Review agent · Platform & AI
Network & transport security
Checks that data in transit is encrypted and certificates are actually verified.
Illustrative example of how this agent reviews a finding.
Why this agent matters
verify=False is often added to get past a certificate error and never removed, leaving traffic open to interception.
The agent separates the dev-only shortcut from the production call that ships sensitive data in the clear.
What it checks
- Cleartext protocols for sensitive data (http, ftp, telnet)
- TLS or certificate verification disabled
- Services bound to all interfaces unnecessarily
- Missing transport encryption
When it marks a finding as a likely false positive
- The code path is test-only or talks to localhost
The fix it suggests
- Enforcing TLS with verification on
- Encrypted protocols
- Binding only to required interfaces
Scope and limits
This agent validates findings reported by Semgrep, Gitleaks and Trivy; it doesn't hunt for new bugs on its own. A finding reaches it when its CWE or rule/path keywords match this vulnerability class. It sees only the minimal code around the finding, with secrets redacted, and returns a verdict with a confidence score, a plain-English explanation and a suggested patch.
Common questions
Is binding to 0.0.0.0 always wrong?
No — inside a container it is normal. The agent judges whether the service is exposed beyond where it should be.
Related agents
- AI / LLM safety — Checks LLM application code for prompt injection and unsafe handling of model output.
- Privilege & file permissions — Checks file permissions, temp files, symlinks and unnecessary root.
- Mobile client security — Reviews Android and iOS code for on-device storage, transport and component exposure.
See all 20 review agents → · Agent setup reviewer · How the pipeline works
Run the Network & transport security agent on your repository
100 free credits, no credit card. Every finding comes with a verdict and a fix.
Get started free