Run submission security scan
POST/marketplace/submissions/{id}/scan
Initiates an automated security scan of the submission, analysing the manifest for permission over-reach, dangerous API usage patterns, and known vulnerability signatures. The scan result is stored on the submission and surfaced to the reviewer. Submissions with a "critical" risk level are automatically rejected.
Request
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
id | integer | Yes | The numeric ID of the submission to scan. |
Responses
200 Security scan completed and results stored
Content type application/json, object · MarketplaceSecurityScanV1.
| Field | Type | Required | Description |
|---|---|---|---|
submission_id | integer | No | ID of the submission that was scanned. |
risk_level | string | No | Overall risk classification. Submissions with "critical" risk are automatically rejected. One of: |
findings | array of object | No | Individual security findings identified during the scan. |
findings[].severity | string | No | Severity of the individual finding. One of: |
findings[].code | string | No | Machine-readable finding code. |
findings[].message | string | No | Human-readable description of the finding. |
scanned_at | string (date-time) | No |
Example
{
"submission_id": 19,
"risk_level": "low",
"findings": [
{
"severity": "info",
"code": "PERMISSION_AUDIT",
"message": "2 permissions requested — within acceptable scope."
}
],
"scanned_at": "2026-04-08T11:30:00Z"
}
404 Submission not found
Example request
curl -X POST "https://{tenant}.faciotech.net/api/v1/marketplace/submissions/{id}/scan" \
-H "Accept: application/json"