{"uid":"cap_9SBk8uzLWydD0tJLLpb5J","slug":"manifest-audit-pypi-package-security-auditor-226af3ee","name":"manifest-audit PyPI Package Security Auditor","description":"Check Python packages from PyPI before you pip install or bump versions. Send {\"packages\":[\"requests==2.25.0\",\"flask>=2.0\"]} or {\"requirements\":\"<requirements.txt text>\"}, up to 50 packages. Per package: latest release and date, whether a pinned version is behind, license, yanked status, requires_python, and known vulnerabilities from OSV with severity and first fixed version. Deterministic, no LLM.","url":"https://audit.152-53-82-29.sslip.io/v1/pypi?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"packages":{"type":"array","items":{"type":"string"},"description":"PyPI requirement lines"},"requirements":{"type":"string","description":"Raw requirements.txt text"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.005","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.005/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_oORheZ28gOdv2LQgFJQVh","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.005","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Audits Python PyPI packages for vulnerabilities, license info, version staleness, yanked status, and Python compatibility before installation or version bumps","exampleAgentPrompt":"Before I run pip install, can you audit these packages for known vulnerabilities, license info, and whether any versions are outdated or yanked: requests==2.25.0, flask>=2.0, and django==3.2.1?","exampleUseCases":[{"title":"Pre-deployment dependency security scan","prompt":"I'm about to deploy my Python app — can you audit these packages for vulnerabilities, yanked versions, and license issues before I push: requests==2.28.0, cryptography==38.0.1, pyjwt==2.4.0, and sqlalchemy==1.4.40?"},{"title":"Requirements.txt safety check","prompt":"Here's my requirements.txt — can you scan all of it for known CVEs, outdated pinned versions, and any packages that have been yanked from PyPI? I want severity levels and the first fixed version for anything flagged."},{"title":"Single package upgrade risk assessment","prompt":"I'm thinking of upgrading to pillow==9.0.0 — is that version behind the latest, does it have any known vulnerabilities from OSV, and what Python versions does it support?"}],"resultDescription":"A per-package breakdown including: the latest available release and its publish date, whether the specified version is behind latest, SPDX license identifier, whether the version has been yanked from PyPI, the requires_python field, and any known vulnerabilities from the OSV database with severity rating and the first version that fixes each issue.","failureModes":["Package name not found on PyPI returns an error for that entry","More than 50 packages submitted returns a 400-class error","Malformed requirement specifier (e.g. invalid version syntax) causes parsing failure for that line","OSV database may not have real-time coverage of very newly disclosed CVEs","Network timeout if PyPI or OSV APIs are slow to respond"],"whenToPreferThis":"Use this endpoint when you need a deterministic, non-LLM audit of Python/PyPI packages specifically — covering vulnerabilities, version staleness, yanked status, license, and Python compatibility in one call. Prefer it over generic vulnerability scanners when you need structured per-package OSV data with first-fixed-version information, or when you want to validate a full requirements.txt before a deploy or dependency bump. Choose the combined npm+PyPI sibling endpoint if you have a mixed-language project.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T02:29:34.851Z","isFirstParty":false,"canonicalSlug":"manifest-audit-pypi-package-security-auditor-226af3ee"}