Live terminal scanning
Run a one-command scan from the terminal and see findings stream back as they are discovered, instead of waiting for a separate report step.
qsa.sh runs an external security scan of your public IP with terminal-streamed results and no local installation, helping you inspect exposed ports and vulnerability signals.
qsa.sh is a terminal-based external security scan service that checks the public IP address your request comes from. It is designed for people who want a quick outside-in view of their own host without installing scanners or assembling a toolchain first.
The service combines naabu, nmap with the vulners script, and nuclei to identify open ports, service versions, TLS posture, and matching vulnerability checks. The free tier streams results live in about 30 seconds, while paid tiers extend the scan to all ports and return fuller reports asynchronously.
Run a one-command scan from the terminal and see findings stream back as they are discovered, instead of waiting for a separate report step.
The free scan checks the top 1,000 TCP ports, while paid tiers expand to all 65,535 TCP ports for broader external exposure coverage.
qsa.sh fingerprints services with nmap and vulners so open ports are paired with detected service versions and known-CVE mapping.
Nuclei checks cover curated exposure, login, takeover, TLS, and CVE templates, with the Deep tier using the full template set plus custom checks.
The service only scans the IP your request comes from, shows that address before scanning, and includes a 15-second chance to cancel with Ctrl-C.
Check what ports and services are exposed on your own public IP and get a quick severity snapshot without setting up local tools.
Use the Full tier when you are fixing an issue and want broader port coverage with repeated verification on the same host.
Use the Deep tier when you want a fuller vulnerability pass, including the complete nuclei template set and a report you can review later.
Run the scan from a server, cloud instance, or datacenter host to inspect its outside-in exposure from the internet.
Use the live terminal output when you want immediate feedback on open ports, service versions, TLS posture, and CVE matches.
qsa.sh scans only the public IP address that your connection arrives from. There is no target field, and continuing past the pre-scan countdown is treated as your authorization to scan that IP.
Free scans stream live to your terminal. Full scans return asynchronously, while Deep scans email a report and a self-expiring results link.
Free scans are limited to one scan per 24 hours per IP. Full scans are limited to one per hour per key, and Deep scans are one-time credits with no per-IP cooldown.
The service refuses known CGNAT and mobile-carrier connections, IPv6 origins, and connections flagged as proxy, VPN, or Tor/relay. Those restrictions apply to paid tokens too.
It uses naabu for port discovery, nmap with the vulners script for service and CVE mapping, and nuclei with the public nuclei templates for vulnerability checks.
ByteAsk is a terminal-first AI coding agent for C and C++ that edits repos and verifies changes with compilers, debuggers, sanitizers, and tests.
Manta AI is an autonomous web app testing tool that maps app behavior, catches regressions, and generates tests from a URL, no scripts or selectors needed.
CreateOS Sandbox is an isolated compute environment for running code and agent workloads in Firecracker micro-VMs with private networking and SDK, CLI, or MCP control.
hob is an independent workspace for coding agents, with local control over sessions, terminals, history, routing, and follow-up work.
ClawTick is an AI agent automation platform for scheduling jobs from the CLI, dashboard, or REST API. Built for developers and teams using LangChain, CrewAI, webhooks, or custom workflows with monitoring, alerts, and logs.
Redline is a budgeting tool for Claude Code that paces sessions by time, tokens, cost, or plan percentage, helping them end with a usable result.