Use the signal. Understand the limit.
These terms explain the current Metal Mantra service in plain language. They do not turn an automated scan into a security assurance.
The service
Metal Mantra provides a registry, automated checks of supported public AI-agent repositories, related domain checks and reports. The first completed scan of a supported repository is free and published immediately after explicit acknowledgement. A verified-domain re-scan is available once after first successful DNS verification. Further re-scans are available only through a paid re-audit pass, and only while checkout is open; if checkout is closed they are unavailable.
Your responsibilities
Submit only public repository URLs and a domain you are entitled to identify in connection with the scan. Do not use Metal Mantra to overload the service, submit secrets or private code, evade limits or misrepresent a report. Signing in and scanning a repository does not establish GitHub ownership; domain DNS verification proves only control of the named domain.
If a public repository has already been associated with another account, use support to request review of the claim. A claim is not transferred automatically.
Reading and sharing results
Findings are static, automated indicators from a source snapshot. They can miss problems, report false positives or differ from a running deployment. The score, grade and DNS status are distinct from independent review, certification, regulatory compliance or a warranty. Check the method, scan time, scope, source and limitations before making decisions.
Publication and corrections
Metal Mantra may temporarily hide critical-finding details on public reports for 30 days; after that, those details may become public automatically. The private owner assessment can contain more detail. Corrections, suspected abuse and privacy requests can be submitted through the support form. We may correct or remove content when review warrants it, but do not promise a specific response time or outcome.
Availability and changes
Scans depend on public source access, domain checks and service availability. Quotas and supported files may limit a scan. We may update the interface, checks or these terms; a report remains tied to its stated method and scan time. Use of the service is at your own risk and should not replace a professional security review.
Paid re-audit passes and refunds
When checkout is open, a re-audit pass costs the price shown at checkout (currently $29) and adds three re-scans to one repository you own the credit record for. It is a one-time purchase with no subscription or auto-renewal. Passes are added after payment is confirmed, usually within seconds, and do not expire while the service operates. Pricing and availability may change; a change does not affect a pass you have already bought.
Payments are processed by Dodo Payments, which acts as Merchant of Record: Dodo sells the pass to you, charges your card or other payment method, collects applicable taxes and sends your receipt. Dodo’s own terms apply to the payment. Metal Mantra never sees or stores your card details.
If you have not used any of the three re-scans, you may request a full refund within 14 days of purchase through the support form, quoting the repository and purchase email. Once a re-scan from the pass has been used, the pass is not refundable except where the law requires it or a re-scan failed because of a fault on our side. When a refund is approved, we remove the unused credits. A refund or payment dispute does not by itself change a published report.