{"uid":"cap_Bssnh3pTiYCmW569gZWnP","slug":"package-safety-gate-f69d5786","name":"Package Safety Gate","description":"Check npm package metadata and security before installation.","url":"https://mcp.dropenginehq.com/api/check-package?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"package":{"type":"string","maxLength":214,"minLength":1},"version":{"type":"string","maxLength":128},"ecosystem":{"type":"string","const":"npm"}}},"responseSchema":{"type":"json","example":{"cached":false,"package":"axios","sources":["npm_registry","osv"],"success":true,"degraded":false,"warnings":[],"ecosystem":"npm","checked_at":"2026-09-28T00:00:00.000Z","deprecated":false,"reputation":"neutral","risk_level":"low","risk_score":10,"similar_to":null,"new_package":null,"recommendation":"allow","typosquat_risk":"low","dependency_risk":"low","known_malicious":false,"maintainer_risk":"unknown","risk_confidence":"medium","dependency_count":0,"maintainer_count":null,"package_age_days":null,"resolved_version":"1.7.0","similarity_score":null,"requested_version":null,"suspicious_scripts":[],"dependency_findings":[],"install_script_risk":"low","malicious_confidence":null,"dependencies_analyzed":0,"known_vulnerabilities":[],"data_freshness_seconds":0}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.005","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.005/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_96oYelquhtjdjqV-df3EZ","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.005","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks npm package metadata and security risks before installation to help agents safely resolve dependencies.","exampleAgentPrompt":"Before we install it, can you run a safety check on the npm package 'axios' version '1.6.2' to make sure it's not flagged for any security issues or suspicious metadata?","exampleUseCases":[{"title":"Dependency vetting before install","prompt":"Before I add 'lodash' version '4.17.21' to my project, can you check if it's safe — no known vulnerabilities, not typosquatted, and still actively maintained?"},{"title":"Catching supply chain attacks","prompt":"I want to install 'colors' version '1.4.44-liberty-2' from npm — can you audit it for security issues or anything that looks like a compromised or malicious release?"},{"title":"Agent autonomously vetting new packages","prompt":"My build script wants to pull in 'cross-env' from npm — run a safety gate check on it before you proceed with the installation so I know it's not going to introduce a vulnerability."}],"resultDescription":"Returns npm package metadata and a security assessment including risk flags such as known vulnerabilities, typosquatting indicators, deprecation status, maintainer signals, and an overall safety verdict to inform whether the package is safe to install.","failureModes":["Package name not found on npm registry — returns not-found or error response","Invalid package name format — validation error","Version string does not exist for the given package — version not found error","Ecosystem value other than 'npm' rejected — const constraint violation","Upstream npm registry or security database unavailable — service error"],"whenToPreferThis":"Use this endpoint when an AI agent is about to install or recommend an npm package and needs a quick, paid preflight security check — especially useful in automated CI pipelines, agent-driven dependency resolution, or when evaluating unfamiliar or newly published packages where typosquatting and supply chain attacks are a concern. Prefer this over manual registry lookups when you need a structured, machine-readable safety verdict.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T00:42:00.825Z","isFirstParty":false,"canonicalSlug":"package-safety-gate-f69d5786"}