
プロトコルへの準拠
100%

検出事項(11)

  • HIGHTool poisoning patterns detected
  • MEDIUMTool description contains URL to non-standard domainaudit_repo 内
  • MEDIUMTool description contains URL to non-standard domainaudit_source 内
  • MEDIUMTool description contains URL to non-standard domainverify_fix 内
  • MEDIUMTool description contains URL to non-standard domainget_loop 内
  • MEDIUMTool description contains URL to non-standard domainmint_key 内
  • MEDIUMTool description contains URL to non-standard domainrun_module 内
  • MEDIUMTool description contains URL to non-standard domainjudge_output 内
  • MEDIUMTool description contains URL to non-standard domaindispute_finding 内
  • MEDIUMTool description contains URL to non-standard domainreport_loop 内

ツール定義とプロトコルへの準拠に関する自動分析に基づいています。

コンテキストコスト

~6,356トークン数(ツール定義)
~3.1 KB一般的なレスポンスサイズ
注意への影響は大きい(128k コンテキストの 4.97%)

これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。

インストール

ワンクリックインストール

これを `claude_desktop_config.json` ファイルに追加してください:

{
  "mcpServers": {
    "nittim": {
      "url": "https://nittim.com/api/mcp"
    }
  }
}

リモートエンドポイント

https://nittim.com/api/mcpstreamable-http

できること

ツール一覧

ツール(15)

🟢 読み取り専用🟡 書き込み🔴 削除⚪ 不明
🟡audit_repo(repoUrl, githubToken, confirmedCost, authorization, fullScan, ...)

Paid nittim AI audit of a GitHub repository: one structured pass over the highest-signal source; the only tool here that returns scores and a verdict. Answers with the audit's id, not the report. `fullScan: true` buys the wider Full Audit tier. NEEDS A KEY: mint one at https://nittim.com/keys. COSTS MONEY in three calls: the first quotes a price and charges nothing; a second with `confirmedCost` set to that exact price returns a one-time link for the ACCOUNT OWNER to confirm — their yes, not the assistant's; a plain third call with the same arguments runs once at that price. A moved price is re-quoted, never charged.DELIVERED AS A BATCH: the report lands Usually within 15 minutes*. * Most reports land within 15 minutes. Worst case, 24 hours.

入力スキーマ

{
  "type": "object",
  "properties": {
    "repoUrl": {
      "type": "string",
      "minLength": 1,
      "description": "GitHub repository URL or owner/repo. A private repo needs a githubToken, unless the account has installed nittim's GitHub App at nittim.com for it."
    },
    "githubToken": {
      "description": "Optional read-only GitHub token for a private repo. Without one, only public repos are reachable — unless the account has installed nittim's GitHub App at nittim.com for this repo, in which case a private repo works with no token at all.",
      "type": "string"
    },
    "confirmedCost": {
      "description": "COST CONFIRMATION. Omit on the first call; then send back the exact quoted `cost`.",
      "type": "object",
      "properties": {
        "kind": {
          "type": "string",
          "description": "The `kind` from the quoted cost, e.g. 'credits'."
        },
        "credits": {
          "type": "number",
          "description": "The `credits` number from the quoted cost."
        },
        "centicredits": {
          "description": "The `centicredits` integer from the quoted cost, if it carried one.",
          "type": "number"
        }
      },
      "required": [
        "kind",
        "credits"
      ]
    },
    "authorization": {
      "description": "HUMAN CONFIRMATION. The `authorization` id from the confirm-link answer, once the account owner has pressed Confirm. Single-use, short TTL.",
      "type": "string"
    },
    "fullScan": {
      "description": "True buys the wider Full Audit tier: every eligible source file, priced by pass count.",
      "type": "boolean"
    },
    "payInstead": {
      "description": "True pays credits now instead of queuing for the daily free-audit budget to reopen, skipping the covered (Audit) entitlement even when it would otherwise be free.",
      "type": "boolean"
    },
    "deployedUrl": {
      "description": "Optional URL of this repository's live deployment, for an origin the account owner actually operates. When set, the audit adds one bounded, READ-ONLY fetch pass against it and reports drift between the deployed artifact and the audited commit. Redirects are never followed; private addresses are refused.",
      "type": "string"
    }
  },
  "required": [
    "repoUrl"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟡audit_source(name, files, uploadGrant, confirmedCost, authorization, ...)

Paid nittim AI audit of source files you post, for a project with no GitHub remote. Send SOURCE files, not build output — no node_modules or dist. On nittim's own key this answers with the audit's id; the report lands Usually within 15 minutes*. * Most reports land within 15 minutes. Worst case, 24 hours. On your own key (BYOK Pro) the report comes back in this call instead. Costs 5.14 credits (a paid+subscribed org's included allowance, an unspent Audit, then prepaid credits), always saved as a PRIVATE report. `fullScan: true` buys the wider Full Audit tier. NEEDS A KEY: mint one at https://nittim.com/keys. COSTS MONEY in three calls: the first quotes a price and charges nothing; a second with `confirmedCost` set to that exact price returns a one-time link for the ACCOUNT OWNER to confirm — their yes, not the assistant's; a plain third call with the same arguments runs once at that price. A moved price is re-quoted, never charged.

入力スキーマ

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 200,
      "description": "A display label for this project, e.g. 'my-abacus-app'. Sanitized before use."
    },
    "files": {
      "minItems": 1,
      "maxItems": 1000,
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "path": {
            "type": "string",
            "minLength": 1,
            "description": "Relative path, e.g. 'src/index.ts'. No absolute paths, no '..', no backslashes."
          },
          "content": {
            "type": "string",
            "description": "The file's full text."
          },
          "encoding": {
            "description": "Omit or 'utf8' for text files. Any other value (e.g. 'base64') is rejected — text only in v1.",
            "type": "string"
          }
        },
        "required": [
          "path",
          "content"
        ]
      },
      "description": "Source files as { path, content }[] — not build output. At most 1000; over the internal per-audit cap, the highest-priority ones win."
    },
    "uploadGrant": {
      "description": "Optional: the id of an upload approval the account owner already confirmed. A large post without one is answered with a confirmation covering the files and the price.",
      "type": "string"
    },
    "confirmedCost": {
      "description": "COST CONFIRMATION. Omit on the first call; then send back the exact quoted `cost`.",
      "type": "object",
      "properties": {
        "kind": {
          "type": "string",
          "description": "The `kind` from the quoted cost, e.g. 'credits'."
        },
        "credits": {
          "type": "number",
          "description": "The `credits` number from the quoted cost."
        },
        "centicredits": {
          "description": "The `centicredits` integer from the quoted cost, if it carried one.",
          "type": "number"
        }
      },
      "required": [
        "kind",
        "credits"
      ]
    },
    "authorization": {
      "description": "HUMAN CONFIRMATION. The `authorization` id from the confirm-link answer, once the account owner has pressed Confirm. Single-use, short TTL.",
      "type": "string"
    },
    "fullScan": {
      "description": "True buys the wider Full Audit tier over the files you post, priced by pass count.",
      "type": "boolean"
    }
  },
  "required": [
    "name",
    "files"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢scan_source(name, files, uploadGrant)

Free nittim look: committed secrets and known CVEs over posted source files. No account, no key, no nittim credits. Hard evidence only: never scores, never a production verdict. Send SOURCE files, not build output (no node_modules, no dist, no binaries).

入力スキーマ

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 200,
      "description": "A display label for this project, e.g. 'my-abacus-app'. Sanitized before use."
    },
    "files": {
      "minItems": 1,
      "maxItems": 1000,
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "path": {
            "type": "string",
            "minLength": 1,
            "description": "Relative path, e.g. 'src/index.ts'. No absolute paths, no '..', no backslashes."
          },
          "content": {
            "type": "string",
            "description": "The file's full text."
          },
          "encoding": {
            "description": "Omit or 'utf8' for text files. Any other value (e.g. 'base64') is rejected — text only in v1.",
            "type": "string"
          }
        },
        "required": [
          "path",
          "content"
        ]
      },
      "description": "Source files as { path, content }[] — not build output. At most 1000; over the internal per-audit cap, the highest-priority ones win."
    },
    "uploadGrant": {
      "description": "Optional: the id of an upload approval the account owner already confirmed. A large post without one is answered with a confirmation covering the files and the price.",
      "type": "string"
    }
  },
  "required": [
    "name",
    "files"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢estimate_audit(repoUrl, githubToken, files, fullScan)

Price an audit before buying one: give a GitHub repository URL, or a manifest of paths and byte sizes — no file content, nothing uploaded — and get the tier (Audit or Full Audit), the pass count and the exact price. No account or key is needed: it never charges, runs no audit, calls no model and stores nothing. Signed in it also returns your credit balance and whether an unspent Audit covers the run; a guest quote omits both. `fullScan: true` prices Full Audit.

入力スキーマ

{
  "type": "object",
  "properties": {
    "repoUrl": {
      "description": "GitHub repository URL or owner/repo. Mutually exclusive with `files` — send one.",
      "type": "string",
      "minLength": 1
    },
    "githubToken": {
      "description": "Optional GitHub personal access token (read-only) for a private repo. Without one, a signed-in account with nittim's GitHub App installed at nittim.com for this repo still prices it — no token needed.",
      "type": "string"
    },
    "files": {
      "description": "A manifest of paths and sizes only, in place of `repoUrl` — the same set you would post. Over the cap the answer names it and how to trim. Send one or the other.",
      "minItems": 1,
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "path": {
            "type": "string",
            "minLength": 1,
            "description": "Relative path, e.g. 'src/index.ts'."
          },
          "bytes": {
            "type": "integer",
            "minimum": 0,
            "maximum": 9007199254740991,
            "description": "The file's byte size. This shape has no `content` — nothing is uploaded."
          }
        },
        "required": [
          "path",
          "bytes"
        ]
      }
    },
    "fullScan": {
      "description": "Price Full Audit (every eligible file, or a refusal with the reason when the selection is too large) instead of the default Audit.",
      "type": "boolean"
    }
  },
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢get_audit(id)

Retrieve a nittim audit by its UUID, at any stage: the finished markdown digest (verdict, scores, top findings) plus its report link, or — no error, nothing charged — that it is still running, or why it failed and what happened to the charge. Free. Reading needs the key of the account that owns the audit.

入力スキーマ

{
  "type": "object",
  "properties": {
    "id": {
      "type": "string",
      "format": "uuid",
      "pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$",
      "description": "The UUID of the saved audit, from the /report/{id} URL."
    }
  },
  "required": [
    "id"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
⚪verify_fix(auditId, findingKey, ref)

NEEDS A KEY: mint one at https://nittim.com/keys. Re-checks ONE finding from a finished audit against the repository's current code, or a commit named in the call, and answers fixed, still present, or undetermined — with the reason. It reads only the file that finding cites. Free, capped per day, and it moves no score or verdict: the report keeps recording what was true of the commit it ran on.

入力スキーマ

{
  "type": "object",
  "properties": {
    "auditId": {
      "type": "string",
      "format": "uuid",
      "pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$",
      "description": "The audit UUID, from its report link."
    },
    "findingKey": {
      "type": "string",
      "minLength": 1,
      "description": "The finding's stable key, as printed beside it in the report's findings list."
    },
    "ref": {
      "description": "A commit SHA or branch to check instead of the repository's current HEAD. Must be the audited commit or newer.",
      "type": "string"
    }
  },
  "required": [
    "auditId",
    "findingKey"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢list_modules

List every audit module nittim can run: the two deterministic scanners (secret scan + OSV dependency CVE check) and the LLM-reasoned checks. Returns each module's key, tier, and a plain-English description of what it checks. Each module's key identifies it for running individually.

入力スキーマ

{
  "type": "object",
  "properties": {},
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢get_loop

Returns the current text of nittim's free, tool-agnostic self-review checklist — the same content served at https://nittim.com/selfcheck.md. Reviews a codebase against the public shape of nittim's 13-category Priority Framework, plus a 14th on what the code gives away, and states the procedure for running it as a loop. No arguments. No key, no account and no charge — nothing here is sent anywhere.

入力スキーマ

{
  "type": "object",
  "properties": {},
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢describe_protocol(section)

How this server works, in full: how a paid call quotes and charges, the two audit tiers, the Nittim Loop and its reward rules and caps, and dispute guidance. Free, no key, no charge, no side effects — it reads static text and calls no model. `section` picks one page; omitted, it returns all of them.

入力スキーマ

{
  "type": "object",
  "properties": {
    "section": {
      "description": "Which page: money, tiers, loop, disputes, or all (the default).",
      "type": "string",
      "enum": [
        "money",
        "tiers",
        "loop",
        "disputes",
        "all"
      ]
    }
  },
  "$schema": "http://json-schema.org/draft-07/schema#"
}
⚪mint_key(keyName)

For a client that cannot sign in over OAuth: a short, one-time link to https://nittim.com/keys/claim/<token>. Opening it, signed in, mints a real nittim API key and shows it once — the key itself is NEVER returned by this tool or by any other MCP result. The link expires in a few minutes and works exactly once. Free.

入力スキーマ

{
  "type": "object",
  "properties": {
    "keyName": {
      "description": "Optional display name for the key that will be minted, e.g. 'my-cursor-key'. Defaults to 'API key'.",
      "type": "string",
      "maxLength": 80
    }
  },
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟡run_module(repoUrl, moduleKey, githubToken, confirmedCost, authorization)

Run ONE nittim audit module against a GitHub repository, never producing scores or a verdict. The two deterministic modules (secret-scan, dependency-cve) return scanner evidence directly, free, with nothing to confirm. Deep-tier modules make one focused model call, cost 5.03 credits each and follow the protocol below. NEEDS A KEY: mint one at https://nittim.com/keys. COSTS MONEY in three calls: the first quotes a price and charges nothing; a second with `confirmedCost` set to that exact price returns a one-time link for the ACCOUNT OWNER to confirm — their yes, not the assistant's; a plain third call with the same arguments runs once at that price. A moved price is re-quoted, never charged.

入力スキーマ

{
  "type": "object",
  "properties": {
    "repoUrl": {
      "type": "string",
      "minLength": 1,
      "description": "GitHub repository URL or owner/repo. A private repo needs a githubToken."
    },
    "moduleKey": {
      "type": "string",
      "minLength": 1,
      "description": "The module's key, e.g. 'secret-scan', 'dependency-cve', 'security', 'privacy', 'gdpr'."
    },
    "githubToken": {
      "description": "Optional read-only GitHub token. Without one, only public repos are reachable.",
      "type": "string"
    },
    "confirmedCost": {
      "description": "COST CONFIRMATION. Omit on the first call; then send back the exact quoted `cost`.",
      "type": "object",
      "properties": {
        "kind": {
          "type": "string",
          "description": "The `kind` from the quoted cost, e.g. 'credits'."
        },
        "credits": {
          "type": "number",
          "description": "The `credits` number from the quoted cost."
        },
        "centicredits": {
          "description": "The `centicredits` integer from the quoted cost, if it carried one.",
          "type": "number"
        }
      },
      "required": [
        "kind",
        "credits"
      ]
    },
    "authorization": {
      "description": "HUMAN CONFIRMATION. The `authorization` id from the confirm-link answer, once the account owner has pressed Confirm. Single-use, short TTL.",
      "type": "string"
    }
  },
  "required": [
    "repoUrl",
    "moduleKey"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟡judge_output(content, criteria, context, modelUnderTest, confirmedCost, ...)

Run a cross-vendor judge model over any text you post: code, a document, another model's output, anything. Returns findings + rationale ONLY — never a score, never a pass/fail verdict. Costs 5.03 credits. The judge always comes from a different vendor family than whatever produced the content, and the answer says which one ran. `modelUnderTest` names that family. NEEDS A KEY: mint one at https://nittim.com/keys. COSTS MONEY in three calls: the first quotes a price and charges nothing; a second with `confirmedCost` set to that exact price returns a one-time link for the ACCOUNT OWNER to confirm — their yes, not the assistant's; a plain third call with the same arguments runs once at that price. A moved price is re-quoted, never charged.

入力スキーマ

{
  "type": "object",
  "properties": {
    "content": {
      "type": "string",
      "minLength": 1,
      "maxLength": 100000,
      "description": "The text to judge — code, a document, another model's output. Up to ~100KB."
    },
    "criteria": {
      "description": "Optional — what to judge it against, e.g. 'correctness and security'.",
      "type": "string"
    },
    "context": {
      "description": "Optional — background the judge should know, e.g. what this content is for.",
      "type": "string"
    },
    "modelUnderTest": {
      "description": "Optional — which vendor family produced `content`, if it is itself a model's output. The judge that runs is always a different family than this names. Use 'unspecified' for anything that is not model output, or when the family is unknown.",
      "type": "string",
      "enum": [
        "anthropic",
        "openai",
        "unspecified"
      ]
    },
    "confirmedCost": {
      "description": "COST CONFIRMATION. Omit on the first call; then send back the exact quoted `cost`.",
      "type": "object",
      "properties": {
        "kind": {
          "type": "string",
          "description": "The `kind` from the quoted cost, e.g. 'credits'."
        },
        "credits": {
          "type": "number",
          "description": "The `credits` number from the quoted cost."
        },
        "centicredits": {
          "description": "The `centicredits` integer from the quoted cost, if it carried one.",
          "type": "number"
        }
      },
      "required": [
        "kind",
        "credits"
      ]
    },
    "authorization": {
      "description": "HUMAN CONFIRMATION. The `authorization` id from the confirm-link answer, once the account owner has pressed Confirm. Single-use, short TTL.",
      "type": "string"
    }
  },
  "required": [
    "content"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
⚪dispute_finding(auditId, findingKey, dimension, title, stance, ...)

NEEDS A KEY: mint one at https://nittim.com/keys. Records that a finding from a prior audit is wrong (stance:'dispute') or genuinely real (stance:'confirm'), backed by evidence from the repo. Free. A SIGNAL for owner triage — it never changes the audit's scores, verdict or stored report on its own. The finding is identified by its findingKey (from the digest), or by its exact dimension and title.

入力スキーマ

{
  "type": "object",
  "properties": {
    "auditId": {
      "type": "string",
      "format": "uuid",
      "pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$",
      "description": "The audit UUID, from its report link."
    },
    "findingKey": {
      "description": "The finding's stable key from the digest, if you have it (preferred over dimension+title).",
      "type": "string"
    },
    "dimension": {
      "description": "The finding's dimension, e.g. 'security' — required if findingKey is omitted.",
      "type": "string"
    },
    "title": {
      "description": "The finding's exact title — required if findingKey is omitted.",
      "type": "string"
    },
    "stance": {
      "type": "string",
      "enum": [
        "dispute",
        "confirm"
      ],
      "description": "'dispute' = this finding is wrong. 'confirm' = this finding is genuinely real."
    },
    "evidence": {
      "type": "object",
      "properties": {
        "file": {
          "type": "string",
          "minLength": 1,
          "description": "The file path your evidence points to."
        },
        "lines": {
          "description": "Line range, e.g. '42-58'.",
          "type": "string"
        },
        "snippet": {
          "description": "A short excerpt of the actual code supporting your stance.",
          "type": "string"
        },
        "explanation": {
          "type": "string",
          "minLength": 1,
          "description": "Why this finding is wrong or confirmed real, in your own words."
        }
      },
      "required": [
        "file",
        "explanation"
      ],
      "description": "What you can see in the repo that supports your stance."
    }
  },
  "required": [
    "auditId",
    "stance",
    "evidence"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢report_loop(repo_hash, client_name, client_version, repo_size_bucket, convergence, ...)

NEEDS A KEY: mint one at https://nittim.com/keys. Records anonymised counts from a Nittim Loop the developer has finished and agreed to send: pass numbers, a findings-by-category tally, a fixed count, and whether each pass was clean. Counts only — never a title, file path or snippet. Nothing is charged, and an eligible report can earn a credit reward (rules and caps: see describe_protocol). Reporting the same repo again updates the existing record; the reply says which happened. Results appear at https://nittim.com/loop.

入力スキーマ

{
  "type": "object",
  "properties": {
    "repo_hash": {
      "type": "string",
      "pattern": "^[0-9a-f]{64}$",
      "description": "sha256 of the repository's canonical identity (the lowercased 'owner/repo', or a stable local fingerprint) — never the repo name itself. nittim never sees the name."
    },
    "client_name": {
      "description": "Your own name — omit to read it from the MCP connection instead.",
      "type": "string",
      "maxLength": 64
    },
    "client_version": {
      "description": "Your own version string, if you have one.",
      "type": "string",
      "maxLength": 64
    },
    "repo_size_bucket": {
      "type": "string",
      "enum": [
        "xs",
        "s",
        "m",
        "l",
        "xl"
      ],
      "description": "A rough size bucket for the repo you looped over."
    },
    "convergence": {
      "description": "Optional: 'converged' (two consecutive clean passes) or 'cap_reached' (stopped for any other reason). Omit if unsure — the read from `passes` is derived either way.",
      "type": "string",
      "enum": [
        "converged",
        "cap_reached"
      ]
    },
    "swept": {
      "description": "Optional: was the CLASS swept — a guard, lint rule or exhaustiveness check that makes a new instance loud — rather than only the instances a pass named? Never derived, never changes the reward. On a repeat report, omitting it keeps the last answer; `false` withdraws it.",
      "type": "boolean"
    },
    "mode": {
      "description": "Optional: 'one_shot' (every lens sweeps the whole tree first, then one fix wave, then a short convergence loop) or 'serial' (one lens or area per pass, fixing between passes).",
      "type": "string",
      "enum": [
        "one_shot",
        "serial"
      ]
    },
    "first_wave_lenses": {
      "description": "Optional, with mode 'one_shot' only: how many lenses ran in parallel on pass 1.",
      "type": "integer",
      "exclusiveMinimum": 0,
      "maximum": 100
    },
    "passes": {
      "minItems": 1,
      "maxItems": 100,
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "n": {
            "type": "integer",
            "exclusiveMinimum": 0,
            "maximum": 9007199254740991,
            "description": "This pass's number, starting at 1."
          },
          "findings": {
            "maxItems": 13,
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "category": {
                  "type": "string",
                  "enum": [
                    "security",
                    "privacy",
                    "reliability",
                    "code_quality",
                    "ai_risk",
                    "performance",
                    "devops",
                    "data",
                    "business",
                    "devex",
                    "accessibility",
                    "observability",
                    "maintainability"
                  ]
                },
                "critical": {
                  "default": 0,
                  "type": "integer",
                  "minimum": 0,
                  "maximum": 9007199254740991
                },
                "high": {
                  "default": 0,
                  "type": "integer",
                  "minimum": 0,
                  "maximum": 9007199254740991
                },
                "medium": {
                  "default": 0,
                  "type": "integer",
                  "minimum": 0,
                  "maximum": 9007199254740991
                },
                "low": {
                  "default": 0,
                  "type": "integer",
                  "minimum": 0,
                  "maximum": 9007199254740991
                }
              },
              "required": [
                "category"
              ],
              "additionalProperties": false
            },
            "description": "Findings this pass named — one entry per category with something to report; omit a category that found nothing. Each count defaults to 0 when omitted."
          },
          "fixed": {
            "type": "integer",
            "minimum": 0,
            "maximum": 9007199254740991,
            "description": "How many findings this pass fixed."
          },
          "clean": {
            "type": "boolean",
            "description": "True iff this pass found nothing new."
          }
        },
        "required": [
          "n",
          "fixed",
          "clean"
        ],
        "additionalProperties": false
      },
      "description": "One entry per pass you actually ran, in order."
    }
  },
  "required": [
    "repo_hash",
    "repo_size_bucket",
    "passes"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟡preview_upload(name, files)

NEEDS A KEY: mint one at https://nittim.com/keys. Send the paths and sizes of the files you would post — no content leaves your machine to ask this — and get back the list, the byte count, and a link for the account owner to approve it. Free. The approval covers that file list and no other, and a paid audit's own confirmation already covers the file list beside the price, so approving ahead of time is optional.

入力スキーマ

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "minLength": 1,
      "maxLength": 200,
      "description": "A display label for this project, e.g. 'my-abacus-app'. Sanitized before use."
    },
    "files": {
      "minItems": 1,
      "maxItems": 1000,
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "path": {
            "type": "string",
            "minLength": 1,
            "description": "Relative path, e.g. 'src/index.ts'."
          },
          "bytes": {
            "type": "integer",
            "minimum": 0,
            "maximum": 9007199254740991,
            "description": "The file's size in bytes. No content."
          }
        },
        "required": [
          "path",
          "bytes"
        ]
      },
      "description": "Paths and sizes only — the same set you would post. Never file content."
    }
  },
  "required": [
    "name",
    "files"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}

コミュニティ

このサーバーを評価する

エビデンス

最近の観測

検証済みバージョンは記録されていませんツール 15 件
検証済みバージョンは記録されていませんツール 15 件