{"uid":"cap_IfdIJrjV3F19f_fZmD6hX","slug":"x402-deployer-x402-deployer-workers-dev-62d7c60a","name":"NPM Package Risk Scanner","description":"npm package risk score / supply-chain scanner / typosquat detector. Maintainer count, weekly downloads, install scripts, dependency depth, deprecation, age, typosquat distance to popular packages. Plus LLM risk summary.","url":"https://x402-deployer.x402-deployer.workers.dev/package-risk-npm","method":"POST","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method","bodyType","body"],"properties":{"body":{"required":["package_name"],"properties":{"version":{"type":"string","description":"Optional specific version (e.g. '4.17.21'). Default: latest tagged version."},"package_name":{"type":"string","description":"npm package name. Supports scoped names (e.g. '@types/node', '@vercel/next')."}}},"type":{"type":"string","const":"http"},"method":{"enum":["POST"],"type":"string"},"bodyType":{"enum":["json","form-data","text"],"type":"string"}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object","properties":{"score":{"type":"integer"},"factors":{"type":"array","items":{"type":"object","properties":{"value":{},"factor":{"type":"string"},"weight":{"type":"string"}}}},"summary":{"type":"string"},"version":{"type":"string"},"risk_level":{"type":"string"},"package_name":{"type":"string"},"typosquat_candidates":{"type":"array"}}}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.030000","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"settled","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.030000/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_aOMB6E-EamddHzkZLs7rr","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.03","costPer":"request","priority":0,"asset":null,"unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Analyzes an npm package for supply-chain risk, including maintainer count, download stats, install scripts, dependency depth, deprecation, age, typosquat detection, and an LLM-generated risk summary.","exampleAgentPrompt":"Can you scan the npm package 'colo' and tell me if it looks like a typosquat of 'colors', how risky it is, and whether it has any suspicious install scripts or sketchy maintainer details?","exampleUseCases":[{"title":"Validate third-party deps before merging","prompt":"I'm about to merge a PR that adds a new package called 'expresss-middleware' to our dependencies. Can you run a supply-chain risk check on it and let me know if it seems legit or if it might be a typosquat of something popular?"},{"title":"Audit legacy project dependencies","prompt":"We inherited an old Node project with hundreds of dependencies and no clear audit trail. Can you scan these packages for red flags—especially ones with few maintainers, old ages, or suspicious names that might be typosquats?"},{"title":"Block risky packages in CI pipeline","prompt":"Set up an automated gate in our deployment pipeline that checks every new npm dependency we try to install and flags anything with a high risk score, missing maintainers, or install scripts. What should I feed into this scanner?"}],"resultDescription":"Returns a structured risk profile including a numeric risk score, maintainer count, weekly download figures, presence of pre/post-install scripts, dependency depth, deprecation flag, package age, typosquat Levenshtein distance to popular packages, and an LLM-generated plain-English risk summary explaining the key concerns.","failureModes":["Package name not found on npm registry — returns 404 or error indicating unknown package","Network timeout fetching npm registry data — returns 5xx error","Malformed or empty package name input — returns validation error","LLM summary generation failure — may return partial data without the risk narrative","Rate limiting or payment failure — request rejected with payment-required error"],"whenToPreferThis":"Use this endpoint when an AI agent needs to evaluate whether an npm package is trustworthy before recommending or installing it — especially for unfamiliar, newly published, or suspiciously named packages. Ideal for automated dependency auditing workflows, CI/CD security gates, or any scenario where you want a combined heuristic + LLM risk assessment rather than just raw registry metadata.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T06:44:43.391Z","isFirstParty":false}