{"uid":"cap_MdW2HQt9NgqIXfrPPM7Tt","slug":"payperbyte-package-verdict-oracle-6a293bec","name":"PayPerByte Package Verdict Oracle","description":"Signed ALLOW/WARN/BLOCK on installing a package@version: OSV.dev malicious-corpus + typosquat distance + registry signals. Verify before you install.","url":"https://x402.payperbyte.io/feeds/pkg-verdict","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"package":{"type":"string","maxLength":214,"description":"Package name (npm scoped names like @scope/name allowed; PyPI names are PEP-503-normalized for matching)."},"version":{"type":"string","maxLength":64,"description":"Exact version to judge. Omitted => the registry's latest is resolved and pinned into answer.query.version."},"ecosystem":{"enum":["npm","pypi"],"type":"string","description":"Package ecosystem."}}},"responseSchema":{"type":"json","example":{"_note":"Illustrative response shape — not a live answer. ALLOW/WARN/BLOCK is a screening signal. The embedded EIP-712 receipt (domain chainId 421614 = Arbitrum Sepolia, a frozen signing namespace, not a settlement rail) proves who signed the exact answer bytes — not that the verdict is correct.","answer":{"v":"pkg-verdict/v1","query":{"package":"left-pad","version":null,"ecosystem":"npm","version_requested":null},"score":96,"reasons":["illustrative — real answers cite the pv-v1 OSV.dev / typosquat / registry / known-bad signals judged"],"verdict":"ALLOW","methodology":"pv-v1"},"attestation":{"domain":{"name":"BYTE Library","chainId":421614,"version":"1"},"signer":"0x…","signature":"0x…","payloadHash":"0x…"}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_0NTGEgN6q_3IvEN4OvaR4","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.1","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns a cryptographically attested ALLOW/WARN/BLOCK security verdict for an npm or PyPI package, with EIP-712 provenance signing.","exampleAgentPrompt":"Is the npm package 'event-stream' safe to use? Give me a signed security verdict — check if it's malicious, a typosquat, or flagged by any known-bad signals.","exampleUseCases":[{"title":"Pre-install dependency safety check","prompt":"Before I install 'colors' from npm, can you check whether it's safe or if there have been any known malicious releases or supply chain issues?"},{"title":"CI pipeline package screening","prompt":"Screen the PyPI package 'cryptography' version 41.0.3 for me — I need an ALLOW, WARN, or BLOCK verdict with a signed receipt before my build pipeline proceeds."},{"title":"Typosquat detection for suspicious package","prompt":"I found a package called 'reacts' on npm — can you check if it's a typosquat or otherwise malicious? Give me the full verdict with attestation."}],"resultDescription":"A JSON object containing: a verdict field (ALLOW, WARN, or BLOCK), a numeric security score (0-100), an array of reasons citing signals from OSV.dev, typosquat detection, registry metadata, and known-bad lists, a pinned resolved version, and an EIP-712 attestation object with the signer address, signature, payload hash, and BYTE Library domain info (Arbitrum Sepolia chainId 421614) proving who signed the exact answer bytes.","failureModes":["Package not found in the specified ecosystem — registry lookup fails","Invalid or non-existent version string — version resolution fails","Unsupported ecosystem value (only npm and pypi accepted)","Package name exceeds 214-character limit","Payment not received or x402 payment header invalid — 402 response returned","Attestation signer address cannot be recovered — signature malformed","Network timeout contacting upstream registries or OSV.dev"],"whenToPreferThis":"Use this endpoint when you need a cryptographically attested, tamper-evident security verdict for a specific npm or PyPI package before installation, publishing, or deployment — especially in agentic pipelines where you need an on-chain-anchored EIP-712 signature to prove provenance. Prefer this over generic vulnerability databases when you need a single ALLOW/WARN/BLOCK decision signal with signed accountability, or when screening for typosquats alongside CVE data. Not suited for bulk dependency audits (single package per call) or ecosystems beyond npm and PyPI.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T00:39:51.774Z","isFirstParty":false}