An Automated Code Security Auditing AI Agent on the Mainnet
- ✓Open-source license (MIT)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Documented (README)
git clone https://github.com/renaat-s/pyresec-agent && cp pyresec-agent/*.md ~/.claude/agents/Subagents overview
# PYRESEC — AI Code Security Engine
> Autonomous SAST/SCA security auditing via x402 USDC micropayments on Base. No subscriptions. No accounts. Just code in, findings out.
[](https://basescan.org)
[](https://x402.org)
[](https://modelcontextprotocol.io)
[](https://pyresec.io/license)
## Live Instance
| Endpoint | URL |
|----------|-----|
| **Landing** | [pyresec-agent-519576377065.us-central1.run.app](https://pyresec-agent-519576377065.us-central1.run.app/docs) |
| **Swagger UI** | [/swagger](https://pyresec-agent-519576377065.us-central1.run.app/swagger) |
| **Health** | [/health](https://pyresec-agent-519576377065.us-central1.run.app/health) |
| **MCP Manifest** | [/mcp/manifest.json](https://pyresec-agent-519576377065.us-central1.run.app/mcp/manifest.json) |
| **OpenAPI Spec** | [/openapi.json](https://pyresec-agent-519576377065.us-central1.run.app/openapi.json) |
---
## Quick Start
### Option 1: x402 Python Client (Recommended)
```bash
pip install x402
```
```python
import x402
client = x402.Client(wallet_key="your-base-private-key")
response = client.post(
"https://pyresec-agent-519576377065.us-central1.run.app/v1/audit/quick-scan",
json={"code": "def login(u,p): return db.query(f\"SELECT * FROM users WHERE name={u} AND pass={p}\")"}
)
print(response.json())
```
### Option 2: curl (Manual x402 Flow)
```bash
# Step 1: Send request (returns 402 with payment requirements)
curl -X POST https://pyresec-agent-519576377065.us-central1.run.app/v1/audit/quick-scan \
-H "Content-Type: application/json" \
-d '{"code": "def login(u,p): return db.query(f\"SELECT * FROM users WHERE name={u} AND pass={p}\")"}'
# Step 2: Pay $0.01 USDC on Base using x402 protocol
# Step 3: Resubmit with X-PAYMENT header
curl -X POST https://pyresec-agent-519576377065.us-central1.run.app/v1/audit/quick-scan \
-H "Content-Type: application/json" \
-H "X-PAYMENT: <payment-proof>" \
-d '{"code": "..."}'
```
### Option 3: GitHub Action (CI/CD)
```yaml
- name: PYRESEC Security Scan
uses: nanoclone-ltd/pyresec-scan-action@main
with:
code-path: ./src
tier: quick-scan
x402-wallet-key: ${{ secrets.X402_WALLET_KEY }}
```
### Option 4: MCP-Compatible Agent (Claude, Cursor, etc.)
PYRESEC is a registered MCP tool. Any MCP-compatible client discovers it automatically:
```json
{
"mcpServers": {
"pyresec": {
"url": "https://pyresec-agent-519576377065.us-central1.run.app/mcp"
}
}
}
```
---
## Service Tiers
| Tier | Price | Endpoint | Description | Model |
|------|-------|----------|-------------|-------|
| **Quick Scan** | $0.01 | `POST /v1/audit/quick-scan` | Top 3 findings by severity, CWE IDs, line numbers | qwen3.6-27b |
| **Deep Audit** | $0.50 | `POST /v1/audit/deep-repo` | OWASP Top 10, SCA dependency scanning, logic flaws, gas optimization | qwen3.8-27b |
| **Remediation** | $5.00 | `POST /v1/audit/remediate` | Full patched code with change explanations and security notes | qwen3.8-27b |
---
## x402 Payment Flow
PYRESEC uses the [x402 protocol](https://x402.org) for permissionless micropayments on Base. No accounts, no API keys, no subscriptions.
```
┌──────────┐ POST /v1/audit/quick-scan ┌──────────┐
│ Client │ ───────────────────────────────▶ │ PYRESEC │
│ (x402) │ ◀──── 402 Payment Required ───── │ Agent │
│ │ { amount, network, to } │ │
│ │ │ │
│ │ ──── X-PAYMENT (proof) ─────────▶ │ │
│ │ ◀──── 200 + Scan Results ──────── │ │
└──────────┘ └──────────┘
```
**How it works:**
1. Client sends a POST request to any audit endpoint
2. PYRESEC returns `402 Payment Required` with payment details (amount, recipient address, network)
3. Client signs and submits a USDC transfer on Base mainnet
4. Client resubmits the original request with the `X-PAYMENT` header containing the payment proof
5. PYRESEC verifies the payment on-chain and returns the scan results
**No wallet?** Use the [x402 Python SDK](https://github.com/coinbase/x402) or any x402-compatible client.
---
## Architecture
```
┌─────────────────────────────────┐
│ Client Layer │
│ x402 SDK / curl / MCP Client │
└──────────────┬──────────────────┘
│
┌─────────▼─────────┐
│ FastAPI Server │
│ (Cloud Run) │
│ │
│ ┌──────────────┐ │
│ │ x402 Payment │ │
│ │ Middleware │ │
│ └──────┬───────┘ │
└─────────┼──────────┘
│
┌───────────────────┼───────────────────┐
│ │ │
┌─────────▼─────────┐ ┌───────▼───────┐ ┌───────▼───────┐
│ Agent Controller │ │ Population │ │ Wallet │
│ (SAST + LLM) │ │ Controller │ │ Interface │
└─────────┬─────────┘ └───────────────┘ └───────────────┘
│
┌─────────▼─────────┐
│ Groq LLM │
│ (qwen models) │
└─────────┬─────────┘
│
┌─────────▼─────────┐
│ Security Findings │
│ JSON Response │
└───────────────────┘
```
---
## Supported Vulnerability Types
| # | Type | CWE | Severity |
|---|------|-----|----------|
| 1 | SQL Injection | CWE-89 | HIGH |
| 2 | Cross-Site Scripting (XSS) | CWE-79 | HIGH |
| 3 | Command Injection | CWE-78 | CRITICAL |
| 4 | Path Traversal | CWE-22 | MEDIUM |
| 5 | Hardcoded Secrets | CWE-798 | CRITICAL |
| 6 | Weak Cryptography | CWE-327 | MEDIUM |
| 7 | SSRF | CWE-918 | HIGH |
| 8 | Insecure Deserialization | CWE-502 | HIGH |
| 9 | Authentication Bypass | CWE-287 | CRITICAL |
| 10 | Improper Input Validation | CWE-20 | MEDIUM |
---
## For AI Agents (MCP Integration)
PYRESEC is discoverable by any MCP-compatible agent. When an agent needs to audit code, it can find PYRESEC automatically through:
- **MCP Registry**: `registry.modelcontextprotocol.io`
- **Smithery.ai**: `smithery.ai/server/@renaat-s/pyresec-agent`
- **Direct manifest**: `/mcp/manifest.json`
### Tool Definitions
| Tool | Description | Cost |
|------|-------------|------|
| `quick_scan` | Fast SAST scan, top 3 findings by severity with CWE IDs | $0.01 USDC |
| `deep_audit` | Full OWASP Top 10, SCA, logic flaws, gas optimization | $0.50 USDC |
| `remediate_code` | Auto-patched code with change explanations, ready for PR | $5.00 USDC |
### Agent Discovery Flow
```
1. Agent queries MCP Registry for "security audit" tools
2. PYRESEC appears in results with tool schemas
3. Agent calls quick_scan with source code
4. PYRESEC returns 402 with x402 payment requirements
5. Agent's x402 wallet pays USDC on Base
6. Agent resubmits with payment proof
7. PYRESEC returns findings as structured JSON
```
---
## Self-Sustaining Agent
PYRESEC runs as an autonomous agent on Base Mainnet:
- **Heartbeat** every 30 min — checks balance, reports health
- **Death** — shuts down if balance < $0.05
- **Replication** — sends 50% surplus to dev wallet when balance > $20
- **Kill switch** — admin can halt all instances remotely
---
## Deployment
### Docker
```bash
docker build -t pyresec-agent .
docker run -p 8080:8080 --env-file .env pyresec-agent
```
### Google Cloud Run
```bash
gcloud run deploy pyresec-agent \
--source . \
--platform managed \
--region us-central1 \
--allow-unauthenticated \
--set-env-vars "CDP_WALLET_SECRET=$CDP_WALLET_SECRET,GROQ_API_KEY=$GROQ_API_KEY"
```
---
## Company
**NanoClone Life Sciences Ltd.** (UK)
Website: [nanoclonesystems.com](https://nanoclonesystems.com/)
## License
Proprietary. See [LICENSE](LICENSE) for details.
What people ask about pyresec-agent
What is renaat-s/pyresec-agent?
+
renaat-s/pyresec-agent is subagents for the Claude AI ecosystem. An Automated Code Security Auditing AI Agent on the Mainnet It has 0 GitHub stars and its last recorded update is dated 2026-09-27.
How do I install pyresec-agent?
+
You can install pyresec-agent by cloning the repository (https://github.com/renaat-s/pyresec-agent) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is renaat-s/pyresec-agent safe to use?
+
Our security agent has analyzed renaat-s/pyresec-agent and assigned a Trust Score of 87/100 (tier: Trusted). See the full breakdown of passed checks and flags on this page.
Who maintains renaat-s/pyresec-agent?
+
renaat-s/pyresec-agent is maintained by renaat-s. The last recorded GitHub activity is dated 2026-09-27, with 0 open issues.
Are there alternatives to pyresec-agent?
+
Yes. On ClaudeWave you can browse similar subagents at /categories/agents, sorted by popularity or recent activity.
Deploy pyresec-agent to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/renaat-s-pyresec-agent)<a href="https://claudewave.com/repo/renaat-s-pyresec-agent"><img src="https://claudewave.com/api/badge/renaat-s-pyresec-agent" alt="Featured on ClaudeWave: renaat-s/pyresec-agent" width="320" height="64" /></a>More Subagents
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
The agent that grows with you
Java 面试 & 后端通用面试指南,覆盖计算机基础、数据库、分布式、高并发、系统设计与 AI 应用开发
Build Agentic workflows, RAG pipelines, with rich AI model and tool support on one collaborative workspace. Deploy on cloud, VPC, or self-hosted, so teams move from prototype to production without rebuilding the stack.
The agent engineering platform.
Makes your AI agent think like the laziest senior dev in the room. The best code is the code you never wrote.