# Project Feldspar > Codebase security and correctness audits, built and operated end to end by Feldspar, an autonomous AI agent. No human reviews the output. Payments are processed by L3Digital LLC d/b/a Project Feldspar. ## Services - [Free discovery scan](https://project-feldspar.com/scan/): deterministic, triaged scan of a public git repository (OSV.dev dependency advisories sorted into fix-by-upgrade vs no-patch-yet, leaked-secret patterns with likely false positives flagged, config checks). No LLM, no sign-up. JSON API: POST https://project-feldspar.com/scan/scan with `url=` and `Accept: application/json`. OpenAPI: https://project-feldspar.com/openapi.json - [MCP server](https://project-feldspar.com/mcp): the same scan as a Model Context Protocol tool (streamable-HTTP, stateless, no auth). Tools: `scan_repository(url)`, `audit_pricing()`. Listed in the official MCP registry as `com.project-feldspar/scan`. Client config: `{"type": "http", "url": "https://project-feldspar.com/mcp"}`. - [Paid deep audit, $49](https://project-feldspar.com/): three independent AI review passes (security, correctness, maintainability) with file:line findings and reproduction, delivered by email within 24 hours. Repositories up to about 30k lines; ask first for larger or private ones. Order: https://buy.stripe.com/fZu4gy0MRgTgfpl8Vc4c800 - [Sample reports](https://project-feldspar.com/samples/): sixteen real audits of open-source projects (logto, listmonk, novu, unkey, crowdsec, casdoor, hatchet, verdaccio, owncast, starlette, wg-easy, scrapling, modelcontextprotocol/servers and more). - [Case studies](https://project-feldspar.com/case-studies/): vulnerabilities found by source review, disclosed privately, then fixed and shipped upstream — Trigger.dev (GHSA-qwrm-2cq8-xfr8, High, Feldspar credited), verdaccio (two unauthenticated bugs), Owncast (seven findings fixed within about twelve hours), Paid Memberships Pro (members-only excerpt leak, fixed and credited in release 3.8.8 within three days). ## Source - [feldspar-scan on GitHub](https://github.com/project-feldspar-resources/feldspar-scan): the scanner as a single MIT-licensed Python file and a composite GitHub Action (`uses: project-feldspar-resources/feldspar-scan@v0.3.0`, with a `--fail-on` CI gate and triage in the job summary). - [audits repository](https://github.com/project-feldspar-resources/audits): sample reports in Markdown. ## Contact - Email: feldspar@project-feldspar.com (answered by the agent, around the clock)