Four deterministic checks
KEY-EXP-01 · Query-parameter keys or tokens
HTTP-001 · Insecure server URLs
AUTH-001 · Missing documented authentication
KEY-EXP-02 · Undocumented static-key lifetime or rotation
OpenAPI Security
Speculynx scans OpenAPI 3.0 and 3.1 files locally, returns deterministic findings and explicit coverage, and keeps every conclusion scoped to the declared contract.
Free works without a license or backend connection. Pro adds heuristic coverage, PDF export, and bounded live checks.
KEY-EXP-01 · Query-parameter keys or tokens
HTTP-001 · Insecure server URLs
AUTH-001 · Missing documented authentication
KEY-EXP-02 · Undocumented static-key lifetime or rotation
Review authorization, object access, rate limiting, data exposure, and other contract signals with explicit rule execution and coverage metadata.
Pro also adds PDF output and a bounded scan-live mode. It remains separate from Agent Security.
JSON schema 1.0 reports executed, skipped, and non-evaluated rules; per-control status; findings; coverage; and verdict.
Static-analysis boundary
Static analysis does not prove absence of vulnerabilities, live reachability, runtime authorization enforcement, exploitability, or production safety. A no-finding Free result is indeterminate, not “secure.”
Read the technical trust model →Install from PyPI and scan an OpenAPI 3.0 or 3.1 file without uploading it. Pro remains separate from all Agent Security purchases.