{"uid":"cap_1P6yZVxkWO5a8RPHlArWZ","slug":"sitesignal-npm-latest-release-risk-pack-31a3c22c","name":"SiteSignal npm Latest Release Risk Pack","description":"Combine current npm registry metadata, last-week downloads, and exact-latest-version OSV records into a bounded release review-priority pack.","url":"https://phases-prot-shine-royal.trycloudflare.com/x402/npm-release-risk-pack","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["package"],"properties":{"package":{"type":"string","description":"Public scoped or unscoped npm package name."}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_oMYba7xjjaePyb70qrapW","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.1","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches a combined npm package risk snapshot including registry metadata, last-week download counts, and OSV vulnerability records for the exact latest version.","exampleAgentPrompt":"Can you pull a risk pack for the npm package 'lodash' — I want to see its latest registry metadata, last-week downloads, and any OSV vulnerabilities for the current latest version before I approve the dependency update?","exampleUseCases":[{"title":"Pre-merge dependency approval check","prompt":"Before we merge this PR that bumps 'axios' to latest, can you pull a release risk pack for the axios npm package so I can see its current metadata, weekly download popularity, and any known OSV vulnerabilities?"},{"title":"Security audit of a newly proposed library","prompt":"We're considering adding 'jsonwebtoken' as a new dependency — can you get me the npm risk pack for it so I can review its latest release metadata, how widely it's downloaded, and whether there are any open security advisories?"},{"title":"Monitoring a critical package for new CVEs","prompt":"Can you check the npm release risk pack for 'semver' right now? I want to know if the latest version has any new OSV vulnerabilities and how its weekly download numbers look compared to what I'd expect for a widely-used package."}],"resultDescription":"Returns a bounded JSON pack containing: npm registry metadata for the package (description, latest version, author, license, repository), last-week download count from the npm stats API, and OSV vulnerability records matched to the exact latest version — structured for quick release review prioritization.","failureModes":["Package not found on npm registry — returns error if the package name is misspelled or does not exist","Private or restricted packages may not return complete metadata","OSV database may have no records for a safe package, returning an empty vulnerabilities list","Rate limiting or upstream npm/OSV API timeouts may cause partial or failed responses","Scoped package names must be properly formatted (e.g. @scope/package)"],"whenToPreferThis":"Choose this endpoint when you need a single bounded call that combines npm registry metadata, download popularity, and OSV security advisories for the latest version of a package — especially useful for dependency approval workflows, pre-merge security gates, or supply-chain audits where aggregating these three sources manually would require multiple API calls.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T16:26:31.253Z","isFirstParty":false}