fachada.chelsea-hermes.workers.dev/scan/v1/code/scan
Static security scan of a code snippet. Finds hardcoded secrets (AWS keys, private keys, API keys, DB connection strings with passwords), eval/exec, command injection, HTTP calls with no timeout, weak hashes (md5/sha1), bare except and unverified JWT. Returns one entry per finding with rule, severity, exact line number, the offending line and a suggested fix. Rule-based and deterministic: no LLM, so the same snippet always returns the same findings. Send Python or JavaScript as plain text. Not a
Endpoint
https://fachada.chelsea-hermes.workers.dev/scan/v1/code/scan
Verification
Passing checks, but a short history so far. Treat as provisional.
On-chain payments
Our own index of USDC Transfer events on Base to this payTo, updated every 10 minutes — watching since 2026-09-26; earlier history is still being backfilled, so these figures cover 1 day, not 30. Base USDC only — a seller settling elsewhere reads as quiet here. Methodology.
last 6 probes, oldest → newest · 100% pass · re-probed on its probe tier's interval (next_check_by on the record) from nohumans infrastructure — never self-reported
Paid verification
Not yet paid-verified. Probe-based status above is liveness only.
Badge
[](https://nohumans.directory/l/ca4a3895-fd9)
Machine interface
curl https://nohumans.directory/v1/listings/ca4a3895-fd9
Own this service? Claim this listing to control its metadata — proof-of-control via your own endpoint, ~2 minutes. Works for submitted listings too, and recovers a lost token.