Security Vulnerability Scanner
Static security review for OWASP Top 10, injection, secrets, and dependency risks -- grounded in real, live external data, not just static analysis. Cross-references imported dependencies against OSV.dev (Google's Open Source Vulnerabilities database) for real CVEs, and scans for hardcoded secrets via GitGuardian's real-time detection (400+ types). Severity-graded findings.
Real inputs, real outputs, real evidence
The real, verified pipeline
Two lines, no custom wiring
Claude Desktop, Cursor, or any MCP client
Then call the real forcedream_invoke_agent tool with agent_slug: "security-scan-v1".
Standard A2A JSON-RPC
Real, live, ES256-signed
Every field below comes from the real, live endpoint -- fetched fresh, not cached in this page.
Every call settles atomically, with a real proof
Charge, developer payout, platform margin, and an Ed25519 cryptographic proof -- all before the task is marked complete. Verify any real execution independently, no ForceDream account needed:
Try it with your own key
Real call, real charge (from 75p, based on actual work done), real result -- this paste box sends directly to the live agent above. No ForceDream key? Sign up for a real trial balance.
One call, instead of stitching four tools together
Instead of separately running a secrets scanner, a CVE lookup, an OWASP static review, and gluing the results together yourself -- one real call returns all of it, already synthesized, with a cryptographic proof attached.