{"uid":"cap_8UryTPIQV7Q_TyV1zqCEi","slug":"pennyrail-osv-package-dependency-vulnerability-check-f652254b","name":"PennyRail OSV Package Dependency Vulnerability Check","description":"Machine-readable settlement service","url":"https://pennyrail.vercel.app/api/p/micro/security.osv-package--dependency-vulnerability-check","method":"POST","headers":{},"bodySchema":{"type":"object","required":["input"],"properties":{"input":{"type":"object"}}},"responseSchema":{"type":"object","additionalProperties":true},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.004","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.004/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.004","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.004","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_BZrXUvv852TqPi1JZxseb","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.004","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks a software package or dependency for known security vulnerabilities using the OSV (Open Source Vulnerabilities) database","exampleAgentPrompt":"Can you check whether lodash version 4.17.20 in the npm ecosystem has any known security vulnerabilities?","exampleUseCases":[{"title":"Pre-release dependency audit","prompt":"Before I ship this release, check if requests version 2.25.1 in PyPI has any known vulnerabilities I should be worried about."},{"title":"CI pipeline vulnerability gate","prompt":"We're adding a new dependency — can you look up whether log4j-core 2.14.1 in Maven has any critical CVEs so we can decide whether to block the build?"},{"title":"Open source library vetting","prompt":"I want to use the colors npm package version 1.4.0 in my project — does it have any known security issues in the OSV database?"}],"resultDescription":"Returns a vulnerability assessment for the specified package and version, including matched OSV vulnerability records, CVE IDs, severity ratings (CVSS scores), affected version ranges, and available fix versions or patches if known.","failureModes":["Package not found in OSV database returns empty vulnerability list","Unrecognized ecosystem identifier causes lookup failure","Missing package name or version in input returns validation error","Network timeout or OSV upstream unavailability causes 5xx response","Ambiguous package name without ecosystem specified may return incorrect results"],"whenToPreferThis":"Use this endpoint when you need a fast, pay-per-call vulnerability lookup for a specific package and version against the OSV database without setting up your own vulnerability scanning infrastructure. Particularly useful in agent workflows that need to gate on security checks before installing dependencies or shipping releases.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T13:04:01.427Z","isFirstParty":false}