Review agent · Platform & AI

Network & transport security

Checks that data in transit is encrypted and certificates are actually verified.

client/api.go1tr := &http.Transport{2 TLSClientConfig: &tls.Config{3 InsecureSkipVerify: true,4 }}Netwhat this review answersCleartext http, ftp or telnet?TLS verification disabled?Bound to 0.0.0.0 needlessly?$ verdict REAL ISSUE$ fix TLS with verification on▍

Illustrative example of how this agent reviews a finding.

Why this agent matters

verify=False is often added to get past a certificate error and never removed, leaving traffic open to interception.

The agent separates the dev-only shortcut from the production call that ships sensitive data in the clear.

What it checks

  • Cleartext protocols for sensitive data (http, ftp, telnet)
  • TLS or certificate verification disabled
  • Services bound to all interfaces unnecessarily
  • Missing transport encryption

When it marks a finding as a likely false positive

  • The code path is test-only or talks to localhost

The fix it suggests

  • Enforcing TLS with verification on
  • Encrypted protocols
  • Binding only to required interfaces

Scope and limits

This agent validates findings reported by Semgrep, Gitleaks and Trivy; it doesn't hunt for new bugs on its own. A finding reaches it when its CWE or rule/path keywords match this vulnerability class. It sees only the minimal code around the finding, with secrets redacted, and returns a verdict with a confidence score, a plain-English explanation and a suggested patch.

Common questions

Is binding to 0.0.0.0 always wrong?

No — inside a container it is normal. The agent judges whether the service is exposed beyond where it should be.

Related agents

See all 20 review agents → · Agent setup reviewer · How the pipeline works

Run the Network & transport security agent on your repository

100 free credits, no credit card. Every finding comes with a verdict and a fix.

Get started free