{"uid":"cap_F7miq0Mc73m3M4Kwck9dJ","slug":"vulnfeed-dependency-vulnerability-scanner-5827777d","name":"VulnFeed Dependency Vulnerability Scanner","description":"Dependency vulnerability scanner with EPSS scoring. MCP server + x402 micropayments.","url":"https://vulnfeed-api.novadyne.ai/vulnscan/query","method":"POST","headers":{},"bodySchema":{"type":"object","required":["packages"],"properties":{"packages":{"type":"array","description":"Packages to scan for vulnerabilities"}}},"responseSchema":{"type":"object","properties":{"ok":{"type":"boolean"},"results":{"type":"array","description":"Per-package vulnerability results with EPSS scores"},"scanned":{"type":"integer"},"affected_packages":{"type":"integer"},"total_vulnerabilities":{"type":"integer"}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_47yCKLRXKjZySqyNKQ-35","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Scans a list of software packages for known vulnerabilities and returns EPSS-scored CVE results per package","exampleAgentPrompt":"Can you scan these packages for known vulnerabilities and give me EPSS scores for anything found: lodash@4.17.11, express@4.17.1, and requests==2.25.0?","exampleUseCases":[{"title":"Automated security audit before deployment","prompt":"Before we deploy this release, can you check all the packages in our package-lock.json file for vulnerabilities? I need to know if any have high EPSS scores that we should patch first."},{"title":"Third-party risk assessment for vendors","prompt":"We're considering using this open-source library in production. Can you scan all its dependencies and tell me which ones have known CVEs and what their exploit risk scores are?"},{"title":"Continuous integration vulnerability gate","prompt":"Our CI pipeline needs to fail the build if we introduce any dependencies with critical vulnerabilities. Can you scan the new packages we're adding and give us the EPSS scores so we can decide if they're acceptable?"}],"resultDescription":"Returns an array of per-package vulnerability results including EPSS scores, plus aggregate counts of total packages scanned, affected packages, and total vulnerabilities found.","failureModes":["Empty packages array returns no results","Unknown or misspelled package names may return no vulnerabilities found (false negative risk)","Network or upstream data source unavailable returns error","Malformed package identifiers may cause validation errors","Rate limiting or payment failure may prevent scan from completing"],"whenToPreferThis":"Use this endpoint when you need EPSS-scored vulnerability data for a specific list of software packages — especially useful in CI/CD pipelines, dependency audits, or when you want exploit-probability scoring (EPSS) alongside CVE listings rather than just raw CVE counts.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T00:35:37.317Z","isFirstParty":false}