{"uid":"cap_E2XI1QteM-18bb-QgDwNG","slug":"salt19-dependency-go-no-go-checker-9a442348","name":"SALT19 Dependency Go/No-Go Checker","description":"SALT19 is an independent applied AI systems lab behind EvoMind governed cognition, the MCP-native Agent Utility Grid, the ARCS research community, AeroClear UAS flight intelligence, and practical software for real-world work.","url":"https://api.salt19.com/v1/dependency-go-no-go","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"package":{"type":"string","maxLength":214,"minLength":1},"version":{"type":"string","maxLength":64}}},"responseSchema":{"type":"json","example":{"reasons":["No OSV vulnerabilities returned","License declared","Recent publication activity"],"verdict":"GO","evidence":{"license":"MIT","package":"hono","version":"4.13.3","vulnerabilities":0},"policy_version":"salt19-dependency-policy-v1"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.2","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.2/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.2","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.2","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_-XEK1pfcOj3MgpI9LhCLN","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.2","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Evaluates an npm/software package and version against vulnerability, license, and activity policies and returns a GO or NO-GO verdict with supporting evidence.","exampleAgentPrompt":"Run a go/no-go dependency check on hono version 4.13.3 — I need to know if it has any vulnerabilities, what its license is, and whether it's been recently maintained.","exampleUseCases":[{"title":"CI/CD dependency safety gate","prompt":"Before we merge this PR, run a go/no-go check on express version 4.18.2 — flag it if there are any OSV vulnerabilities, a non-permissive license, or it looks abandoned."},{"title":"Vetting a new open source library","prompt":"I'm thinking of adding zod version 3.22.4 to our project — can you check if it gets a GO verdict on safety, licensing, and recent activity?"},{"title":"Auditing a flagged transitive dependency","prompt":"Our security team flagged lodash version 4.17.21 as a potential risk — can you run a dependency policy check on it and tell me the verdict and reasons?"}],"resultDescription":"A JSON object containing: a 'verdict' field ('GO' or 'NO-GO'), a 'reasons' array explaining the decision (e.g. vulnerability status, license presence, publication activity), an 'evidence' object with the package name, version, resolved license, and vulnerability count, and a 'policy_version' string identifying the policy applied.","failureModes":["Unknown or misspelled package name returns an error or NO-GO with no evidence","Invalid or malformed version string may return a validation error","Package not found in the vulnerability or registry database may result in incomplete evidence","Rate limiting or payment failure (x402) results in 402 response and no verdict","Network timeouts if upstream OSV or registry APIs are slow"],"whenToPreferThis":"Use this endpoint when you need a structured, policy-backed GO/NO-GO verdict on a software package rather than raw vulnerability data alone. It is ideal for automated dependency gates in CI/CD pipelines, agent-driven code review, or any workflow requiring a single authoritative decision combining vulnerability, license, and maintenance signals under a versioned policy. Prefer this over manually querying OSV or npm registries when you want a normalized, actionable verdict without post-processing.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T12:41:01.594Z","isFirstParty":false}