{"uid":"cap_KxqduIvH8QFOgG9Ed9b0i","slug":"dependency-trust-package-safety-check-15f2d21b","name":"Dependency Trust Package Safety Check","description":"Should your agent install this package? Vulnerabilities, license, age, popularity, provenance, typosquat lookalikes and a trust score for npm, PyPI, crates.io, Go and Maven, in one call. Pay per call over x402, no API key.","url":"https://dep-trust.agent-utils.workers.dev/v1/package","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["ecosystem","name"],"properties":{"name":{"type":"string","description":"Package name (npm scoped names allowed; Maven as groupId:artifactId; Go as module path)"},"version":{"type":"string","description":"Exact version. Defaults to the registry's latest/default version."},"ecosystem":{"enum":["npm","pypi","cargo","go","maven"],"type":"string","description":"Package ecosystem"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object","properties":{"name":{"type":"string"},"found":{"type":"boolean"},"yanked":{"type":"boolean"},"license":{"type":["string","null"],"description":"SPDX id when known"},"project":{"type":["object","null"],"properties":{"forks":{"type":["integer","null"]},"stars":{"type":["integer","null"]},"scorecard":{"type":["number","null"],"description":"OpenSSF Scorecard 0-10"},"openIssues":{"type":["integer","null"]},"scorecardChecks":{"type":["object","null"]}}},"reasons":{"type":"array","items":{"type":"string"}},"sources":{"type":"array","items":{"type":"string"}},"verdict":{"enum":["ok","review","avoid"],"type":"string"},"version":{"type":"string"},"homepage":{"type":["string","null"]},"isLatest":{"type":"boolean"},"ecosystem":{"enum":["npm","pypi","cargo","go","maven"],"type":"string","description":"Package ecosystem"},"typosquat":{"type":"object","properties":{"isPopular":{"type":"boolean"},"lookalikes":{"type":"array","items":{"type":"object","properties":{"kind":{"type":"string"},"name":{"type":"string"},"rank":{"type":"integer"},"distance":{"type":"integer"}}}},"suspicious":{"type":"boolean"},"popularRank":{"type":["integer","null"]}}},"deprecated":{"type":"boolean"},"provenance":{"enum":["verified","unverified","none"],"type":"string","description":"Build provenance / publish attestation"},"repository":{"type":["string","null"]},"trustScore":{"type":"integer","maximum":100,"minimum":0},"vulnCounts":{"type":"object"},"generatedAt":{"type":"string"},"maintainers":{"type":["integer","null"]},"publishedAt":{"type":["string","null"]},"latestVersion":{"type":["string","null"]},"installScripts":{"type":["array","null"],"items":{"type":"string"},"description":"npm lifecycle scripts that run on install"},"packageAgeDays":{"type":["integer","null"]},"totalDownloads":{"type":["integer","null"]},"versionAgeDays":{"type":["integer","null"]},"versionsBehind":{"type":["integer","null"]},"licenseCategory":{"enum":["permissive","weak-copyleft","copyleft","unknown","none"],"type":"string"},"vulnerabilities":{"type":"array","items":{"type":"object","properties":{"id":{"type":"string"},"url":{"type":"string"},"aliases":{"type":"array","items":{"type":"string"}},"fixedIn":{"type":"array","items":{"type":"string"}},"summary":{"type":"string"},"severity":{"enum":["critical","high","medium","low","unknown"],"type":"string"},"cvssScore":{"type":["number","null"]},"published":{"type":["string","null"]}}}},"weeklyDownloads":{"type":["integer","null"]},"deprecatedReason":{"type":["string","null"]},"firstPublishedAt":{"type":["string","null"]}}}}}}},"responseSchema":{"type":"json","example":{"name":"lodash","found":true,"yanked":false,"license":"MIT","project":{"forks":7000,"stars":60000,"scorecard":6.2,"openIssues":120,"scorecardChecks":{"Maintained":10,"Code-Review":4}},"reasons":["1 high-severity vulnerability(ies) affect 4.17.15","2 medium-severity vulnerability(ies)","single maintainer for a very widely used package (bus factor)"],"sources":["deps.dev","osv.dev","registry.npmjs.org","api.npmjs.org"],"verdict":"review","version":"4.17.15","homepage":"https://lodash.com/","isLatest":false,"ecosystem":"npm","typosquat":{"isPopular":true,"lookalikes":[],"suspicious":false,"popularRank":34},"deprecated":false,"provenance":"none","repository":"https://github.com/lodash/lodash","trustScore":60,"vulnCounts":{"low":0,"high":1,"medium":2,"unknown":0,"critical":0},"generatedAt":"2026-09-06T19:00:00.000Z","maintainers":1,"publishedAt":"2019-07-17T19:10:23Z","latestVersion":"4.18.1","installScripts":[],"packageAgeDays":5249,"totalDownloads":null,"versionAgeDays":2608,"versionsBehind":6,"licenseCategory":"permissive","vulnerabilities":[{"id":"GHSA-29mw-wpgm-hmr9","url":"https://osv.dev/vulnerability/GHSA-29mw-wpgm-hmr9","aliases":["CVE-2020-28500"],"fixedIn":["4.17.21"],"summary":"Regular Expression Denial of Service (ReDoS) in lodash","severity":"medium","cvssScore":5,"published":"2021-02-19T00:00:00Z"}],"weeklyDownloads":173745865,"deprecatedReason":null,"firstPublishedAt":"2012-04-23T16:37:12Z"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_oh6TAxC-Fn3JNqzxHQy03","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns a comprehensive trust score, vulnerability report, license info, typosquat detection, and provenance data for a package across npm, PyPI, crates.io, Go, and Maven ecosystems.","exampleAgentPrompt":"Before we install lodash version 4.17.15 from npm, can you check if it's safe — look up its vulnerabilities, trust score, license, and whether it might be a typosquat?","exampleUseCases":[{"title":"Pre-install security gate in CI pipeline","prompt":"We're about to add requests version 2.28.2 from PyPI to our project — can you check its trust score, any known CVEs, and whether it has a permissive license before we approve the PR?"},{"title":"Typosquat detection for suspicious package","prompt":"Someone on my team wants to install a package called 'colourama' from npm — can you check if it's a typosquat of a popular package and whether it looks suspicious?"},{"title":"Supply chain audit for Rust dependency","prompt":"Can you run a trust check on the 'serde' crate version 1.0.160 from cargo, including its OpenSSF Scorecard, maintainer count, and any vulnerabilities?"}],"resultDescription":"A JSON object containing: a verdict (ok/review/avoid), a numeric trust score (0-100), CVE/vulnerability list with severity and CVSS scores, SPDX license identifier and category, typosquat detection with lookalike names, OpenSSF Scorecard rating, GitHub stars/forks/open issues, maintainer count, download stats, provenance type, deprecation/yanked status, version age and how many versions behind latest, and the data sources used.","failureModes":["Package not found in the specified ecosystem — 'found: false' returned","Ecosystem enum value not one of npm/pypi/cargo/go/maven — 400 error","Version string not recognized or not published — falls back to latest","Registry API timeout causing incomplete data — partial results with available sources listed","Payment not fulfilled — 402 Payment Required response","Malformed Maven groupId:artifactId format — query parse error"],"whenToPreferThis":"Choose this endpoint when you need a holistic, multi-signal trust assessment of an open-source package before installation or dependency approval — especially when you want vulnerability data, license info, typosquat detection, and supply chain provenance all in one call across npm, PyPI, cargo, Go, or Maven. Prefer this over dedicated vulnerability scanners when you also need license compliance, maintainer bus-factor risk, and typosquat checks in a single request without managing API keys.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:34:02.869Z","isFirstParty":false}