{"uid":"cap_4Tt0HedeC2-Hnf2vTCfOt","slug":"npm-trust-check-1585d274","name":"npm Trust Check","description":"npm package trust check / risk score / security audit: registry age, weekly downloads, GitHub org/stars, OSV.dev vulnerabilities, typosquat detection.","url":"https://x402-api-catalog.onrender.com/api/trust-check","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"type":"object","required":["package"],"properties":{"repo":{"type":"string","description":"owner/repo override if npm metadata lacks a repo link"},"package":{"type":"string","description":"npm package name to check"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object","properties":{"score":{"type":"number"},"package":{"type":"string"},"verdict":{"type":"string"}}}}}}},"responseSchema":{"type":"json","example":{"score":72,"package":"left-pad","reasons":[],"signals":{},"verdict":"trustworthy"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_Ms7VMD2670y9aMBjlxWoW","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns a trust/risk score for an npm package based on registry age, weekly downloads, GitHub org/stars, and OSV.dev vulnerability data.","exampleAgentPrompt":"Can you check the trust score for the 'lodash' npm package — I want to know if it's safe and well-maintained before I add it as a dependency?","exampleUseCases":[{"title":"Vetting a new npm dependency","prompt":"Before I add 'axios' to my project, can you pull its trust and risk score — I want to see its download numbers, how old it is, any known vulnerabilities, and whether it's backed by a legit GitHub org?"},{"title":"Auditing a suspicious package","prompt":"I found a package called 'colors2023' in our package.json that I don't recognize — can you run a trust check on it and tell me if it looks risky or legitimate?"},{"title":"Comparing packages before adoption","prompt":"We're deciding between 'node-fetch' and 'got' for HTTP requests — can you get the trust scores for both so we can compare their security posture and community health?"}],"resultDescription":"Returns a trust score (numeric), a verdict string (e.g. trusted, risky, unknown), and the package name. Underlying data draws from npm registry age, weekly download counts, GitHub organization and star count, and known OSV.dev vulnerability records.","failureModes":["Package not found on npm registry — returns an error or low-confidence score","No GitHub repo link in npm metadata and no repo override provided — GitHub signals may be missing","OSV.dev API unavailable — vulnerability data may be incomplete","Invalid or misspelled package name — returns error","Rate limiting or upstream timeouts from GitHub or OSV.dev"],"whenToPreferThis":"Choose this endpoint when you need a quick, composite trust signal for an npm package before adding it as a dependency, auditing an existing dependency, or evaluating open-source supply chain risk. It aggregates multiple signals (registry longevity, community adoption, GitHub credibility, known CVEs) into a single score, saving you from querying npm, GitHub, and OSV.dev separately.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T18:30:13.055Z","isFirstParty":false}