Skip to content

Run submission security scan

POST/marketplace/submissions/{id}/scan

Initiates an automated security scan of the submission, analysing the manifest for permission over-reach, dangerous API usage patterns, and known vulnerability signatures. The scan result is stored on the submission and surfaced to the reviewer. Submissions with a "critical" risk level are automatically rejected.

Request

Path parameters

NameTypeRequiredDescription
idintegerYes

The numeric ID of the submission to scan.

Responses

200 Security scan completed and results stored

Content type application/json, object · MarketplaceSecurityScanV1.

FieldTypeRequiredDescription
submission_idintegerNo

ID of the submission that was scanned.

risk_levelstringNo

Overall risk classification. Submissions with "critical" risk are automatically rejected.

One of: "low", "medium", "high", "critical"

findingsarray of objectNo

Individual security findings identified during the scan.

findings[].severitystringNo

Severity of the individual finding.

One of: "info", "low", "medium", "high", "critical"

findings[].codestringNo

Machine-readable finding code.

findings[].messagestringNo

Human-readable description of the finding.

scanned_atstring (date-time)No

Example

{
  "submission_id": 19,
  "risk_level": "low",
  "findings": [
    {
      "severity": "info",
      "code": "PERMISSION_AUDIT",
      "message": "2 permissions requested — within acceptable scope."
    }
  ],
  "scanned_at": "2026-04-08T11:30:00Z"
}

404 Submission not found

Example request

curl -X POST "https://{tenant}.faciotech.net/api/v1/marketplace/submissions/{id}/scan" \
  -H "Accept: application/json"
Loading