{"uid":"cap_Gga-_FnFelxKSOV3B603Z","slug":"beyourspace-npm-package-risk-api-e664f9cd","name":"beyourspace npm Package Risk API","description":"Endpoints de pago por uso para extraer datos de texto, leer páginas públicas y transformar CSV en JSON normalizado. Sin cuentas ni permanencia, con esquemas documentados y ejemplos ejecutables.","url":"https://api.beyourspace.es/v1/riesgo-paquete-npm","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"paquete":{"type":"string"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.004","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.004/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.004","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.004","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_f3O29AOYpvaYv1_fdxHTX","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.004","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns license, repository, dependency count, and known vulnerabilities (OSV.dev) for a specific npm package version","exampleAgentPrompt":"Can you check the npm package 'lodash' version 4.17.21 for known security vulnerabilities, its license, and how many dependencies it has?","exampleUseCases":[{"title":"Pre-install security audit of npm package","prompt":"Before I add 'axios' version 1.6.0 to our project, can you check if it has any known vulnerabilities, what license it uses, and how many dependencies it pulls in?"},{"title":"License compliance check for open source package","prompt":"I need to know what license 'react' version 18.2.0 uses — can you look it up and also tell me if there are any known security issues with it?"},{"title":"Supply chain risk assessment for CI pipeline","prompt":"Can you pull the OSV vulnerability data and dependency count for 'minimist' version 1.2.5 so I can decide whether to block it in our dependency policy?"}],"resultDescription":"A JSON object containing the package license, repository URL, total number of dependencies, and a list of known vulnerability advisories sourced from OSV.dev, each with advisory ID, severity, and source references.","failureModes":["Package name not found on npm registry — returns error or empty result","Specific version does not exist — version not found error","OSV.dev upstream unavailable — vulnerability data may be incomplete or stale","Malformed package name input — validation error returned","Network timeout fetching registry or OSV data"],"whenToPreferThis":"Use this endpoint when you need a consolidated risk snapshot (license + deps + CVEs) for a specific npm package version in a single call. Prefer it over manual OSV.dev queries or npm info commands when building automated dependency auditing pipelines, CI gates, or agent-driven supply chain checks. It is particularly useful when you need OSV advisory sources cited alongside the vulnerability count.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-18T06:46:51.755Z","isFirstParty":false}