{"uid":"cap_-f5duKOFR30Tpu79lTqlF","slug":"dep-doctor-npm-dependency-security-screener-6201da9f","name":"Dep Doctor – npm Dependency Security Screener","description":"Screen declared npm packages before you install them. POST package.json (optional lockfile) ($0.02). After payment we look up each name on the npm registry and OSV: missing/hallucinated packages, lookalikes, brand-new publishes, deprecations, known CVEs. Returns 0–100, do_this_first, ci_failed. Caps at 60 packages; never fetches buyer URLs. Report: GET /v1/tools/dep-doctor/report?project=your-app.","url":"https://quietstore-production.edge-7e13f.workers.dev/v1/tools/dep-doctor","method":"POST","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method","bodyType","body"],"properties":{"body":{"type":"object"},"type":{"type":"string","const":"http"},"method":{"enum":["POST"],"type":"string"},"bodyType":{"enum":["json"],"type":"string"}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_ShoK1CEFq9NK_dqWQmZLy","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Screens a project's npm packages for supply chain risks including hallucinated/missing packages, typosquatting lookalikes, brand-new suspicious publishes, deprecations, and known CVEs, returning a 0–100 safety score.","exampleAgentPrompt":"Before I run npm install, screen my package.json for hallucinated packages, typosquatting lookalikes, and known CVEs — I need the safety score and whether CI should be blocked.","exampleUseCases":[{"title":"Pre-install dependency safety check","prompt":"I'm about to install all the packages in my package.json for a new Node.js project — can you run them through dep-doctor first and tell me the safety score and if anything looks like a fake or malicious package?"},{"title":"CI pipeline gate for npm audits","prompt":"We want to block deployments in our CI pipeline if our npm dependencies score below 80 — can you scan our current package.json and lockfile and flag anything that would cause a failure?"},{"title":"Detecting AI-hallucinated packages","prompt":"Our AI coding assistant suggested a few npm packages that I want to verify actually exist and aren't hallucinated or newly published fakes — can you run them through dep-doctor and tell me which ones are suspicious?"}],"resultDescription":"Returns a JSON object with: a 0–100 integer safety score, a do_this_first field highlighting the most urgent issue to address, and a ci_failed boolean indicating whether the package set should block CI. Individual findings may include missing/hallucinated packages, lookalike names, packages published very recently, deprecated packages, and CVEs sourced from the OSV database. Caps at 60 packages per request.","failureModes":["Payment not received or underpaid – endpoint returns 402 Payment Required before processing","More than 60 packages submitted – request is rejected or truncated with an error","Malformed package.json body – returns 400 with parsing error","npm registry or OSV lookup timeout – may return partial results or a 503","Package name too ambiguous to resolve – flagged as unresolvable in output"],"whenToPreferThis":"Choose this endpoint when you need a fast, low-cost pre-install or pre-deploy screen of npm dependencies for supply chain risks — particularly when AI-generated code may have introduced hallucinated package names, or when you want OSV CVE checks combined with typosquatting and novelty detection in a single call. Prefer over manual npm audit when you need a composite 0–100 score and ci_failed signal for automated gating.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T18:37:26.468Z","isFirstParty":false}