{"uid":"cap_VDUvbFyVjg8rsjn82DsJx","slug":"aayat-ai-package-safety-checker-461a0b2d","name":"Aayat AI Package Safety Checker","description":"Should a coding agent install this package? Checks one npm, PyPI, crates or Go package version for known vulnerabilities and malware (OSV.dev), deprecation, typosquat look-alike names, install scripts, licence, downloads, release activity and OpenSSF Scorecard, then gives a verdict (ok/caution/avoid), a 0-100 score and every reason. Pass ?ecosystem=npm&name=express.","url":"https://aayatai.com/package/check?utm_source=zero.xyz","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["name"],"properties":{"name":{"type":"string","maxLength":214,"minLength":1,"description":"Package name, e.g. express, requests, serde or github.com/gin-gonic/gin."},"version":{"type":"string","maxLength":64,"description":"Exact version to check (default: the latest release)."},"ecosystem":{"enum":["npm","pypi","crates","go"],"type":"string","default":"npm","description":"Package ecosystem: npm, pypi, crates (Rust) or go (Go modules)."}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"name":"express","repo":{"forks":16000,"stars":66000,"scorecard":8.1,"openIssues":180},"flags":[{"code":"not-latest","level":"info","message":"A newer version exists: 5.1.0."}],"score":100,"sources":["deps.dev","OSV.dev","npm registry"],"verdict":"ok","version":"4.21.2","isLatest":false,"licences":["MIT"],"releases":{"latest":"5.1.0","versions":280,"firstPublishedAt":"2010-12-29T19:38:25Z","latestPublishedAt":"2026-03-31T14:00:00Z","releasesLast365Days":6},"checkedAt":"2026-09-28T12:00:00.000Z","ecosystem":"npm","deprecated":null,"repository":"https://github.com/expressjs/express","description":"Fast, unopinionated, minimalist web framework","licenceKind":"permissive","lookalikeOf":[],"maintainers":5,"latestVersion":"5.1.0","installScripts":[],"vulnerabilities":[],"weeklyDownloads":41000000,"vulnerabilityCounts":{"low":0,"high":0,"unknown":0,"critical":0,"moderate":0}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.005","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.005/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_0RB-vpTYU-BHSdrA5Eu73","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.005","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks a single npm, PyPI, crates, or Go package version for vulnerabilities, malware, deprecation, typosquats, install scripts, licence, and OpenSSF Scorecard, returning a verdict (ok/caution/avoid) and 0–100 safety score.","exampleAgentPrompt":"Is the npm package `lodash` version 4.17.21 safe to install? Check it for vulnerabilities, malware, deprecation, and any suspicious install scripts, and give me a verdict.","exampleUseCases":[{"title":"Vetting a new npm dependency","prompt":"Before I add `axios` version 1.6.0 to my Node.js project, can you check if it's safe — any known CVEs, is it deprecated, does it have risky install scripts, and what's its licence?"},{"title":"Auditing a Python package for a coding agent","prompt":"My AI coding agent wants to install the PyPI package `requests` — can you run a safety check on it and tell me if the verdict is ok, caution, or avoid, along with the safety score?"},{"title":"Catching a typosquat before it ships","prompt":"Someone submitted a PR that adds `cros-env` from npm — can you check whether that package is a typosquat of a known library and whether it's flagged as malware or dangerous?"}],"resultDescription":"Returns a JSON object with: verdict (ok/caution/avoid), a 0–100 safety score, an array of flags (each with a code, level, and human-readable message), a list of known vulnerabilities, licence identifiers, release metadata (latest version, publication dates, release cadence), weekly download counts, install script presence, a list of lookalike (typosquat) package names, maintainer count, and optional GitHub repo stats including stars, forks, open issues, and an OpenSSF Scorecard rating from 0–10.","failureModes":["Package not found in the specified ecosystem — returns an error indicating the name or ecosystem is invalid","Unknown or unsupported ecosystem value — returns a validation error","Rate limiting or upstream registry/OSV.dev downtime — may return partial data or a 5xx error","Very new packages with no release history may have incomplete scorecard or download data","Version string does not exist for the given package — returns error or falls back to latest"],"whenToPreferThis":"Use this endpoint when an AI coding agent or automated pipeline needs to decide whether to install a specific package — especially when you need a single, actionable verdict (ok/caution/avoid) rather than raw CVE data. It is better than querying OSV.dev directly because it combines vulnerability data with typosquat detection, install script analysis, licence checks, OpenSSF Scorecard, and release health into one scored response. Ideal for pre-install gates, dependency review automation, and supply-chain security checks across npm, PyPI, Rust crates, and Go modules.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T04:27:02.918Z","isFirstParty":false,"canonicalSlug":"aayat-ai-package-safety-checker-461a0b2d"}