{"uid":"cap_TKOd6KLeR-atNU4kHRoqm","slug":"pocket-network-taint-check-dependency-security-scanner-a6d22765","name":"Pocket Network Taint Check — Dependency Security Scanner","description":"Pay-per-call access to Pocket Network services. No account, no API key.","url":"https://agent.pocket.network/v1/taint-check?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"options":{"type":"object","properties":{"since":{"type":"string","description":"Only advisories newer than this timestamp (monitor mode)."},"heuristics":{"type":"boolean","description":"Add typosquat, install-script and dormancy signals."}},"description":"Scan options."},"lockfile":{"type":"object","properties":{"format":{"enum":["package-lock.json","pnpm-lock.yaml","yarn.lock","requirements.txt","poetry.lock","uv.lock","Pipfile.lock","Cargo.lock","go.sum"],"type":"string","description":"Lockfile format."},"content":{"type":"string","description":"Raw lockfile content."}},"description":"A raw lockfile."},"components":{"type":"array","items":{"type":"object","properties":{"name":{"type":"string","description":"Package name."},"version":{"type":"string","description":"Package version."},"ecosystem":{"type":"string","description":"e.g. npm, pypi, go, cargo."}}},"description":"Pre-parsed dependencies."}}},"responseSchema":{"type":"json","example":{"data":{},"portal":{"serviceId":"taint-check","provenance":"third-party-supplier","schemaCheck":"passed"}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.005","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.005/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_7Y0jCuRyFngBHu1dkQcyE","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.005","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Scans a dependency lockfile or component list for known-vulnerable and malicious packages, returning per-dependency verdicts sourced from OSV.dev and the OpenSSF Malicious Packages feed.","exampleAgentPrompt":"Can you scan my package-lock.json for any malicious or vulnerable npm packages? I want verdicts for each dependency, including typosquat and install-script heuristics enabled.","exampleUseCases":[{"title":"Pre-deploy supply chain audit","prompt":"Before I ship this release, scan my requirements.txt for any known-malicious or vulnerable Python packages — I want to see a verdict for every dependency with a summary of any issues found."},{"title":"CI security gate for Node project","prompt":"Check this package-lock.json for any npm packages flagged as malicious or vulnerable — only flag advisories newer than 2024-01-01 so I can focus on recent threats in my CI pipeline."},{"title":"Cargo dependency health check","prompt":"Run a security scan on my Cargo.lock — I want to know which Rust crates have known vulnerabilities or have been flagged as malicious, and turn on heuristics to catch suspicious packages too."}],"resultDescription":"A per-dependency list of verdicts (malicious, vulnerable, suspicious, or clean), each with an advisory summary, the data source (OSV.dev or OpenSSF Malicious Packages), and a snapshot timestamp indicating when the advisory data was last updated.","failureModes":["Unsupported lockfile format returns a validation error","Malformed or unparseable lockfile content results in a parse error","Packages not found in OSV.dev or OpenSSF are returned as clean with no advisory data","Very large lockfiles may time out or be rejected if they exceed size limits","Stale snapshot timestamps may mean very recent advisories are not yet reflected","Payment not provided or insufficient USDC results in a 402 Payment Required response"],"whenToPreferThis":"Choose this endpoint when you need a fast, pay-per-call dependency security scan without setting up an account or API key — especially useful for ephemeral CI/CD pipelines, agent workflows, or one-off audits. It is ideal when you need combined coverage from both OSV.dev vulnerability data and the OpenSSF Malicious Packages feed in a single call, with optional heuristics for typosquatting and install-script signals. Prefer it over alternatives when you want to scan raw lockfiles directly without pre-processing.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T18:35:24.660Z","isFirstParty":false,"canonicalSlug":"pocket-network-taint-check-dependency-security-scanner-a6d22765"}