{"uid":"cap__ZD6ldDLNE9sFr1Mp35Hc","slug":"forest-gas-station-package-security-vulnerability-lookup-eb4a5419","name":"Forest Gas Station – Package Security Vulnerability Lookup","description":"Known vulnerabilities for package+version; normalized evidence, not a safety verdict. Base mainnet USDC","url":"https://http--forest-gas-station-mainnet--lcjl27p8lmjs.code.run/package/security?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"package":{"type":"string","maxLength":214,"minLength":1,"description":"Public package name to inspect."},"version":{"type":"string","maxLength":128,"minLength":1,"description":"Package version whose public metadata should be checked."},"ecosystem":{"enum":["npm","pypi"],"description":"Public ecosystem value used to scope this lookup."}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.003","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.003/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_3r5EjeRtO-R_X15_WO2w6","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.003","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns known vulnerabilities for a specified package and version in npm or PyPI ecosystems, providing normalized evidence without issuing a safety verdict.","exampleAgentPrompt":"Can you look up known vulnerabilities for the npm package lodash at version 4.17.20 and give me the normalized evidence?","exampleUseCases":[{"title":"Pre-deployment dependency security check","prompt":"Before I deploy, can you check if there are any known vulnerabilities for the PyPI package requests at version 2.27.1?"},{"title":"Audit npm package in CI pipeline","prompt":"I need to audit express version 4.17.3 on npm — can you pull up any known security issues or CVEs for that specific version?"},{"title":"Triage a flagged transitive dependency","prompt":"One of our transitive dependencies got flagged — can you look up vulnerability evidence for the npm package minimist at version 1.2.5?"}],"resultDescription":"A normalized list of known vulnerabilities (e.g. CVEs, security advisories) associated with the specified package and version, structured as evidence records without a binary safe/unsafe verdict. Includes metadata such as vulnerability IDs, descriptions, and severity signals where available.","failureModes":["Package or version not found in the ecosystem — returns empty or error response","Invalid ecosystem value (not 'npm' or 'pypi') — schema validation error","Package name or version exceeds length limits — rejected by schema","No vulnerability data available for an obscure or very new package — returns empty result","Network or upstream data source unavailable — service error"],"whenToPreferThis":"Use this endpoint when you need raw, normalized vulnerability evidence for a specific package+version combination in npm or PyPI, and you want factual CVE/advisory data rather than a pass/fail security verdict. Prefer this over general-purpose security scanners when you need programmatic, per-package evidence to feed into your own risk assessment logic or CI/CD pipeline.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T04:49:17.516Z","isFirstParty":false,"canonicalSlug":"forest-gas-station-package-security-vulnerability-lookup-eb4a5419"}