{"uid":"cap_Vlxzj-vo2J4NPaL5bv6oM","slug":"aayat-ai-package-lockfile-security-audit-9f3326a1","name":"Aayat AI Package Lockfile Security Audit","description":"Audit a whole lockfile for known vulnerabilities and malware in one call: package-lock.json, yarn.lock, pnpm-lock.yaml, requirements.txt, poetry.lock, uv.lock, Pipfile.lock, Cargo.lock or go.sum, up to 1,000 exact versions checked against OSV.dev, with affected packages, severity and versions to upgrade to. POST {url} (raw file) or {content, filename}.","url":"https://aayatai.com/package/audit/lockfile?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"url":{"type":"string","format":"uri","maxLength":2048,"description":"Raw lockfile address, e.g. https://raw.githubusercontent.com/owner/repo/main/package-lock.json."},"format":{"enum":["package-lock","yarn","pnpm","requirements","poetry","uv","pipfile","cargo","gosum"],"type":"string","description":"Force the format if detection fails."},"content":{"type":"string","maxLength":60000,"description":"Or: the lockfile text itself (up to 60 KB; use url for bigger files)."},"filename":{"type":"string","maxLength":100,"description":"The file's name when sending content, e.g. poetry.lock (helps detect the format)."}}},"responseSchema":{"type":"json","example":{"found":2,"counts":{"low":0,"high":1,"unknown":0,"critical":0,"moderate":2},"format":"requirements","source":"content","checked":2,"verdict":"fix","packages":[{"name":"requests","version":"2.19.0","upgradeTo":"2.32.4","vulnerabilities":[{"id":"GHSA-x84v-xcm2-53pg","url":"https://osv.dev/vulnerability/GHSA-x84v-xcm2-53pg","aliases":["CVE-2018-18074"],"fixedIn":["2.20.0"],"summary":"Insufficiently Protected Credentials in Requests","severity":"high","published":"2018-10-29T19:06:39Z"}]}],"checkedAt":"2026-09-28T12:00:00.000Z","ecosystem":"pypi","truncated":false,"cleanCount":1,"detailsTruncated":false,"vulnerablePackages":1}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.05","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.05/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_FxIztwUS91xIGmO71YP8M","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.05","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Scans a dependency lockfile (npm, Yarn, pnpm, pip, Poetry, Cargo, Go, etc.) for known vulnerabilities and returns severity-graded findings with fix recommendations.","exampleAgentPrompt":"Can you audit my requirements.txt lockfile for vulnerabilities? Here's the content: requests==2.19.0\\nnumpy==1.21.0 — use the requirements format and tell me what needs fixing.","exampleUseCases":[{"title":"Pre-deploy dependency security check","prompt":"Before I deploy this Node.js app, can you scan the package-lock.json at https://raw.githubusercontent.com/myorg/myapp/main/package-lock.json for any known vulnerabilities and tell me which ones are critical or high severity?"},{"title":"Python project CVE scan","prompt":"I have a poetry.lock file I want you to audit for security issues — here's the content: [paste]. Use the poetry format and give me a verdict on whether it's safe to ship."},{"title":"Rust crate vulnerability audit","prompt":"Check my Cargo.lock for known vulnerabilities — the file is at https://raw.githubusercontent.com/myorg/rustapp/main/Cargo.lock — I need to know if any crates have high or critical CVEs and what versions to upgrade to."}],"resultDescription":"A JSON object with a verdict ('fix', 'ok', etc.), total packages checked, counts of vulnerabilities by severity (critical/high/moderate/low/unknown), a list of vulnerable packages each with name, version, recommended upgrade version, and detailed vulnerability records (GHSA/CVE IDs, summary, severity, published date, fixed-in versions), plus ecosystem, format detected, and a timestamp.","failureModes":["Lockfile URL is unreachable or returns non-200 — endpoint will fail to fetch content","Lockfile content exceeds 60 KB limit — must use URL parameter instead","Format auto-detection fails if filename is ambiguous — use the format enum to force it","Unknown or unsupported ecosystem returns no vulnerability data","OSV database may not have coverage for very new or niche packages","Malformed lockfile syntax causes parsing errors"],"whenToPreferThis":"Choose this endpoint when you need a fast, pay-per-use, no-account lockfile security audit across multiple ecosystems (npm, Yarn, pnpm, pip, Poetry, uv, Pipfile, Cargo, Go) without setting up a CI/CD integration. It's ideal for AI agents doing ad-hoc security checks, pre-deploy gates, or one-off audits. Prefer it over full SCA platforms like Snyk or Dependabot when you want lightweight, per-call billing via USDC and no persistent account management.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T02:00:44.803Z","isFirstParty":false,"canonicalSlug":"aayat-ai-package-lockfile-security-audit-9f3326a1"}