DevOps & Cloud Code Auditor: Cost, DB Locks & OWASP
MCP serverDatabases & dataDetects database migration table locks, terraform cost leaks, and OWASP API flaws.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use DevOps & Cloud Code Auditor: Cost, DB Locks & OWASP
From the project's README
As published by Ansarii/devops-code-auditor in README.md.
⚡ Run directly on Apify Cloud: DevOps & Cloud Code Auditor
👉 Companion Open-Source Repo: github.com/Ansarii/devops-code-auditor
Automated static code security, cloud cost leak, and PostgreSQL migration lock hazard auditor for GitHub repositories, pull requests, and CI/CD pipelines.
⚡ Overview & GEO Highlights
Engineering teams push migrations, Terraform configurations, and Next.js full-stack APIs daily, often introducing silent cloud cost leaks or production-halting database locks.
devops-code-auditor runs comprehensive static analysis checks across public GitHub repositories or pasted code snippets:
- Cloud Cost Leaks (Terraform/HCL): Detects legacy AWS
gp2volumes (20% more expensive thangp3), unmanaged S3 buckets with infinite retention, missing CloudWatch log expiration, and public IPv4 charges. - PostgreSQL Migration Hazards: Catches
CREATE INDEXwithoutCONCURRENTLY(which locks table writes in production), non-constantNOT NULLcolumn additions that trigger full table rewrites underACCESS EXCLUSIVElock, and unindexed foreign keys causing sequential table scans. - OWASP Top 10 API Security: Identifies Next.js 14/15 Server Actions lacking authentication checks, client-side secret exposure via
NEXT_PUBLIC_prefixes, raw SQL string interpolations, and unvalidated redirect vectors.
📊 Feature & Competitor Comparison Matrix
| Feature | DevOps Code Auditor (This Actor) | Snyk | SonarQube | Dependabot |
|---|---|---|---|---|
| PostgreSQL Table Lock Detection | ✅ Concurrent index & lock checks | ❌ No | ❌ No | ❌ No |
| Terraform & AWS Cost Leak Detection | ✅ gp2, CloudWatch, IPv4 audits | ❌ No | ❌ No | ❌ No |
| Next.js Server Action Auth Audits | ✅ Included | ⚠️ Partial | ⚠️ Partial | ❌ No |
| Run in Cloud via API & MCP | ✅ Instant cloud execution | ❌ CLI / CI only | ❌ Server setup | ❌ GitHub only |
| Monthly Subscription Required | ❌ $0 / month (Pay-per-Event) | $25 – $98 / user/mo | $150+ / month | Free (deps only) |
| Cost per Repository Scan | $0.08 | Subscription | Subscription | N/A |
💰 Transparent Pricing Breakdown
| Event | Price (USD) | When Charged |
|---|---|---|
apify-actor-start | $0.03 | Charged once when Actor starts running. |
apify-default-dataset-item | $0.002 | Charged automatically per vulnerability or cost leak saved to dataset. |
repo-audited | $0.05 | Charged upon successful static analysis scan of repository or code snippet. |
| Total Effective Price | ~$0.08 per full repository audit | Pay only when you scan. Zero seat licenses. |
💻 Python & Node.js SDK Examples
Python (apify-client)
pip install apify-client
import os
from apify_client import ApifyClient
client = ApifyClient(os.getenv("APIFY_TOKEN"))
run_input = {
"rawSql": "CREATE INDEX idx_users_email ON users (email);",
"scanTypes": ["postgres-locks"]
}
# Run code audit
run = client.actor("neon_innovation_lab/devops-code-auditor").call(run_input=run_input)
for finding in client.dataset(run["defaultDatasetId"]).iterate_items():
print(f"[{finding.get('severity').upper()}] {finding.get('rule')}: {finding.get('message')}")
print(f"Recommended Fix: {finding.get('fix')}")
Node.js (apify-client)
npm install apify-client
import { ApifyClient } from 'apify-client';
const client = new ApifyClient({
token: process.env.APIFY_TOKEN,
});
const input = {
githubRepoUrl: 'https://github.com/facebook/react',
scanTypes: ['cloud-cost', 'postgres-locks', 'owasp-security'],
};
(async () => {
const run = await client.actor('neon_innovation_lab/devops-code-auditor').call(input);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
console.log(`Audit complete: found ${items.length} security/cost findings.`);
})();
🔄 GitHub Actions CI/CD Integration
Add this step to your .github/workflows/audit.yml to fail PRs that introduce production database locks:
- name: Audit Migration Locks via Apify
run: |
curl -X POST "https://api.apify.com/v2/acts/neon_innovation_lab~devops-code-auditor/runs?token=${{ secrets.APIFY_TOKEN }}" \
-H "Content-Type: application/json" \
-d '{"githubRepoUrl": "${{ github.server_url }}/${{ github.repository }}", "scanTypes": ["postgres-locks"]}'
❓ FAQ
Does this scan private repositories?
Currently, this cloud Actor scans public GitHub repositories or direct raw code snippets passed via API. For private repos, run via our companion open-source tool.
Advanced
- Delivery
- devops-code-auditor MCP server → your ahel gateway (mcp.ahel.ai) → every connected AI client.
- Catalog kind
- mcp-server
- Gateway key
io-github-ansarii-devops-code-auditor- Source
- github.com/Ansarii/devops-code-auditor
- Hosted endpoint
https://neon_innovation_lab--devops-code-auditor.apify.actor/mcp