{"uid":"cap_65AWPrrWBf0D4V9jlMvu2","slug":"aayat-ai-package-dependency-audit-e0b31cf8","name":"Aayat AI Package Dependency Audit","description":"Audit a whole dependency list in one call: up to 200 exact npm, PyPI, crates or Go package versions checked against OSV.dev for known vulnerabilities and malware. Returns which packages are affected, severity, fixed versions and an overall verdict. POST {ecosystem, packages:[\"name@version\"]} or {ecosystem:\"pypi\", requirements:\"requests==2.31.0\\n...\"}.","url":"https://aayatai.com/package/audit?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"packages":{"type":"array","items":{"type":"string","maxLength":300},"maxItems":200,"description":"Exact versions, e.g. [\"express@4.17.1\", \"lodash@4.17.15\"]."},"ecosystem":{"enum":["npm","pypi","crates","go"],"type":"string","default":"npm","description":"Package ecosystem: npm, pypi, crates (Rust) or go (Go modules)."},"requirements":{"type":"string","maxLength":60000,"description":"Alternative: requirements.txt-style text, one name==version (or name@version) per line."}}},"responseSchema":{"type":"json","example":{"clean":["express@4.21.2"],"counts":{"low":0,"high":3,"unknown":0,"critical":1,"moderate":2},"source":"OSV.dev","checked":2,"verdict":"fix","packages":[{"name":"lodash","version":"4.17.15","upgradeTo":"4.17.21","vulnerabilities":[{"id":"GHSA-p6mc-m468-83gw","url":"https://osv.dev/vulnerability/GHSA-p6mc-m468-83gw","aliases":["CVE-2020-8203"],"fixedIn":["4.17.19"],"summary":"Prototype Pollution in lodash","severity":"high","published":"2020-07-15T19:15:48Z"}]}],"checkedAt":"2026-09-28T12:00:00.000Z","ecosystem":"npm","detailsTruncated":false,"vulnerablePackages":1}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_rDHIw7HTfQL7ZSuI9r3NV","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Bulk-audits up to 200 npm, PyPI, crates, or Go package versions in a single call against OSV.dev for known vulnerabilities and malware, returning affected packages, severities, fix versions, and an overall verdict.","exampleAgentPrompt":"Can you audit these npm packages for known vulnerabilities — express@4.17.1, lodash@4.17.15, and axios@0.21.0 — and tell me which ones need to be upgraded and how severe the issues are?","exampleUseCases":[{"title":"Pre-deploy lockfile security check","prompt":"Before we ship this release, scan these 15 npm packages from our lockfile for any known CVEs or malware: react@18.2.0, webpack@5.88.0, lodash@4.17.15, express@4.17.1, axios@0.21.0, moment@2.29.4, chalk@4.1.2, dotenv@16.0.3, jest@29.5.0, typescript@5.1.6, eslint@8.44.0, babel-core@6.26.3, nodemon@2.0.22, cors@2.8.5, morgan@1.10.0 — give me severity counts and which ones I need to fix."},{"title":"Python requirements.txt vulnerability audit","prompt":"Here's my requirements.txt — can you check all these PyPI packages against known vulnerabilities and tell me which ones are unsafe and what versions I should upgrade to?\n\nrequests==2.28.0\ndjango==3.2.18\nnumpy==1.23.0\npillow==9.0.0\ncryptography==38.0.0"},{"title":"Rust crates security review","prompt":"I'm using these Rust crates in my project and want to know if any have known security issues before I publish: serde@1.0.150, tokio@1.25.0, hyper@0.14.23, openssl@0.10.45, rand@0.8.5 — check them against OSV and tell me the overall verdict and any fixes available."}],"resultDescription":"Returns a JSON object with: a verdict string (e.g. 'fix' or 'clean'), a list of vulnerable packages each with vulnerability IDs, CVE aliases, severity levels, summary, published date, and the version that fixes the issue; a list of clean packages; counts broken down by severity (critical, high, moderate, low, unknown); total number of packages checked; the ecosystem; timestamp; and a flag indicating if details were truncated.","failureModes":["Invalid ecosystem value returns validation error","Package version string not in expected name@version format causes parse failure","More than 200 packages in a single call exceeds limit","OSV.dev upstream unavailability causes service degradation","Malformed requirements.txt input may cause parsing errors","Unknown or unpublished package versions may return no vulnerability data","Payment failure (x402) blocks the request"],"whenToPreferThis":"Use this endpoint when you need to audit a batch of up to 200 packages in a single API call across npm, PyPI, Rust crates, or Go modules. It is ideal for CI/CD pipelines, pre-deploy checks, or agent workflows that need a fast, structured security verdict with fix recommendations. Prefer it over single-package lookup endpoints when dealing with lockfiles or requirements files. It is backed by OSV.dev, which aggregates CVEs, GitHub Security Advisories, and ecosystem-specific advisories, making it more comprehensive than registry-only checkers.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T04:48:50.446Z","isFirstParty":false,"canonicalSlug":"aayat-ai-package-dependency-audit-e0b31cf8"}