{"uid":"cap_KRmpwFYz-7k3Y9ugqwzGr","slug":"agent-trust-api-npm-package-trust-risk-score-292c820e","name":"Agent Trust API – npm Package Trust & Risk Score","description":"Trust/risk score for an npm package: registry age, downloads, GitHub signals, and OSV.dev vulnerabilities.","url":"https://agent-trust-api-496e.onrender.com/api/trust-check","method":"GET","headers":{},"bodySchema":{"type":"object","properties":{"properties":{"type":"string"}}},"responseSchema":{"type":"json","example":{"score":72,"package":"left-pad","signals":{"npm":{"ageInDays":3200,"latestVersion":"1.3.0","weeklyDownloads":1500000},"github":{"org":"left-pad","isOrg":false,"stars":400,"createdAt":"2014-01-01"},"vulnerabilities":{"ids":[],"count":0}},"verdict":"reasonable"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_2dg2kzC1zxajC6-BiPyFU","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns a composite trust/risk score for an npm package by aggregating registry age, download volume, GitHub signals, and known OSV.dev vulnerabilities.","exampleAgentPrompt":"Can you check the trust score for the npm package 'left-pad' — I want to know if it's safe to add as a dependency, including any known vulnerabilities and how popular it is?","exampleUseCases":[{"title":"Vetting a new npm dependency","prompt":"Before I add 'axios' to our project, can you run a trust check on it and tell me the score, any known vulnerabilities, and how many weekly downloads it gets?"},{"title":"Automated CI security gate","prompt":"As part of our pull request pipeline, check the trust score for the npm package 'lodash' and flag it if the score is below 60 or it has any open CVEs."},{"title":"Auditing unfamiliar transitive dependency","prompt":"I noticed 'event-stream' in our lock file and I've never heard of it — can you pull its trust score, GitHub star count, and any OSV vulnerabilities so I can decide whether to remove it?"}],"resultDescription":"A JSON object containing a numeric trust score (0–100), the package name, a human-readable verdict (e.g. 'reasonable', 'risky'), and a signals breakdown: npm signals (age in days, latest version, weekly downloads), GitHub signals (org, star count, creation date), and vulnerability data (list of OSV IDs and total count).","failureModes":["Unknown or misspelled package name returns an error or zero-score result","Private/scoped packages not published on the public npm registry may not resolve","GitHub repository not linked to the npm package results in missing GitHub signals","OSV.dev API downtime may cause vulnerability data to be incomplete or absent","Rate limiting or cold-start latency on the Render-hosted service may cause timeouts"],"whenToPreferThis":"Choose this endpoint when you need a quick, multi-signal trust summary for a specific npm package without building your own aggregation pipeline. It combines npm registry metadata, GitHub reputation signals, and OSV vulnerability data into a single scored verdict — ideal for CI gates, dependency vetting workflows, or supply-chain risk dashboards. Prefer it over raw OSV.dev queries when you also need download popularity and registry age context alongside security findings.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T18:30:26.443Z","isFirstParty":false}