{"uid":"cap_9mTIO7kMD2kKKlmvEVE9w","slug":"repo-health-scan-vulnerability-watch-d9d7f9c8","name":"Repo Health Scan + Vulnerability Watch","description":"Cross-verified: GitHub repo metadata: license, stars, maintenance state. Combined with osv vulnerability scan for a package with a pinned-or-upgrade verdict.","url":"https://k2so.wrong.systems/api/services/repo-health-scan-vulnerability-watch","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"type":"object","properties":{"meta":{"enum":["0","1"],"type":"string","description":"Set to 1 for free metadata JSON (no payment required)"},"repo":{"type":"string","description":"Composite input parameter"},"package":{"type":"string","description":"Composite input parameter"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object","title":"Repo Health Scan + Vulnerability Watch paid response","$schema":"https://json-schema.org/draft/2020-12/schema","required":["ok","paid","service","provider","result"],"properties":{"ok":{"type":"boolean"},"paid":{"type":"boolean"},"result":{"type":"object","required":["ok","service"],"properties":{"ok":{"type":"boolean","description":"Handler success"},"score":{"type":"number"},"service":{"type":"string","description":"Service slug"},"summary":{"type":"string"},"evidence":{"type":"object"},"strengths":{"type":"array","items":{"type":"string"}},"confidence":{"type":"string"},"generatedAt":{"type":"string","description":"ISO-8601 timestamp"},"riskFactors":{"type":"array","items":{"type":"string"}}}},"payment":{"type":"object","properties":{"code":{"type":"string"},"payer":{"type":"string"},"detail":{"type":"string"},"selfPay":{"type":"boolean"},"transaction":{"type":"string"}}},"service":{"type":"string"},"provider":{"type":"string","const":"K-2SO"}}}}}}},"responseSchema":{"type":"json","example":{"ok":true,"paid":true,"result":{"ok":true,"service":"repo-health-scan-vulnerability-watch"},"service":"repo-health-scan-vulnerability-watch","provider":"K-2SO"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.05","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.05/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_CIFdq62NcAfs41YE5fPmH","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.05","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Combines GitHub repository metadata (license, stars, maintenance state) with OSV vulnerability scanning for a package, returning a pinned-or-upgrade verdict and health score.","exampleAgentPrompt":"Can you scan the repo 'expressjs/express' and the 'express' npm package for known vulnerabilities and tell me whether I should pin or upgrade my dependency, along with the overall health score?","exampleUseCases":[{"title":"Pre-merge dependency vetting","prompt":"Before I merge this PR, can you check the GitHub repo 'lodash/lodash' and the 'lodash' package for vulnerabilities and maintenance issues — I need to know if it's safe to keep it pinned at the current version or if I should upgrade?"},{"title":"New open source library evaluation","prompt":"I'm thinking of adding 'requests' as a Python dependency — can you pull the health data for 'psf/requests' on GitHub and run a vulnerability scan on the 'requests' package so I know if it's well-maintained and CVE-free?"},{"title":"Security audit of legacy codebase","prompt":"We have 'moment/moment' in our legacy app and I've heard it's deprecated — can you check the repo health and vulnerability status for the 'moment' package and tell me the risk factors and whether I should pin or migrate?"}],"resultDescription":"Returns a JSON object with an overall health score (0-1), a pinned-or-upgrade verdict, a plain-English summary, a confidence rating, a list of strengths, a list of risk factors, and raw evidence combining GitHub metadata (stars, license, maintenance state) and OSV vulnerability findings. Also includes an ISO-8601 generatedAt timestamp.","failureModes":["Unknown or private repository returns an error in the result object with ok:false","Package not found in OSV database results in empty vulnerability findings","Missing required 'repo' or 'package' query parameters causes a 400-level error","Payment not made results in a 402 response requiring USDC payment before data is returned","Stale or rate-limited GitHub API data may reduce evidence completeness"],"whenToPreferThis":"Choose this endpoint when you need a combined, cross-verified view of both repository health and package vulnerability status in a single call, rather than querying GitHub and OSV separately. Ideal for automated dependency review pipelines, pre-merge checks, or supply chain audits where you need a structured pinned-or-upgrade recommendation with a confidence score rather than raw data.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T15:25:42.103Z","isFirstParty":false}