{"uid":"cap_Vkeeh8GsReMSz7ZQ34ip0","slug":"ot-ics-vendor-supply-chain-risk-assessment-fc421673","name":"OT/ICS Vendor Supply-Chain Risk Assessment","description":"OT/ICS supply-chain vendor risk assessment. Pass ?vendor=(name) e.g. Schneider Electric, Siemens, Rockwell Automation, optionally &product=(line) e.g. Modicon. Returns risk tier, confidence, cited CVEs (KEV/EPSS), threat actors with historical targeting interest, and supply-chain mitigation recommendations. DeepSeek-synthesised, ICD-203 language. Certain restricted-license sources excluded.","url":"https://ot-intel-api.onrender.com/ot/vendor-risk","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":[],"properties":{"vendor":{"type":"string","description":"OT/ICS vendor name e.g. Schneider Electric, Siemens, Rockwell Automation. Required — at least this param must be present."},"product":{"type":"string","description":"Optional product line filter e.g. Modicon, SIMATIC."}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"tlp":"TLP:CLEAR","vendor":"Schneider Electric","product":null,"summary":"Multiple actively exploited CVEs and one actor with historical targeting interest.","risk_tier":"elevated","confidence":"moderate","targeting_actors":[{"name":"CHERNOVITE","rationale":"Historical targeting of Modicon PLC lines."}],"supply_chain_recommendations":["Verify patch status of Modicon M580/M340 controllers against CVE-2024-XXXXX."],"known_exploited_vulnerabilities":[{"kev":true,"cve_id":"CVE-2024-XXXXX","epss_score":0.87}]}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.15","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.15/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.15","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.15","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_MAmIvdoXUqPB8pP1ztkkU","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.15","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns a risk tier, confidence score, cited CVEs (KEV/EPSS), threat actor targeting history, and supply-chain mitigation recommendations for a named OT/ICS vendor and optional product line.","exampleAgentPrompt":"Can you pull a supply-chain vendor risk assessment for Schneider Electric, specifically the Modicon product line — I need the risk tier, any KEV or EPSS-cited CVEs, which threat actors have historically targeted them, and recommended mitigations?","exampleUseCases":null,"resultDescription":"A structured report containing: a risk tier classification for the vendor (and optionally the product line), a confidence score for the assessment, a list of cited CVEs tagged with KEV and EPSS scoring, known threat actor groups with documented historical interest in targeting that vendor or product line, and prescriptive supply-chain mitigation recommendations — all written in ICD-203 intelligence language.","failureModes":["Missing vendor parameter returns an error indicating at least one query param is required","Unknown or obscure vendor name may return low-confidence result or empty threat actor list","Payment failure (402) if x402 USDC payment is not successfully processed before the request","Vendor name misspelling may result in no match or incorrect vendor being assessed","Rate limiting or service unavailability from the Render-hosted backend"],"whenToPreferThis":"Use this endpoint when you need a synthesized, intelligence-grade OT/ICS supply-chain risk profile for a named vendor — especially when you need CVE citations (KEV/EPSS), threat actor attribution, and mitigation guidance in ICD-203 language in a single call. Prefer this over generic vulnerability databases when OT/ICS-specific context and supply-chain framing are required.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:48:47.748Z","isFirstParty":false}