You're set. Open a pull request.
The next PR opened on any repository you granted access to gets audited automatically — dependencies checked against the live PyPI and npm registries, secrets and AI-specific flaws flagged inline. Findings arrive as a comment on the PR, usually in a couple of seconds. No SDK, no CI config, nothing to install locally.
Three things, in this order.
curl yourself.
@magaudit ignore <id> on the pull request with the id printed
next to the finding, or @magaudit ignore rule <RULE-ID> for all of
them. For a decision your whole team can see and review, a .magaudit.yml
in the repository. And if you already use another scanner we honour its markers
— pragma: allowlist secret, nosec,
nosemgrep, gitleaks:allow — so you never annotate the
same line twice.
Whatever your settings hide is still counted and still declared in the comment, with the reason for each one. Here is how often we get it wrong →
Looking at what is already in your repositories…
We check the code you already have, not just the next pull request. The most common problem in AI-written apps is written once, when the project is created, so a tool that only reads pull requests never sees it.
Public repos are free forever. Private ones need a plan.
Same detection engine on every tier — nothing is locked behind a higher plan. You only pay for how many private repositories it covers.
Your installation is linked. A subscription started from this page is activated on your organisation automatically as soon as Stripe confirms the payment; we also confirm it by email, and fix it by hand in the rare case something did not match. Nothing to send us.
Reached this page directly? Subscribing still works. Email contact@magsolutionsai.com with your GitHub organisation name and we will activate the plan within one business day.
Two things worth five minutes.
Scan a dependency file right now — paste a requirements.txt into
the scanner on the homepage. It queries PyPI live, from your browser, and shows you the same
verdict the App gives on a PR.
Read what the App actually looks for — the seven gates, why CVE-based scanners miss invented packages, and what we deliberately do not claim.
Read the write-up →