{"uid":"cap_4lfgau1lZ6LFVKYOPjoA8","slug":"saylor-innovations-dependency-security-audit-32dee2bb","name":"Saylor Innovations Dependency Security Audit","description":"Dependency Audit — up to 50 packages (OSV) — Security","url":"https://saylorinnovations.com/api/vuln/audit?utm_source=zero.xyz","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","POST","PUT","PATCH","DELETE","HEAD"],"type":"string"},"queryParams":{"type":"object","properties":{"packages":{"type":"string","description":"comma list of ecosystem:name@version, e.g. npm:lodash@4.17.15,pypi:requests@2.19.0 (query)"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string","const":"json"},"example":{"type":"object","required":["packages","vulnerable","results"],"properties":{"results":{"type":"array","items":{"type":"object"}},"packages":{"type":"number"},"upgrades":{"type":"array","items":{"type":"object"}},"vulnerable":{"type":"number"}}}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.005","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.005/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_t7ApplPxKXOHbcz-woHo-","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.005","costPer":"request","priority":0,"asset":"EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks up to 50 software packages against the OSV vulnerability database and returns a list of known vulnerabilities and suggested upgrades","exampleAgentPrompt":"Can you check these npm and pypi packages for known security vulnerabilities: npm:lodash@4.17.15, npm:axios@0.21.1, pypi:requests@2.19.0? I want to know which ones are vulnerable and if there are safer versions to upgrade to.","exampleUseCases":[{"title":"Pre-deploy dependency security check","prompt":"Before I deploy, can you audit these packages for known vulnerabilities: npm:express@4.17.1, npm:jsonwebtoken@8.5.1, npm:mongoose@5.9.0? Flag anything with active CVEs and suggest what to upgrade."},{"title":"Python data science library audit","prompt":"Check these Python packages for security issues: pypi:numpy@1.19.0, pypi:pandas@1.1.0, pypi:pillow@7.2.0, pypi:scikit-learn@0.23.1 — are any of them vulnerable and do they have safe upgrade paths?"},{"title":"CI pipeline vulnerability gate","prompt":"Scan these mixed ecosystem packages for known CVEs so I can decide whether to block the build: npm:lodash@4.17.11, npm:minimist@1.2.0, pypi:requests@2.18.0, pypi:pyyaml@5.1.0."}],"resultDescription":"A JSON object containing the total number of packages checked, the count of vulnerable packages, a detailed results array with per-package vulnerability information, and an upgrades array with recommended safer versions for affected packages.","failureModes":["Malformed package identifier format (missing ecosystem prefix or version) causes the query to fail or return no results","Unsupported ecosystem not recognized by OSV returns empty results","Exceeding 50 packages in a single call may result in truncated or error responses","Packages with very new or obscure vulnerabilities may not yet be indexed in OSV","Network timeout if the OSV database is temporarily unavailable"],"whenToPreferThis":"Choose this endpoint when you need a quick, pay-per-call vulnerability scan for up to 50 packages across multiple ecosystems (npm, pypi, etc.) without maintaining your own OSV integration. It is ideal for CI/CD pipeline checks, pre-deployment audits, or on-demand developer tooling where you want structured JSON output including upgrade recommendations. Prefer it over general web search or manual CVE lookups when you need machine-readable, programmatic results tied directly to specific package versions.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T02:59:18.364Z","isFirstParty":false,"canonicalSlug":"saylor-innovations-dependency-security-audit-32dee2bb"}