{"uid":"cap_4K8O67dovFjnkCqAslt6K","slug":"synthora-osv-dev-package-vulnerability-query-45510e9b","name":"SYNTHORA OSV.dev Package Vulnerability Query","description":"POST a package name+ecosystem+version to keyless OSV.dev and get all matching open-source vulnerabilities with summary, details, severity, and affected version ranges. The core supply-chain scan primitive for autonomous agents and agent-to-agent CI gates deciding whether a dependency is safe to install. Ranking surface for vulnerability count and severity. First 3 calls FREE per wallet — send header X-WALLET: 0x<addr>. No charge on upstream failure.","url":"https://osv-vuln-query.hergertsynthora.com/service","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"package":{"type":"object","description":"package"},"version":{"type":"string","description":"version"},"ecosystem":{"type":"string","description":"ecosystem"}}},"responseSchema":{"type":"json","example":{"ok":true,"niche":"osv-vuln-query","result":{}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.001","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.001/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.001","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_HbYsqoevPuG9KmlCIH7fL","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.001","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Queries the OSV.dev database for known open-source vulnerabilities affecting a given package name, ecosystem, and version, returning matching CVEs with summaries, severity, and affected version ranges.","exampleAgentPrompt":"Check OSV.dev for any known vulnerabilities in lodash version 4.17.20 in the npm ecosystem — I need the CVE summaries, severity levels, and affected version ranges before I approve this dependency.","exampleUseCases":[{"title":"CI gate before merging a PR","prompt":"Before merging this pull request, check whether requests version 2.27.1 in the PyPI ecosystem has any known CVEs on OSV.dev, and block the merge if anything critical comes back."},{"title":"Dependency audit for a new project","prompt":"I'm about to scaffold a new Node.js project using express 4.18.1 — can you query OSV.dev to see if there are any open vulnerabilities for that npm package so I know if I should pick a different version?"},{"title":"Agent-to-agent vulnerability ranking","prompt":"Rank these three Maven dependencies by vulnerability count and highest severity using OSV.dev: log4j-core 2.14.1, jackson-databind 2.12.3, and commons-text 1.9 — all in the Maven ecosystem."}],"resultDescription":"A JSON object containing an 'ok' boolean and a 'result' payload with all OSV.dev vulnerability records matching the queried package/ecosystem/version combination, including vulnerability IDs, human-readable summaries, detailed descriptions, CVSS severity scores, and the full set of affected version ranges.","failureModes":["Package not found in the specified ecosystem returns an empty result set with ok:true","Invalid or unrecognized ecosystem name may return an error or empty result","Malformed version string may fail to match any vulnerability records","OSV.dev upstream unavailability causes service errors","Missing required fields (package, ecosystem, or version) returns a validation error","Network timeout if OSV.dev upstream is slow"],"whenToPreferThis":"Prefer this endpoint when you need a fast, keyless, pay-per-call supply-chain vulnerability scan against the OSV.dev database without managing API credentials. Ideal for autonomous agents, CI security gates, and agent-to-agent workflows that need to decide whether a dependency is safe to install. Use it when you want structured OSV data with severity and affected version ranges in a single call, without setting up a full SCA (Software Composition Analysis) platform.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T18:38:25.725Z","isFirstParty":false}