Audit Dockerfiles for root execution, mutable images, embedded secrets, download-to-shell, unsafe permissions, remote ADD and weak package installation patterns.
1
Users / 7d
29
Runs / 30d
—
Rating
Updated 15 Sept 2026
Apify builder
@q_services
Leaderboard position
out of 6,248
New Actors / 7d
#4602
Total Actors
#150
Active users / 7d
#342
Total users
#1059
Runs / 30d
#745
Total runs
#1248
Portfolio stats
New Actors / 7d
0
Total Actors
87
Active users / 7d
74
+19 since first snapshot
Total users
181
Runs / 30d
1.7K
-10 since first snapshot
Total runs
3.7K
Portfolio history
Daily publishing
0
Each bar represents one UTC day.
No new public Actors were detected during this 7-day window.
Actor portfolio
87 matching of 87 Actors · page 2 of 4
Audit Dockerfiles for root execution, mutable images, embedded secrets, download-to-shell, unsafe permissions, remote ADD and weak package installation patterns.
1
Users / 7d
29
Runs / 30d
—
Rating
Audit any domain's email authentication (MX, SPF, DMARC, BIMI, DKIM) and get a deliverability score with actionable issues.
1
Users / 7d
29
Runs / 30d
Extract favicons, apple-touch-icons, web manifest, theme-color and brand images from any list of sites. Great for CRM and directory enrichment.
1
Users / 7d
29
Runs / 30d
Gate proposed payments using amount, currency, recipient, daily budget, confirmation, memo and independent-approver policies without executing transactions.
1
Users / 7d
1
Runs / 30d
Find AWS, Google, GitHub, Stripe, Slack, JWT, private-key and generic secret patterns exposed in HTML or JavaScript.
1
Users / 7d
29
Runs / 30d
q_services/github-actions-workflow-security-auditor
1%
users
Audit workflow YAML for unpinned actions, excessive permissions, untrusted interpolation, risky pull_request_target use and self-hosted runners.
1
Users / 7d
29
Runs / 30d
Run bounded non-destructive GraphQL probes for reachability, introspection exposure, GET support, CORS mistakes and stack-trace leakage.
1
Users / 7d
29
Runs / 30d
Gate agent-generated GraphQL with AST-based depth, field, alias, operation, list-size, mutation and introspection limits before execution.
1
Users / 7d
1
Runs / 30d
Audit Cache-Control, validators, Brotli/gzip, Vary and stale directives to reduce latency and CDN bandwidth costs.
1
Users / 7d
29
Runs / 30d
Validate agent JSON against JSON Schema and return deterministic repairs as RFC 6902 patches.
1
Users / 7d
1
Runs / 30d
Audit Kubernetes workloads for privileged containers, root execution, writable filesystems, missing capability drops, host access and mutable images.
1
Users / 7d
29
Runs / 30d
Check websites for llms.txt and llms-full.txt, extract sections and links for AI readiness and GEO audits.
1
Users / 7d
29
Runs / 30d
Redact, normalize, fingerprint and group logs or stack traces for agent incident workflows.
1
Users / 7d
1
Runs / 30d
Audit remote MCP servers: connectivity, latency, tools/list schemas, duplicate names, descriptions and mutating-tool signals.
1
Users / 7d
6
Runs / 30d
Find HTTP resources on HTTPS pages, third-party scripts/styles without SRI, and invalid integrity attributes.
1
Users / 7d
29
Runs / 30d
Audit Apple AASA and Android assetlinks.json files for missing apps, certificate fingerprints, relations and deployment mistakes.
1
Users / 7d
29
Runs / 30d
Audit package-lock.json files for missing integrity, insecure or non-registry sources, install scripts, duplicate versions and unsupported formats.
1
Users / 7d
29
Runs / 30d
Turn OpenAPI 3.x or Swagger operations into agent-ready tool names, input schemas, response schemas, auth and risk metadata.
1
Users / 7d
29
Runs / 30d
Gate agent-generated REST requests against OpenAPI operations, required parameters, authentication, scopes, media types, body limits and mutation confirmation.
1
Users / 7d
1
Runs / 30d
Audit OpenAPI and Swagger specifications for unsecured operations, unsafe server URLs, weak auth schemes and missing security responses.
1
Users / 7d
29
Runs / 30d
Audit OIDC discovery documents and JWKS for issuer mismatches, unsafe endpoints, weak keys, insecure algorithms and missing PKCE.
1
Users / 7d
29
Runs / 30d
Gate agent-generated email by recipient and domain policy, external-recipient confirmation, BCC, header injection, attachment and sensitive-content controls.
1
Users / 7d
1
Runs / 30d
Check HTML, JavaScript, CSS, image and font weight against configurable performance budgets without a browser.
1
Users / 7d
29
Runs / 30d
Scan webpages or text for prompt injection, secret exfiltration, hidden instructions and Unicode control characters.
1
Users / 7d
29
Runs / 30d
—
Rating
—
Rating
—
Rating
—
Rating
—
Rating
—
Rating
—
Rating
—
Rating
—
Rating
—
Rating
—
Rating
—
Rating
—
Rating
—
Rating
—
Rating
—
Rating
—
Rating
—
Rating
—
Rating
—
Rating
—
Rating
—
Rating
—
Rating