Server definition
- Hash
- sha256:f06961ffb39d0e422401bf159dfbbe4fc7c5cef41f8e2817e2bdc9880d811524
- What it is
- What a remote MCP server returned when asked what it offers: 15 tools
The blob, as servednamed by its sha256
{
"instructions": "## Keys\nPaid tools need a nittim key: mint one at https://nittim.com/keys and send it as the bearer token in your MCP server config. `scan_source`, `list_modules`, `estimate_audit` and `describe_protocol` work free with no key. A paid tool called with no key may answer with a 401 sign-in challenge instead of a tool result; a client with no OAuth of its own sends `x-nittim-auth: none` in its server config to get a plain tool error instead.\n\n## Spending money (every paid tool, identical protocol)\nPrice it first, free and keyless, with `estimate_audit` — same `cost` object, nothing runs or charges. Show that price to the person you are working for. The first call to a paid tool NEVER runs and NEVER charges either — it answers with the price as a `cost` object, in `structuredContent` and as a fenced JSON block of the exact arguments to send back. Call again with `confirmedCost` set to the exact `cost` you were quoted — this second, price-confirming call doesn't have to follow an earlier quote-only one: sending `confirmedCost` on your very first call to a paid tool reaches the same step directly. A price that moved is refused and re-quoted, never charged. Unless the key was deliberately made autonomous, that second call answers with a one-time link the ACCOUNT OWNER opens and confirms — their yes, never yours, and never inferred. A plain third call with the same arguments then runs once at that price, or set `authorization` to the id from the second answer. Repeating the second call while you wait is free and safe.\n\n## Two tiers\n`audit_repo` and `audit_source` default to Audit: one structured pass over the highest-signal source. `fullScan: true` buys Full Audit — every eligible source file, priced by pass count — and `estimate_audit` prices either without charging or running anything.\n\n## How audits are delivered\n`audit_repo` and `audit_source` submit and return an id immediately; nothing runs inside the call. The report lands Usually within 15 minutes* — poll `get_audit` with the id to read it. * Most reports land within 15 minutes. Worst case, 24 hours. Subscribers can run `audit_source` on their own Anthropic key via the `x-nittim-anthropic-key` header (BYOK Pro), which returns its report in the call.\n\n## Before the AI audit\nCall `get_loop` — free, no key — and run it on a repository you own before spending on an audit. An AI audit is worth more on fixed code, so the Nittim Loop comes first — fix, re-run, and stop at two consecutive passes that find nothing new. The AI audit is the sensible step from there. On a repository you own, running this costs nothing and sends nothing — fix and commit before spending on an AI audit. Claude Code users can install it as the nittim-loop skill from github.com/ilanwolberger/nittim-mcp instead of fetching https://nittim.com/selfcheck.md by hand each time. \n\n## The full protocol\n`describe_protocol` is free, needs no key, and returns this in full detail — the money protocol, the tiers, the Nittim Loop and its reward rules, and dispute guidance.\n\n## Server version\nThis is nittim's MCP server, version 0.2.0+6125d24. If tools suddenly error or look missing after they worked before, the server was likely updated — reconnect or reload the nittim MCP connection in your client and try again; nothing is lost and nothing was charged. More cases — a 401, a long-running audit, a \"not found\" on an id you own — are answered at https://nittim.com/agents.md under Troubleshooting.\n",
"tools": [
{
"description": "Paid nittim AI audit of a GitHub repository: one structured pass over the highest-signal source; the only tool here that returns scores and a verdict. Answers with the audit's id, not the report. `fullScan: true` buys the wider Full Audit tier. NEEDS A KEY: mint one at https://nittim.com/keys. COSTS MONEY in three calls: the first quotes a price and charges nothing; a second with `confirmedCost` set to that exact price returns a one-time link for the ACCOUNT OWNER to confirm — their yes, not the assistant's; a plain third call with the same arguments runs once at that price. A moved price is re-quoted, never charged.DELIVERED AS A BATCH: the report lands Usually within 15 minutes*. * Most reports land within 15 minutes. Worst case, 24 hours. ",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"authorization": {
"description": "HUMAN CONFIRMATION. The `authorization` id from the confirm-link answer, once the account owner has pressed Confirm. Single-use, short TTL.",
"type": "string"
},
"confirmedCost": {
"description": "COST CONFIRMATION. Omit on the first call; then send back the exact quoted `cost`.",
"properties": {
"centicredits": {
"description": "The `centicredits` integer from the quoted cost, if it carried one.",
"type": "number"
},
"credits": {
"description": "The `credits` number from the quoted cost.",
"type": "number"
},
"kind": {
"description": "The `kind` from the quoted cost, e.g. 'credits'.",
"type": "string"
}
},
"required": [
"kind",
"credits"
],
"type": "object"
},
"deployedUrl": {
"description": "Optional URL of this repository's live deployment, for an origin the account owner actually operates. When set, the audit adds one bounded, READ-ONLY fetch pass against it and reports drift between the deployed artifact and the audited commit. Redirects are never followed; private addresses are refused.",
"type": "string"
},
"fullScan": {
"description": "True buys the wider Full Audit tier: every eligible source file, priced by pass count.",
"type": "boolean"
},
"githubToken": {
"description": "Optional read-only GitHub token for a private repo. Without one, only public repos are reachable — unless the account has installed nittim's GitHub App at nittim.com for this repo, in which case a private repo works with no token at all.",
"type": "string"
},
"payInstead": {
"description": "True pays credits now instead of queuing for the daily free-audit budget to reopen, skipping the covered (Audit) entitlement even when it would otherwise be free.",
"type": "boolean"
},
"repoUrl": {
"description": "GitHub repository URL or owner/repo. A private repo needs a githubToken, unless the account has installed nittim's GitHub App at nittim.com for it.",
"minLength": 1,
"type": "string"
}
},
"required": [
"repoUrl"
],
"type": "object"
},
"name": "audit_repo",
"outputSchema": null
},
{
"description": "Paid nittim AI audit of source files you post, for a project with no GitHub remote. Send SOURCE files, not build output — no node_modules or dist. On nittim's own key this answers with the audit's id; the report lands Usually within 15 minutes*. * Most reports land within 15 minutes. Worst case, 24 hours. On your own key (BYOK Pro) the report comes back in this call instead. Costs 5.14 credits (a paid+subscribed org's included allowance, an unspent Audit, then prepaid credits), always saved as a PRIVATE report. `fullScan: true` buys the wider Full Audit tier. NEEDS A KEY: mint one at https://nittim.com/keys. COSTS MONEY in three calls: the first quotes a price and charges nothing; a second with `confirmedCost` set to that exact price returns a one-time link for the ACCOUNT OWNER to confirm — their yes, not the assistant's; a plain third call with the same arguments runs once at that price. A moved price is re-quoted, never charged.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"authorization": {
"description": "HUMAN CONFIRMATION. The `authorization` id from the confirm-link answer, once the account owner has pressed Confirm. Single-use, short TTL.",
"type": "string"
},
"confirmedCost": {
"description": "COST CONFIRMATION. Omit on the first call; then send back the exact quoted `cost`.",
"properties": {
"centicredits": {
"description": "The `centicredits` integer from the quoted cost, if it carried one.",
"type": "number"
},
"credits": {
"description": "The `credits` number from the quoted cost.",
"type": "number"
},
"kind": {
"description": "The `kind` from the quoted cost, e.g. 'credits'.",
"type": "string"
}
},
"required": [
"kind",
"credits"
],
"type": "object"
},
"files": {
"description": "Source files as { path, content }[] — not build output. At most 1000; over the internal per-audit cap, the highest-priority ones win.",
"items": {
"properties": {
"content": {
"description": "The file's full text.",
"type": "string"
},
"encoding": {
"description": "Omit or 'utf8' for text files. Any other value (e.g. 'base64') is rejected — text only in v1.",
"type": "string"
},
"path": {
"description": "Relative path, e.g. 'src/index.ts'. No absolute paths, no '..', no backslashes.",
"minLength": 1,
"type": "string"
}
},
"required": [
"path",
"content"
],
"type": "object"
},
"maxItems": 1000,
"minItems": 1,
"type": "array"
},
"fullScan": {
"description": "True buys the wider Full Audit tier over the files you post, priced by pass count.",
"type": "boolean"
},
"name": {
"description": "A display label for this project, e.g. 'my-abacus-app'. Sanitized before use.",
"maxLength": 200,
"minLength": 1,
"type": "string"
},
"uploadGrant": {
"description": "Optional: the id of an upload approval the account owner already confirmed. A large post without one is answered with a confirmation covering the files and the price.",
"type": "string"
}
},
"required": [
"name",
"files"
],
"type": "object"
},
"name": "audit_source",
"outputSchema": null
},
{
"description": "How this server works, in full: how a paid call quotes and charges, the two audit tiers, the Nittim Loop and its reward rules and caps, and dispute guidance. Free, no key, no charge, no side effects — it reads static text and calls no model. `section` picks one page; omitted, it returns all of them.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"section": {
"description": "Which page: money, tiers, loop, disputes, or all (the default).",
"enum": [
"money",
"tiers",
"loop",
"disputes",
"all"
],
"type": "string"
}
},
"type": "object"
},
"name": "describe_protocol",
"outputSchema": null
},
{
"description": "NEEDS A KEY: mint one at https://nittim.com/keys. Records that a finding from a prior audit is wrong (stance:'dispute') or genuinely real (stance:'confirm'), backed by evidence from the repo. Free. A SIGNAL for owner triage — it never changes the audit's scores, verdict or stored report on its own. The finding is identified by its findingKey (from the digest), or by its exact dimension and title.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"auditId": {
"description": "The audit UUID, from its report link.",
"format": "uuid",
"pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$",
"type": "string"
},
"dimension": {
"description": "The finding's dimension, e.g. 'security' — required if findingKey is omitted.",
"type": "string"
},
"evidence": {
"description": "What you can see in the repo that supports your stance.",
"properties": {
"explanation": {
"description": "Why this finding is wrong or confirmed real, in your own words.",
"minLength": 1,
"type": "string"
},
"file": {
"description": "The file path your evidence points to.",
"minLength": 1,
"type": "string"
},
"lines": {
"description": "Line range, e.g. '42-58'.",
"type": "string"
},
"snippet": {
"description": "A short excerpt of the actual code supporting your stance.",
"type": "string"
}
},
"required": [
"file",
"explanation"
],
"type": "object"
},
"findingKey": {
"description": "The finding's stable key from the digest, if you have it (preferred over dimension+title).",
"type": "string"
},
"stance": {
"description": "'dispute' = this finding is wrong. 'confirm' = this finding is genuinely real.",
"enum": [
"dispute",
"confirm"
],
"type": "string"
},
"title": {
"description": "The finding's exact title — required if findingKey is omitted.",
"type": "string"
}
},
"required": [
"auditId",
"stance",
"evidence"
],
"type": "object"
},
"name": "dispute_finding",
"outputSchema": null
},
{
"description": "Price an audit before buying one: give a GitHub repository URL, or a manifest of paths and byte sizes — no file content, nothing uploaded — and get the tier (Audit or Full Audit), the pass count and the exact price. No account or key is needed: it never charges, runs no audit, calls no model and stores nothing. Signed in it also returns your credit balance and whether an unspent Audit covers the run; a guest quote omits both. `fullScan: true` prices Full Audit.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"files": {
"description": "A manifest of paths and sizes only, in place of `repoUrl` — the same set you would post. Over the cap the answer names it and how to trim. Send one or the other.",
"items": {
"properties": {
"bytes": {
"description": "The file's byte size. This shape has no `content` — nothing is uploaded.",
"maximum": 9007199254740991,
"minimum": 0,
"type": "integer"
},
"path": {
"description": "Relative path, e.g. 'src/index.ts'.",
"minLength": 1,
"type": "string"
}
},
"required": [
"path",
"bytes"
],
"type": "object"
},
"minItems": 1,
"type": "array"
},
"fullScan": {
"description": "Price Full Audit (every eligible file, or a refusal with the reason when the selection is too large) instead of the default Audit.",
"type": "boolean"
},
"githubToken": {
"description": "Optional GitHub personal access token (read-only) for a private repo. Without one, a signed-in account with nittim's GitHub App installed at nittim.com for this repo still prices it — no token needed.",
"type": "string"
},
"repoUrl": {
"description": "GitHub repository URL or owner/repo. Mutually exclusive with `files` — send one.",
"minLength": 1,
"type": "string"
}
},
"type": "object"
},
"name": "estimate_audit",
"outputSchema": null
},
{
"description": "Retrieve a nittim audit by its UUID, at any stage: the finished markdown digest (verdict, scores, top findings) plus its report link, or — no error, nothing charged — that it is still running, or why it failed and what happened to the charge. Free. Reading needs the key of the account that owns the audit.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"id": {
"description": "The UUID of the saved audit, from the /report/{id} URL.",
"format": "uuid",
"pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$",
"type": "string"
}
},
"required": [
"id"
],
"type": "object"
},
"name": "get_audit",
"outputSchema": null
},
{
"description": "Returns the current text of nittim's free, tool-agnostic self-review checklist — the same content served at https://nittim.com/selfcheck.md. Reviews a codebase against the public shape of nittim's 13-category Priority Framework, plus a 14th on what the code gives away, and states the procedure for running it as a loop. No arguments. No key, no account and no charge — nothing here is sent anywhere.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {},
"type": "object"
},
"name": "get_loop",
"outputSchema": null
},
{
"description": "Run a cross-vendor judge model over any text you post: code, a document, another model's output, anything. Returns findings + rationale ONLY — never a score, never a pass/fail verdict. Costs 5.03 credits. The judge always comes from a different vendor family than whatever produced the content, and the answer says which one ran. `modelUnderTest` names that family. NEEDS A KEY: mint one at https://nittim.com/keys. COSTS MONEY in three calls: the first quotes a price and charges nothing; a second with `confirmedCost` set to that exact price returns a one-time link for the ACCOUNT OWNER to confirm — their yes, not the assistant's; a plain third call with the same arguments runs once at that price. A moved price is re-quoted, never charged.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"authorization": {
"description": "HUMAN CONFIRMATION. The `authorization` id from the confirm-link answer, once the account owner has pressed Confirm. Single-use, short TTL.",
"type": "string"
},
"confirmedCost": {
"description": "COST CONFIRMATION. Omit on the first call; then send back the exact quoted `cost`.",
"properties": {
"centicredits": {
"description": "The `centicredits` integer from the quoted cost, if it carried one.",
"type": "number"
},
"credits": {
"description": "The `credits` number from the quoted cost.",
"type": "number"
},
"kind": {
"description": "The `kind` from the quoted cost, e.g. 'credits'.",
"type": "string"
}
},
"required": [
"kind",
"credits"
],
"type": "object"
},
"content": {
"description": "The text to judge — code, a document, another model's output. Up to ~100KB.",
"maxLength": 100000,
"minLength": 1,
"type": "string"
},
"context": {
"description": "Optional — background the judge should know, e.g. what this content is for.",
"type": "string"
},
"criteria": {
"description": "Optional — what to judge it against, e.g. 'correctness and security'.",
"type": "string"
},
"modelUnderTest": {
"description": "Optional — which vendor family produced `content`, if it is itself a model's output. The judge that runs is always a different family than this names. Use 'unspecified' for anything that is not model output, or when the family is unknown.",
"enum": [
"anthropic",
"openai",
"unspecified"
],
"type": "string"
}
},
"required": [
"content"
],
"type": "object"
},
"name": "judge_output",
"outputSchema": null
},
{
"description": "List every audit module nittim can run: the two deterministic scanners (secret scan + OSV dependency CVE check) and the LLM-reasoned checks. Returns each module's key, tier, and a plain-English description of what it checks. Each module's key identifies it for running individually.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {},
"type": "object"
},
"name": "list_modules",
"outputSchema": null
},
{
"description": "For a client that cannot sign in over OAuth: a short, one-time link to https://nittim.com/keys/claim/<token>. Opening it, signed in, mints a real nittim API key and shows it once — the key itself is NEVER returned by this tool or by any other MCP result. The link expires in a few minutes and works exactly once. Free.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"keyName": {
"description": "Optional display name for the key that will be minted, e.g. 'my-cursor-key'. Defaults to 'API key'.",
"maxLength": 80,
"type": "string"
}
},
"type": "object"
},
"name": "mint_key",
"outputSchema": null
},
{
"description": "NEEDS A KEY: mint one at https://nittim.com/keys. Send the paths and sizes of the files you would post — no content leaves your machine to ask this — and get back the list, the byte count, and a link for the account owner to approve it. Free. The approval covers that file list and no other, and a paid audit's own confirmation already covers the file list beside the price, so approving ahead of time is optional.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"files": {
"description": "Paths and sizes only — the same set you would post. Never file content.",
"items": {
"properties": {
"bytes": {
"description": "The file's size in bytes. No content.",
"maximum": 9007199254740991,
"minimum": 0,
"type": "integer"
},
"path": {
"description": "Relative path, e.g. 'src/index.ts'.",
"minLength": 1,
"type": "string"
}
},
"required": [
"path",
"bytes"
],
"type": "object"
},
"maxItems": 1000,
"minItems": 1,
"type": "array"
},
"name": {
"description": "A display label for this project, e.g. 'my-abacus-app'. Sanitized before use.",
"maxLength": 200,
"minLength": 1,
"type": "string"
}
},
"required": [
"name",
"files"
],
"type": "object"
},
"name": "preview_upload",
"outputSchema": null
},
{
"description": "NEEDS A KEY: mint one at https://nittim.com/keys. Records anonymised counts from a Nittim Loop the developer has finished and agreed to send: pass numbers, a findings-by-category tally, a fixed count, and whether each pass was clean. Counts only — never a title, file path or snippet. Nothing is charged, and an eligible report can earn a credit reward (rules and caps: see describe_protocol). Reporting the same repo again updates the existing record; the reply says which happened. Results appear at https://nittim.com/loop.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"client_name": {
"description": "Your own name — omit to read it from the MCP connection instead.",
"maxLength": 64,
"type": "string"
},
"client_version": {
"description": "Your own version string, if you have one.",
"maxLength": 64,
"type": "string"
},
"convergence": {
"description": "Optional: 'converged' (two consecutive clean passes) or 'cap_reached' (stopped for any other reason). Omit if unsure — the read from `passes` is derived either way.",
"enum": [
"converged",
"cap_reached"
],
"type": "string"
},
"first_wave_lenses": {
"description": "Optional, with mode 'one_shot' only: how many lenses ran in parallel on pass 1.",
"exclusiveMinimum": 0,
"maximum": 100,
"type": "integer"
},
"mode": {
"description": "Optional: 'one_shot' (every lens sweeps the whole tree first, then one fix wave, then a short convergence loop) or 'serial' (one lens or area per pass, fixing between passes).",
"enum": [
"one_shot",
"serial"
],
"type": "string"
},
"passes": {
"description": "One entry per pass you actually ran, in order.",
"items": {
"additionalProperties": false,
"properties": {
"clean": {
"description": "True iff this pass found nothing new.",
"type": "boolean"
},
"findings": {
"description": "Findings this pass named — one entry per category with something to report; omit a category that found nothing. Each count defaults to 0 when omitted.",
"items": {
"additionalProperties": false,
"properties": {
"category": {
"enum": [
"security",
"privacy",
"reliability",
"code_quality",
"ai_risk",
"performance",
"devops",
"data",
"business",
"devex",
"accessibility",
"observability",
"maintainability"
],
"type": "string"
},
"critical": {
"default": 0,
"maximum": 9007199254740991,
"minimum": 0,
"type": "integer"
},
"high": {
"default": 0,
"maximum": 9007199254740991,
"minimum": 0,
"type": "integer"
},
"low": {
"default": 0,
"maximum": 9007199254740991,
"minimum": 0,
"type": "integer"
},
"medium": {
"default": 0,
"maximum": 9007199254740991,
"minimum": 0,
"type": "integer"
}
},
"required": [
"category"
],
"type": "object"
},
"maxItems": 13,
"type": "array"
},
"fixed": {
"description": "How many findings this pass fixed.",
"maximum": 9007199254740991,
"minimum": 0,
"type": "integer"
},
"n": {
"description": "This pass's number, starting at 1.",
"exclusiveMinimum": 0,
"maximum": 9007199254740991,
"type": "integer"
}
},
"required": [
"n",
"fixed",
"clean"
],
"type": "object"
},
"maxItems": 100,
"minItems": 1,
"type": "array"
},
"repo_hash": {
"description": "sha256 of the repository's canonical identity (the lowercased 'owner/repo', or a stable local fingerprint) — never the repo name itself. nittim never sees the name.",
"pattern": "^[0-9a-f]{64}$",
"type": "string"
},
"repo_size_bucket": {
"description": "A rough size bucket for the repo you looped over.",
"enum": [
"xs",
"s",
"m",
"l",
"xl"
],
"type": "string"
},
"swept": {
"description": "Optional: was the CLASS swept — a guard, lint rule or exhaustiveness check that makes a new instance loud — rather than only the instances a pass named? Never derived, never changes the reward. On a repeat report, omitting it keeps the last answer; `false` withdraws it.",
"type": "boolean"
}
},
"required": [
"repo_hash",
"repo_size_bucket",
"passes"
],
"type": "object"
},
"name": "report_loop",
"outputSchema": null
},
{
"description": "Run ONE nittim audit module against a GitHub repository, never producing scores or a verdict. The two deterministic modules (secret-scan, dependency-cve) return scanner evidence directly, free, with nothing to confirm. Deep-tier modules make one focused model call, cost 5.03 credits each and follow the protocol below. NEEDS A KEY: mint one at https://nittim.com/keys. COSTS MONEY in three calls: the first quotes a price and charges nothing; a second with `confirmedCost` set to that exact price returns a one-time link for the ACCOUNT OWNER to confirm — their yes, not the assistant's; a plain third call with the same arguments runs once at that price. A moved price is re-quoted, never charged.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"authorization": {
"description": "HUMAN CONFIRMATION. The `authorization` id from the confirm-link answer, once the account owner has pressed Confirm. Single-use, short TTL.",
"type": "string"
},
"confirmedCost": {
"description": "COST CONFIRMATION. Omit on the first call; then send back the exact quoted `cost`.",
"properties": {
"centicredits": {
"description": "The `centicredits` integer from the quoted cost, if it carried one.",
"type": "number"
},
"credits": {
"description": "The `credits` number from the quoted cost.",
"type": "number"
},
"kind": {
"description": "The `kind` from the quoted cost, e.g. 'credits'.",
"type": "string"
}
},
"required": [
"kind",
"credits"
],
"type": "object"
},
"githubToken": {
"description": "Optional read-only GitHub token. Without one, only public repos are reachable.",
"type": "string"
},
"moduleKey": {
"description": "The module's key, e.g. 'secret-scan', 'dependency-cve', 'security', 'privacy', 'gdpr'.",
"minLength": 1,
"type": "string"
},
"repoUrl": {
"description": "GitHub repository URL or owner/repo. A private repo needs a githubToken.",
"minLength": 1,
"type": "string"
}
},
"required": [
"repoUrl",
"moduleKey"
],
"type": "object"
},
"name": "run_module",
"outputSchema": null
},
{
"description": "Free nittim look: committed secrets and known CVEs over posted source files. No account, no key, no nittim credits. Hard evidence only: never scores, never a production verdict. Send SOURCE files, not build output (no node_modules, no dist, no binaries).",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"files": {
"description": "Source files as { path, content }[] — not build output. At most 1000; over the internal per-audit cap, the highest-priority ones win.",
"items": {
"properties": {
"content": {
"description": "The file's full text.",
"type": "string"
},
"encoding": {
"description": "Omit or 'utf8' for text files. Any other value (e.g. 'base64') is rejected — text only in v1.",
"type": "string"
},
"path": {
"description": "Relative path, e.g. 'src/index.ts'. No absolute paths, no '..', no backslashes.",
"minLength": 1,
"type": "string"
}
},
"required": [
"path",
"content"
],
"type": "object"
},
"maxItems": 1000,
"minItems": 1,
"type": "array"
},
"name": {
"description": "A display label for this project, e.g. 'my-abacus-app'. Sanitized before use.",
"maxLength": 200,
"minLength": 1,
"type": "string"
},
"uploadGrant": {
"description": "Optional: the id of an upload approval the account owner already confirmed. A large post without one is answered with a confirmation covering the files and the price.",
"type": "string"
}
},
"required": [
"name",
"files"
],
"type": "object"
},
"name": "scan_source",
"outputSchema": null
},
{
"description": "NEEDS A KEY: mint one at https://nittim.com/keys. Re-checks ONE finding from a finished audit against the repository's current code, or a commit named in the call, and answers fixed, still present, or undetermined — with the reason. It reads only the file that finding cites. Free, capped per day, and it moves no score or verdict: the report keeps recording what was true of the commit it ran on.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"auditId": {
"description": "The audit UUID, from its report link.",
"format": "uuid",
"pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$",
"type": "string"
},
"findingKey": {
"description": "The finding's stable key, as printed beside it in the report's findings list.",
"minLength": 1,
"type": "string"
},
"ref": {
"description": "A commit SHA or branch to check instead of the repository's current HEAD. Must be the audited commit or newer.",
"type": "string"
}
},
"required": [
"auditId",
"findingKey"
],
"type": "object"
},
"name": "verify_fix",
"outputSchema": null
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:f06961ffb39d0e422401bf159dfbbe4fc7c5cef41f8e2817e2bdc9880d811524 | sha256sum