Merge 2 to 50 ICS feeds into one subscribable ICS file at a stable key-value record. Remove duplicate events.
Watch public JSON GET endpoints for response-shape drift without an OpenAPI spec. The Actor learns the shape from the response, compares it against a stored baseline, and reports each field-level change with a breaking flag.
Writes the security opinion that a vendor-intake review needs before a company connects to a SaaS vendor, an identity provider or a remote MCP server. For each issuer that you name, the Actor reads the public OpenID Connect Discovery or RFC 8414 metadata
Validate Open Graph and social-preview cards for public URLs across Slack, Discord, X, Facebook, LinkedIn, and iMessage without a browser.
Audit the OpenAPI or Swagger documents that you publish. The Actor reports every unresolved reference, every duplicate or absent operationId, every response without a schema, and every example that violates its own schema, with a JSON pointer and a sugges
SPF result for your egress IP, before the first mail. Give it the From domain, the egress IP addresses and the DKIM selectors of a new relay, tenant or email provider. It runs SPF check_host() for each IP (RFC 7208, with lookup counts), checks reverse DNS
Prove that a published npm or PyPI artifact carries a signed provenance attestation, that the attestation subject digest equals the registry artifact digest, and that the public transparency log holds the entry.
Reads your RSS, Atom or JSON Feed, then sends one HEAD and one ranged GET to each recent enclosure. It reports range support, content type, declared length against reported length, the redirect chain, TLS use, and every item whose GUID or enclosure URL ch
Read manifest files from more than one ecosystem. Report the license, the deprecation flag and the abandonment age of each package in one table.
Compares the commit that a production site serves with the head of its git release branch. Measures how long production lags across scheduled runs, flags a commit that is not on the branch, and gives one pass or fail gate. Works for Vercel, Netlify, Cloud
Finds each open GitHub pull request where a reviewer already reviewed, the author then pushed new commits, and nobody requested a new review. One dataset record for each pull request and reviewer pair, plus one summary for each reviewer. HTTP only, no bro
Reads the manifest link from the HTML head of each origin, reads the web app manifest, then verifies every declared icon, screenshot and shortcut icon with one HEAD and one ranged GET. It reports the true pixel size read from the file header against the d
Prove that no hop of a redirect chain reaches your internal network. For each URL the Actor walks every hop with automatic redirects off, resolves the hostname of each hop, classifies every address the resolver answers (public, RFC1918 private, loopback,
Resolve each declared range or channel tag the way a package manager does, and report when the resolved version is withdrawn, holds no live file, or moved to another version since the last run. One row for each target, with the resolved version, the rule
Watch remote MCP servers for tool-surface and permission changes. The Actor reads the declared tool list with anonymous requests, compares it against a stored digest, and reports each added tool, removed tool, changed input schema, changed destructive-act
Audit destination pages after a migration: extract and check every resource and link reference, flag old-domain references, broken URLs, redirects, mixed content, and missing references.
Watches scheduled GitHub Actions workflows and reports the ones that stopped to fire, that fail again and again, or that GitHub disabled for inactivity. One dataset record for each workflow plus one summary record. HTTP only, no browser, no proxy.
Your cron job sends one curl ping after each run. This Actor keeps the ledger in a named key-value store and reports every job that went silent, with an optional webhook alert. HTTP only, no browser, no proxy, no database.
Check each scheduled release page from outside, inside its release window. The Actor fails a gate when the outcome content is public before the release time, or when the preview content is still public after it. It compares the CDN copy with a cache-buste
Check each scrape source with a plain HTTP fetch and a body marker. Keep consecutive-failure, quarantine, and recovery counters between runs, and report the sources that changed state.
Learn when a deploy, a CDN rule or a proxy change removes or weakens a security header on your production URLs. The Actor compares HSTS, CSP (each directive), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy and the cross-origi
Checks security.txt files for expiry, unresolvable OpenPGP keys and unreachable contacts. Keeps a ledger of changes between runs.
Monitor selected parts of public web pages: fetch HTML over HTTP, extract text or inner HTML by CSS selector, and report only selector-level changes after a quiet baseline.
Run this on a short schedule. Each run reads what the vendor status page claims and measures a public endpoint of the same service from outside. Each check writes one typed event: MATCH, SHADOW_OUTAGE when the endpoint fails and the vendor still claims th