{"uid":"cap_UW3OLsBkQI0COJO3ux7qb","slug":"api-the402-ai-f6b91dfb","name":"Dependency Vulnerability Audit","description":"Purchase: Dependency Vulnerability Audit","url":"https://api.the402.ai/v1/services/svc_9c54812071f2412b/purchase","method":"POST","headers":{},"bodySchema":{"type":"object","required":["id"],"properties":{"id":{"type":"string"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.263","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.263/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.263","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.263","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_Sx3EK08lv6N3YYQLG_Yhf","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.263","costPer":"request","priority":0,"asset":null,"unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Audits a software project's dependencies for known security vulnerabilities and CVEs","exampleAgentPrompt":"Can you run a dependency vulnerability audit on my project — here's my package.json — and tell me which packages have known CVEs and how severe they are?","exampleUseCases":[{"title":"Pre-release security check for app","prompt":"Before we ship this release, can you scan our requirements.txt and flag any Python packages with critical or high-severity CVEs so we can patch them before the build goes out?"},{"title":"Code review dependency risk scan","prompt":"I'm reviewing this pull request that adds several new npm packages — can you audit the updated package.json and let me know if any of the new dependencies have known vulnerabilities I should flag for the author?"},{"title":"Cargo.toml vulnerability report check","prompt":"Can you take a look at my Rust project's Cargo.toml and give me a full vulnerability report? I want to know which crates have known security issues and what versions I should upgrade to in order to fix them."}],"resultDescription":"A structured vulnerability report listing affected dependencies, associated CVE identifiers, severity levels (critical/high/medium/low), and recommended remediation steps or version upgrades.","failureModes":["Unsupported package ecosystem or manifest format returns an error","Malformed or missing dependency file causes parsing failure","Unknown or private packages may not have vulnerability data","Payment of 0.263 USDC must be completed before results are returned; payment failure blocks execution","Rate limiting or service unavailability may return a 402 or 5xx error"],"whenToPreferThis":"Use this endpoint when you need a quick, pay-per-use dependency vulnerability audit without setting up a full SCA (Software Composition Analysis) pipeline. Ideal for AI agents that need on-demand security scanning as part of a CI workflow or code review process, especially when integrated with the x402 payment protocol on the402.ai marketplace.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T10:25:12.022Z","isFirstParty":false}