skip to content
fizzgig
sign in
// suite
architectureknow what you builtoperationsknow it’s runningauditknow it’s safe to shipintegrationspricingdocschangelog
// community
sourdough startersproject kicks-off in 1 prompt
sign inrequest access →
audit suite/security/fetch_url_scanner
newsecurityv0.1.0free

fizzgig__fetch_url_scanner

detects third-party apis called via fetch() urls (no installed sdk). emits architecture_facts for stack-map.

// ai does this over time

the AI calls a third-party API via raw fetch() with no SDK installed. your stack-map shows packaged dependencies; the integrated services stay invisible. when the API breaks, rate-limits, or rotates keys, you're flying blind.

// the tool does

scans concatenated source for fetch() URLs and bare hostnames cited in fetch / axios / SDK base_url config, classifies against a registry of 70+ platforms across 12 categories (auth, payments, AI, cloud, comms, observability, data + search, maps + geo, code hosting, UK public data, web tools + scrapers, commerce + property), emits architecture_facts in the exact shape stack-map ingests.

// so you can

the integrated stack lights up on the map after you run this. catches the integrations dep-audit + stack-map alone can't see - exactly the ones most likely to break.

● new● v0.1.0● free
// input schema
schema · application/json
{
"type": "object"
"required": [
"project"
]
"properties": {
"project": {
"type": "string"
"description": "the project slug or path"
}
"strict": {
"type": "boolean"
"default": false
"description": "fail on warnings, not just errors"
}
}
}
// output schema
schema · application/json
{
"type": "object"
"properties": {
"ok": {
"type": "boolean"
}
"findings": {
"type": "array"
"items": {
"type": "object"
"properties": {
"severity": {
"enum": [
"info"
"warn"
"high"
"critical"
]
}
"message": {
"type": "string"
}
"fix": {
"type": "string"
}
}
}
}
}
}
// example call from cursor
~/myapp - example output
→ fizzgig__fetch_url_scanner(project="myapp")
{
"ok": false,
"findings": [
{ "severity": "high",
"message": "policy uses user_id without auth.uid()",
"fix": "USING (auth.uid() = user_id)" }
],
"scanned": 3, "duration_ms": 142
}
// reviews
@maya.codes★★★★★
2 days ago

caught a policy that would have leaked every user's comments. shipped a fix in 4 minutes.

@solo_at_3am★★★★★
1 week ago

first tool i installed. it's the one that pays for itself.

@vibebuilder★★★★☆
2 weeks ago

works great. one false positive on a join table - easy to ignore.

// primary action

add to your editor

paste this into your mcp config.
.cursor/mcp.json
{
  "fizzgig": {
    "url": "https://mcp.fizzgig.ai",
    "tools": ["fetch_url_scanner"]
  }
}
full setup guide →
// pricing
free
unlimited calls on the free tier.
// related tools
secret_leak_finder
v0.9.0
→
rls_checker
v0.6.0
→
env_auditor
v0.4.0
→
fizzgig

the fluffy guardian of vibe-coded products. growls at insecure code so you don't have to.

all systems operational

suite

architectureoperationsauditintegrationspricingdocschangelog

community

sourdough startersdiscord (soon)github (soon)x / twitter (soon)rss (soon)

company

aboutcontacttermsprivacycookies
© 2026 fizzgig.
v1.5.0 · 2026-07-26
AI usage: fizzgig uses AI internally (Anthropic Claude, Google Gemini, OpenAI embeddings) to power audit checks, summarise decisions, and rank findings. Content surfaced from these tools is labelled as such in the dashboard. No user data is used to train third-party AI models — see our privacy policy for the full sub-processor list.