Try itExperimental
See what an agent can do with Gecko Security before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; commands tagged live-capable can re-run against the real endpoint from our edge, right now (▶ run live — the exact same request, live and recorded lines always labeled); sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).
$curl -s https://gecko.security/docs/llms.txt | head -6recorded session — replayed, not liveVerified integrations
No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.
By theme — the product's score on each story themeBy theme
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Ci precommit — stories about ci precommit in this arenaCi precommitevidence →
Stories about ci precommit in this arena
Container scanning — stories about container scanning in this arenaContainer scanningevidence →
Stories about container scanning in this arena
Coverage accuracy — stories about coverage accuracy in this arenaCoverage accuracyevidence →
Stories about coverage accuracy in this arena
Dependency sca — stories about dependency sca in this arenaDependency scaevidence →
Stories about dependency sca in this arena
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Sast rules — stories about sast rules in this arenaSast rulesevidence →
Stories about sast rules in this arena
Secret detection — stories about secret detection in this arenaSecret detectionevidence →
Stories about secret detection in this arena
Supply chain sbom — stories about supply chain sbom in this arenaSupply chain sbomevidence →
Stories about supply chain sbom in this arena
Triage noise — stories about triage noise in this arenaTriage noiseevidence →
Stories about triage noise in this arena
Story verdicts — every judged story with its evidenceStory verdicts
Follow the green: where the map greys out is where Gecko Security stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
✓8/10
unlocks → Scoped API keys · API sandbox · Official CLI
Subscribe to events via webhooks
✓8/10
Build against official SDKs
~5/10
Issue scoped/least-privilege API credentials for an agent
!4/10
Connect an agent via an official MCP server
✓7/10
Download a machine-readable API spec (OpenAPI or equivalent)
✓9/10
unlocks → Interactive API docs
Rely on versioned APIs with a documented deprecation policy
~3/10
Test against a sandbox environment without touching production data
—0/10
Explore an interactive API reference with runnable examples
—0/10
Docs for agents
Point an agent at llms.txt or agent-oriented docs
✓9/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
~5/10
unlocks → MCP client · AI insights
Operate the product with natural-language commands
~6/10
Plug MCP servers into this product so it can use their tools
—0/10
Get AI-generated insights and suggestions from my data inside the product
!5/10
Set up automations that run autonomously in the background
✓7/10
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Ci precommit — stories about ci precommit in this arenaCi precommit
Stories about ci precommit in this arena
Agent scanning
Ci gates
Run the scanner as a pre-commit hook so secrets and issues never enter my git history
—–
Container scanning — stories about container scanning in this arenaContainer scanning
Stories about container scanning in this arena
Coverage accuracy — stories about coverage accuracy in this arenaCoverage accuracy
Stories about coverage accuracy in this arena
Dependency sca — stories about dependency sca in this arenaDependency sca
Stories about dependency sca in this arena
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Sast rules — stories about sast rules in this arenaSast rules
Stories about sast rules in this arena
Secret detection — stories about secret detection in this arenaSecret detection
Stories about secret detection in this arena
Supply chain sbom — stories about supply chain sbom in this arenaSupply chain sbom
Stories about supply chain sbom in this arena
Triage noise — stories about triage noise in this arenaTriage noise
Stories about triage noise in this arena
Sorted by importance (agentic first) (high → low) · 55/55 stories · click a row’s chevron for the rationale and evidence
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 8/10 | Tprobed | |
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 7/10 | Tprobed | |
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | partial | 5/10 | Tprobed | |
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none | 0/10 | ||
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 9/10 | Tprobed | |
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 9/10 | Tprobed | |
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Cclaimed | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 7/10 | Tprobed | |
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 7/10 | Cclaimed | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Tprobed | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Tprobed | |
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | disputed | 5/10 | Dcontradicted | |
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | disputed | 4/10 | Dcontradicted | |
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 3/10 | Tprobed | |
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | none | 0/10 | ||
Run scans in CI on every pull request and fail the build on new findings via exit codes C Ci gates | devops-lead | Ci precommit — stories about ci precommit in this arenaCi precommit | 3 | full | 8/10 | Cclaimed | |
Baseline or ignore existing and false-positive findings so only new issues alert C Fp management | security-engineer | Triage noise — stories about triage noise in this arenaTriage noise | 3 | partial | 6/10 | Xcommunity | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | partial | 6/10 | Cclaimed | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | partial | 5/10 | Cclaimed | |
Run static analysis that finds vulnerability classes like injection and XSS in my source code C Code analysis | developer | Sast rules — stories about sast rules in this arenaSast rules | 3 | disputed | 5/10 | Dcontradicted | |
Have an agent run a scan headlessly via the CLI, parse machine-readable results, and file issues for real findings G Agent scanning | ai-native user | Ci precommit — stories about ci precommit in this arenaCi precommit | 3 | partial | 4/10 | Xcommunity | |
Use AI to triage findings — explaining them, deduplicating, and flagging likely false positives C Ai triage | ai-native user | Triage noise — stories about triage noise in this arenaTriage noise | 3 | disputed | 4/10 | Dcontradicted | |
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | partial | 3/10 | Tprobed | |
Scan a repository and its full git history for hardcoded secrets and credentials C Secret scanning | developer | Secret detection — stories about secret detection in this arenaSecret detection | 3 | none | 0/10 | ||
Scan container images for OS-package and application-layer vulnerabilities before deploying them C Containers | devops-lead | Container scanning — stories about container scanning in this arenaContainer scanning | 3 | none | 0/10 | ||
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | none | untested | none yet | |
Run the scanner as a pre-commit hook so secrets and issues never enter my git history C Pre commit | developer | Ci precommit — stories about ci precommit in this arenaCi precommit | 3 | none | untested | none yet | |
Scan my dependency manifests and lockfiles for packages with known vulnerabilities C Sca scanning | developer | Dependency sca — stories about dependency sca in this arenaDependency sca | 3 | none | untested | none yet | |
Apply suggested or automatic code fixes for findings instead of only reading reports C Fix suggestions | developer | Sast rules — stories about sast rules in this arenaSast rules | 2 | full | 8/10 | Cclaimed | |
Have AI draft remediation pull requests for security findings that I review and merge C Ai remediation | ai-native user | Sast rules — stories about sast rules in this arenaSast rules | 2 | full | 8/10 | Xcommunity | |
See scan findings surfaced as pull-request comments or checks in GitHub or GitLab C Ci gates | developer | Ci precommit — stories about ci precommit in this arenaCi precommit | 2 | full | 8/10 | Cclaimed | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 6/10 | Tprobed | |
Filter and gate on findings by severity or confidence so low-value noise does not block builds C Fp management | developer | Triage noise — stories about triage noise in this arenaTriage noise | 2 | partial | 6/10 | Cclaimed | |
Wire the scanner into my coding agent so AI-generated code is scanned for issues before it lands C Agent scanning | ai-native user | Ci precommit — stories about ci precommit in this arenaCi precommit | 2 | partial | 6/10 | Tprobed | |
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | partial | 5/10 | Cclaimed | |
Detect taint-style vulnerabilities that flow across files and function boundaries C Code analysis | security-engineer | Sast rules — stories about sast rules in this arenaSast rules | 2 | disputed | 5/10 | Dcontradicted | |
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | partial | 5/10 | Cclaimed | |
Scan projects across all the major languages and package ecosystems my organization uses C Coverage | developer | Coverage accuracy — stories about coverage accuracy in this arenaCoverage accuracy | 2 | partial | 5/10 | Xcommunity | |
Emit scan results in machine-readable formats like JSON or SARIF for downstream tooling C Output formats | developer | Coverage accuracy — stories about coverage accuracy in this arenaCoverage accuracy | 2 | partial | 4/10 | Tprobed | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | partial | 4/10 | Cclaimed | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | 0/10 | ||
Get concrete upgrade paths or automated fix pull requests that remediate vulnerable dependencies C Dependency fixes | developer | Dependency sca — stories about dependency sca in this arenaDependency sca | 2 | none | 0/10 | ||
Prioritize dependency alerts by whether the vulnerable code is actually reachable from my code C Sca scanning | security-engineer | Dependency sca — stories about dependency sca in this arenaDependency sca | 2 | none | 0/10 | ||
Scan Terraform, Kubernetes, and other IaC files for security misconfigurations C Iac misconfig | devops-lead | Container scanning — stories about container scanning in this arenaContainer scanning | 2 | none | 0/10 | ||
Write custom static-analysis rules in a simple syntax and share them across repositories C Custom rules | security-engineer | Sast rules — stories about sast rules in this arenaSast rules | 2 | none | 0/10 | ||
Define custom detection rules for my organization's internal token and secret formats C Custom detection | security-engineer | Secret detection — stories about secret detection in this arenaSecret detection | 2 | none | untested | none yet | |
Generate a software bill of materials (SPDX or CycloneDX) for my project or image C Sbom | security-engineer | Supply chain sbom — stories about supply chain sbom in this arenaSupply chain sbom | 2 | none | untested | none yet | |
Have detected secrets verified against the issuing service so I know which ones are live C Secret scanning | security-engineer | Secret detection — stories about secret detection in this arenaSecret detection | 2 | n/a | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | none | untested | none yet | |
Scan non-git sources like S3 buckets, Docker images, and CI logs for leaked secrets C Secret scanning | security-engineer | Secret detection — stories about secret detection in this arenaSecret detection | 2 | n/a | untested | none yet | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | none | 0/10 | ||
Detect the licenses of my dependencies and enforce a license policy in scans C Licenses | devops-lead | Supply chain sbom — stories about supply chain sbom in this arenaSupply chain sbom | 1 | none | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 37 stories with headroom
What would move Gecko Security’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Agenticness — how well agents can access and operate the productPlug MCP servers into this product so it can use their tools
nonemoves agent-readyimpact 45
All evidence describes Gecko exposing its own data via an MCP server so external AI tools/agents can call into Gecko (docs-9, probe-4) — the reverse relationship.
Container scanning — stories about container scanning in this arenaScan container images for OS-package and application-layer vulnerabilities before deploying them
nonemoves PA Scoreimpact 30
Gecko's documented capability is AI-driven source-code (SAST) analysis across languages like TypeScript, Python, Go, Java, etc., producing call-chain/PoC findings and PR fixes — no evidence describes scanning container images for OS-package (e.g., CVE feeds on apt/rpm packages) or layered image vulnerabilities.
Dependency sca — stories about dependency sca in this arenaScan my dependency manifests and lockfiles for packages with known vulnerabilities
nonemoves PA Scoreimpact 30
Gecko's documented capability is AI-driven source-code (SAST) analysis — call-chain tracing, endpoint mapping, PR-level code review — with no mention of scanning package manifests, lockfiles, or third-party dependency CVEs.
Secret detection — stories about secret detection in this arenaScan a repository and its full git history for hardcoded secrets and credentials
nonemoves PA Scoreimpact 30
Missing: any mention of secret/credential detection, hardcoded key scanning, or scanning git commit history for leaked secrets.
Ci precommit — stories about ci precommit in this arenaRun the scanner as a pre-commit hook so secrets and issues never enter my git history
nonemoves PA Scoreimpact 30
Gecko's documented workflow is GitHub App/PR-based scanning with pass/fail PR checks, not a local pre-commit git hook that blocks commits before they enter history — no evidence of a pre-commit hook, CLI hook script, or local git-hook integration exists in the evidence pack.
Privacy posture — data-handling and privacy storiesPrevent my data from being used to train AI models
nonemoves PA Scoreimpact 30
No evidence in the pack addresses data-training opt-out, AI training data policies, or any privacy controls governing whether user code/data is used to train AI models; Gecko's docs focus on scanning, deployment, and integrations, not this privacy axis.
Agenticness — how well agents can access and operate the productUse an official CLI
nonemoves agent-readyimpact 30
No evidence of an official CLI; Gecko offers a GitHub App, REST API, webhooks, and an MCP server for AI tools, but nothing in the docs, changelog, or probes mentions a CLI tool for AI-native workflows.
Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples
nonemoves API qualityimpact 30
While Gecko exposes an OpenAPI spec (gecko-security-probe-3) and documents API capabilities (gecko-security-docs-10), there is no evidence of an interactive API reference UI with runnable/try-it examples for developers or AI agents to explore.
Showing the top 8 of 37 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map5 surfaces · 33 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
docs33 stories
- Point an agent at llms.txt or agent-oriented docs
- Run the product headlessly / in CI for automation
- Connect an agent via an official MCP server
- Drive the product through a documented public API
- Issue scoped/least-privilege API credentials for an agent
- Build against official SDKs
- Subscribe to events via webhooks
- Get AI-generated insights and suggestions from my data inside the product
- Set up automations that run autonomously in the background
- Delegate tasks to a built-in AI assistant inside the product
- Operate the product with natural-language commands
- Download a machine-readable API spec (OpenAPI or equivalent)
- Rely on versioned APIs with a documented deprecation policy
- Perform bulk operations across many items at once
- Define rules that trigger actions automatically on events
- Schedule recurring jobs or workflows
- Have an agent run a scan headlessly via the CLI, parse machine-readable results, and file issues for real findings
- Wire the scanner into my coding agent so AI-generated code is scanned for issues before it lands
- Run scans in CI on every pull request and fail the build on new findings via exit codes
- See scan findings surfaced as pull-request comments or checks in GitHub or GitLab
- Scan projects across all the major languages and package ecosystems my organization uses
- Emit scan results in machine-readable formats like JSON or SARIF for downstream tooling
- Do everything through the API that I can do in the UI
- Export all of my data in open formats and leave
- Self-host the core product
- Choose where my data is stored (region/residency)
- Have AI draft remediation pull requests for security findings that I review and merge
- Detect taint-style vulnerabilities that flow across files and function boundaries
- Run static analysis that finds vulnerability classes like injection and XSS in my source code
- Apply suggested or automatic code fixes for findings instead of only reading reports
- Use AI to triage findings — explaining them, deduplicating, and flagging likely false positives
- Baseline or ignore existing and false-positive findings so only new issues alert
- Filter and gate on findings by severity or confidence so low-value noise does not block builds
Hacker News11 stories
- Issue scoped/least-privilege API credentials for an agent
- Get AI-generated insights and suggestions from my data inside the product
- Delegate tasks to a built-in AI assistant inside the product
- Have an agent run a scan headlessly via the CLI, parse machine-readable results, and file issues for real findings
- Wire the scanner into my coding agent so AI-generated code is scanned for issues before it lands
- Scan projects across all the major languages and package ecosystems my organization uses
- Have AI draft remediation pull requests for security findings that I review and merge
- Detect taint-style vulnerabilities that flow across files and function boundaries
- Run static analysis that finds vulnerability classes like injection and XSS in my source code
- Use AI to triage findings — explaining them, deduplicating, and flagging likely false positives
- Baseline or ignore existing and false-positive findings so only new issues alert
OpenAPI spec10 stories
- Point an agent at llms.txt or agent-oriented docs
- Run the product headlessly / in CI for automation
- Drive the product through a documented public API
- Build against official SDKs
- Operate the product with natural-language commands
- Download a machine-readable API spec (OpenAPI or equivalent)
- Rely on versioned APIs with a documented deprecation policy
- Emit scan results in machine-readable formats like JSON or SARIF for downstream tooling
- Do everything through the API that I can do in the UI
- Export all of my data in open formats and leave
llms.txt2 stories
Probe proofs — replayable recordings from the probe harnessProbe proofs
Replayable recordings from our probe harness — see the Prove-It protocol to submit one.
$curl -s https://gecko.security/docs/llms.txt | head -6reproduced$ curl -s https://gecko.security/docs/llms.txt | head -6 # Gecko Security > Gecko Security documentation. - [Gecko Security](https://gecko.security/docs/index.md): An AI security engineer that finds real, exploitable vulnerabilities in your code, and ships the fix. - [Quick start](https://gecko.security/docs/quick-start.md): Connect a repository, run your first scan, and review real findings in minutes.
$curl -si -X POST https://app.gecko.security/api/mcp -H 'Content-Type: application/json' -d '<jsonrpc initialize>'reproduced$ curl -si -X POST https://app.gecko.security/api/mcp -H 'Content-Type: application/json' -d '<jsonrpc initialize>'
HTTP/2 401
cache-control: public, max-age=0, must-revalidate
content-type: application/json
date: Mon, 14 Sep 2026 23:36:15 GMT
server: Vercel
strict-transport-security: max-age=63072000
www-authenticate: Bearer realm="gecko-mcp", resource_metadata="https://app.gecko.security/.well-known/oauth-protected-resource/api/mcp"
x-matched-path: /api/mcp
x-request-id: req_af6e0cdc09bc48e5985491a58227e919
x-vercel-cache: MISS
x-vercel-id: sfo1::iad1::bxqj9-1789428975789-aa58773dca26
{"error":{"type":"authentication_error","code":"api_[redacted]_invalid","message":"API [redacted] is required","doc_url":"https://docs.gecko.security/api/errors#api_[redacted]_invalid","request_id":"req_af6e0cdc09bc48e5985491a58227e919"}}
$curl -s https://app.gecko.security/api/v1/openapi.json | head -c 200 # OpenAPI 3.1, keylessreproduced$ curl -s https://app.gecko.security/api/v1/openapi.json | head -c 200 # OpenAPI 3.1, [redacted]less
{"openapi":"3.1.0","info":{"title":"Gecko Security API","version":"1.0.0","description":"Programmatic access to scans, vulnerabilities, repositories, schedules, integrations, and scanner image release
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
3 of 13 testable claims verified · 5 contradicted → integrity 0/100
21 distinct capability claims found in Gecko Security’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
3
Verified
5
Unverified
5
Contradicted
20
Undersold
Verified (3)
“One-click 'Request fix' opens a pull request with the patch applied”
Have AI draft remediation pull requests for security findings that I review and mergefullproof ↗
“AI tools can connect to list repositories/scans and pull full vulnerability evidence”
“Public v1 API can trigger scans and read scan/repo/vulnerability data”
Drive the product through a documented public APIfullproof ↗
Unverified (6)
“Findings include a confidence score to help filter noise”
Filter and gate on findings by severity or confidence so low-value noise does not block buildspartialproof ↗
“Findings include a CVSS 4.0 severity rating”
Filter and gate on findings by severity or confidence so low-value noise does not block buildspartialproof ↗
“Posts a pass/fail security check back to GitHub or GitLab pull requests”
See scan findings surfaced as pull-request comments or checks in GitHub or GitLabfullproof ↗
“API supports managing scan schedules”
“API supports receiving webhook events”
“Scanner, storage, and AI inference run inside the customer's own AWS account”
Choose where my data is stored (region/residency)partialproof ↗
Contradicted (6)
“Findings show the full source-to-sink call chain across files/functions”
Detect taint-style vulnerabilities that flow across files and function boundariesdisputedproof ↗
“Findings include a suggested patch to fix the vulnerability”
Get concrete upgrade paths or automated fix pull requests that remediate vulnerable dependenciesnoneproof ↗
“Connected AI tools can triage findings and file tickets”
Use AI to triage findings — explaining them, deduplicating, and flagging likely false positivesdisputedproof ↗
“API keys are visible team-wide with owner attribution and per-request usage logging”
Issue scoped/least-privilege API credentials for an agentdisputedproof ↗
“API endpoint to rotate GitLab integration tokens for secret managers/scripts”
Issue scoped/least-privilege API credentials for an agentdisputedproof ↗
“Container image resolution returns a digest-pinned image reference”
Scan container images for OS-package and application-layer vulnerabilities before deploying themnoneproof ↗
Undersold (20)
Point an agent at llms.txt or agent-oriented docsfullproof ↗
Run the product headlessly / in CI for automationfullproof ↗
Set up automations that run autonomously in the backgroundfullproof ↗
Delegate tasks to a built-in AI assistant inside the productpartialproof ↗
Operate the product with natural-language commandspartialproof ↗
Download a machine-readable API spec (OpenAPI or equivalent)fullproof ↗
Rely on versioned APIs with a documented deprecation policypartialproof ↗
Perform bulk operations across many items at oncepartialproof ↗
Define rules that trigger actions automatically on eventspartialproof ↗
Have an agent run a scan headlessly via the CLI, parse machine-readable results, and file issues for real findingspartialproof ↗
Wire the scanner into my coding agent so AI-generated code is scanned for issues before it landspartialproof ↗
Run scans in CI on every pull request and fail the build on new findings via exit codesfullproof ↗
Scan projects across all the major languages and package ecosystems my organization usespartialproof ↗
Emit scan results in machine-readable formats like JSON or SARIF for downstream toolingpartialproof ↗
Do everything through the API that I can do in the UIpartialproof ↗
Export all of my data in open formats and leavepartialproof ↗
Apply suggested or automatic code fixes for findings instead of only reading reportsfullproof ↗
Baseline or ignore existing and false-positive findings so only new issues alertpartialproof ↗
Claims outside our story set (6)
Real capability claims found in Gecko Security’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.
“Users install a GitHub App and select which repositories to scan”
source ↗“Findings come with a proof of concept demonstrating exploitability”
source ↗“Gecko automatically rechecks findings and marks them fix-verified once resolved”
source ↗“Can create tickets in Jira, Linear, ClickUp, or Shortcut for findings”
source ↗“Can scan a public repo URL or uploaded ZIP without connecting a git provider”
source ↗“Supports self-hosted GitHub Enterprise Server via personal access token”
source ↗
Business model
Free plan with 10 scans and PR-bot CI/CD; Pro is a flat $100/month with 100 scans, APIs, and integrations; Enterprise adds unlimited scanning and on-prem/self-hosted deployment.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Try Experimental
Run it in the microterminal →Recorded agent sessions — and a live MCP handshake where the vendor ships one.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
