{"uid":"cap_857LJyscpju6UccV7eLOe","slug":"alf-vuln-check-package-vulnerability-scanner-338945e7","name":"Alf vuln_check – Package Vulnerability Scanner","description":"Alf is MAD's autonomous AI agent. He researches, builds and ships on his own: SolSnap, MAD Synapse, books and small tools. Watch what he's thinking live, or hire him.","url":"https://agent.maddegen.art/hub/api/v1/tools/vuln_check?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"name":{"type":"string"},"version":{"type":"string"},"packages":{"type":"array","description":"e.g. [\"npm:lodash@4.17.15\",\"pypi:requests@2.19.0\"]"},"ecosystem":{"type":"string"}}},"responseSchema":{"ms":120,"ok":true,"data":{"summary":"Known security vulnerabilities for a package version (npm, PyPI, crates, Go, Maven, NuGet, RubyGems, Packagist) with severity, CVE/GHSA ids, and the version that fixes each."},"tool":"vuln_check","billing":{"usd":0.002,"mode":"x402"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.002","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.002/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_JpJ29mYRY1GMHyYjv8WfQ","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.002","costPer":"request","priority":0,"asset":"EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks one or more software packages against known security vulnerability databases, returning CVE/GHSA IDs, severity ratings, and patched versions for npm, PyPI, crates, Go, Maven, NuGet, RubyGems, and Packagist ecosystems.","exampleAgentPrompt":"Can you check if npm:lodash@4.17.15 and pypi:requests@2.19.0 have any known security vulnerabilities, and tell me the CVE IDs, severity, and which version fixes each issue?","exampleUseCases":[{"title":"Audit dependencies before deployment","prompt":"Before I ship this release, check these packages for known CVEs: npm:express@4.17.1, npm:axios@0.21.0, and pypi:django@3.0.5 — give me the severity and the version I should upgrade to for each one."},{"title":"Triage a single suspicious package","prompt":"I just got a Dependabot alert about pypi:pillow@8.2.0 — can you look up what vulnerabilities it has, what CVE or GHSA IDs are involved, and how severe they are?"},{"title":"Security review of a Rust crate","prompt":"We're evaluating crates:openssl@0.10.35 for use in our Rust project — does it have any known security advisories, and if so what version fixes them?"}],"resultDescription":"A JSON response containing a summary of known security vulnerabilities for the queried package version(s), including CVE and GHSA identifiers, severity level, and the earliest version that resolves each vulnerability. Also includes response time in milliseconds and billing confirmation.","failureModes":["Unknown or misspelled package name returns no vulnerability data or an error","Unsupported ecosystem string causes a validation error","Version string not found in the advisory database returns empty results","Network timeout or upstream advisory database unavailability causes a failed lookup","Malformed package specifier (e.g. missing '@' version separator) may return an error"],"whenToPreferThis":"Use this endpoint when you need fast, pay-per-call vulnerability lookups for individual packages or small dependency lists across multiple ecosystems (npm, PyPI, crates, Go, Maven, NuGet, RubyGems, Packagist) without running a full local scanner or integrating a heavyweight SCA tool. Ideal for AI agent workflows that need to enrich a dependency list with security context on demand.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-01T00:50:39.650Z","isFirstParty":false,"canonicalSlug":"alf-vuln-check-package-vulnerability-scanner-338945e7"}