{"uid":"cap_RMzlXyOvxSIRS3sMeP3Bi","slug":"saylor-innovations-package-vulnerability-check-257dabae","name":"Saylor Innovations Package Vulnerability Check","description":"Package Vulnerability Check (OSV) — Security","url":"https://saylorinnovations.com/api/vuln/check?utm_source=zero.xyz","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","POST","PUT","PATCH","DELETE","HEAD"],"type":"string"},"queryParams":{"type":"object","properties":{"name":{"type":"string","description":"package name (query)"},"version":{"type":"string","description":"installed version (query)"},"ecosystem":{"type":"string","description":"npm | pypi | crates | go | maven | nuget | rubygems | packagist | pub | hex (query)"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string","const":"json"},"example":{"type":"object","required":["name","version","vulnerable","vulnerabilities"],"properties":{"name":{"type":"string"},"version":{"type":"string"},"vulnerable":{"type":"boolean"},"vulnerabilities":{"type":"array","items":{"type":"object"}},"highest_severity":{"type":["string","null"]},"recommended_upgrade":{"type":["string","null"]}}}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.002","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.002/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.002","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_3Vwd5jE38g1Gy9gibGxtI","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.002","costPer":"request","priority":0,"asset":"EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks a specific package version against the OSV database to detect known vulnerabilities and recommend upgrades","exampleAgentPrompt":"Can you check if lodash version 4.17.20 in the npm ecosystem has any known vulnerabilities, and whether I should upgrade?","exampleUseCases":[{"title":"Pre-deploy dependency security audit","prompt":"Before I deploy my app, check whether express version 4.17.1 in the npm ecosystem has any known security vulnerabilities and what the recommended safe version would be."},{"title":"Python package vulnerability check","prompt":"Is requests version 2.25.0 in the pypi ecosystem vulnerable to anything? If so, what's the highest severity and which version should I upgrade to?"},{"title":"Automated CI pipeline security gate","prompt":"Check if log4j version 2.14.1 in the maven ecosystem has any known vulnerabilities — I need to know if it's safe to use in production or if there's a patched version I should switch to."}],"resultDescription":"Returns a JSON object containing the package name, version queried, a boolean 'vulnerable' flag, an array of vulnerability objects from OSV, the highest severity level found (e.g. CRITICAL, HIGH, MEDIUM, LOW, or null), and a recommended upgrade version string (or null if none is available).","failureModes":["Missing required query parameters (name, version, ecosystem) returns an error","Unknown or unsupported ecosystem value returns an error or empty result","Package not found in OSV database returns vulnerable=false with empty vulnerabilities array","Network or upstream OSV API timeout may cause delayed or failed responses","Malformed version string may result in no matches being found"],"whenToPreferThis":"Choose this endpoint when you need a fast, per-package vulnerability check against the OSV database without running a full local scanner. It is ideal for CI/CD pipelines, agent-driven dependency audits, or single-package spot-checks across a wide range of ecosystems including npm, pypi, crates, go, maven, nuget, rubygems, packagist, pub, and hex. It is cheaper and simpler than integrating a full SCA (Software Composition Analysis) tool when only one package needs checking at a time.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-03T00:48:24.092Z","isFirstParty":false,"canonicalSlug":"saylor-innovations-package-vulnerability-check-257dabae"}