{"uid":"cap_AgPC-mRgEB0Q4erPfZggU","slug":"openssf-scorecard-via-proxy-suverse-io-0767b610","name":"OpenSSF Scorecard via proxy.suverse.io","description":"OpenSSF Scorecard for a public GitHub repo: aggregate score out of 10 plus per-check results for branch protection, code review, maintenance, pinned deps and vulnerabilities. Keyless.","url":"https://proxy.suverse.io/v1/data/suverse-ossf-scorecard","method":"POST","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method","bodyType","body"],"properties":{"body":{"properties":{}},"type":{"type":"string","const":"http"},"method":{"enum":["POST","PUT","PATCH"],"type":"string"},"bodyType":{"enum":["json","form-data","text"],"type":"string"}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.15","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.15/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.15","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.15","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_15PL85wqq5_r7Md4some9","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.15","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Fetches OpenSSF Scorecard results for a public GitHub repository, returning an aggregate security score out of 10 plus per-check breakdowns for branch protection, code review, maintenance, pinned dependencies, and vulnerabilities.","exampleAgentPrompt":"Can you pull the OpenSSF Scorecard for the github.com/expressjs/express repository and tell me the overall score and which security checks it's failing?","exampleUseCases":[{"title":"Vetting an open source dependency","prompt":"Before we add lodash to our project, can you check its OpenSSF Scorecard score on GitHub and flag any checks it's failing, especially around pinned dependencies and branch protection?"},{"title":"Security audit of internal open source project","prompt":"We just open-sourced our tool at github.com/myorg/myrepo — can you run an OpenSSF Scorecard on it and show me the per-check results so I know what to fix?"},{"title":"Comparing security posture of candidate libraries","prompt":"Can you get the OpenSSF Scorecard for github.com/axios/axios and tell me how it scores on code review, maintenance, and vulnerability checks?"}],"resultDescription":"Returns an aggregate OpenSSF Scorecard score out of 10 and individual check scores with pass/fail details for branch protection, code review practices, maintenance activity, pinned dependencies, and known vulnerabilities for the specified public GitHub repository.","failureModes":["Repository not found or is private — scorecard cannot be computed for non-public repos","Invalid or malformed GitHub repository URL in the request body","OpenSSF Scorecard service upstream timeout or unavailability","Payment failure or insufficient USDC balance ($0.15 per call required via x402)","Rate limiting if too many requests are made in quick succession"],"whenToPreferThis":"Choose this endpoint when you need a quick, keyless, structured OpenSSF Scorecard lookup for any public GitHub repository without setting up your own Scorecard infrastructure or managing GitHub API tokens. It is ideal for automated dependency vetting pipelines, security audits, and agent workflows that need to assess open source project health on demand.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T18:56:58.650Z","isFirstParty":false}