{"uid":"cap_aIk43EM9cEQUyPkrYLSHX","slug":"dependency-cve-scan-c3987c3c","name":"Dependency / CVE Scan","description":"Scan package.json or lockfile text for dependency CVE risk signals — outdated lodash/axios, deprecated packages, wildcard pins, risky postinstall scripts, and embedded secrets.","url":"https://x402-hono-api.inraby.workers.dev/api/v1/dependency-cve-scan","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"manifestText":{"type":"string","description":"package.json, package-lock.json, or yarn.lock contents"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.05","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.05/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_f4FqMTsRVu1IgZDgjyLPP","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.05","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Scans package.json or lockfile text for dependency CVE risk signals including outdated packages, deprecated libraries, wildcard version pins, risky postinstall scripts, and embedded secrets.","exampleAgentPrompt":"Can you scan this package.json for CVE risks, outdated lodash or axios versions, deprecated packages, wildcard pins, and any suspicious postinstall scripts? Here's the manifest text: [paste contents]","exampleUseCases":[{"title":"Pre-merge dependency security gate","prompt":"Before we merge this PR, scan this package-lock.json for any CVE risk signals, outdated axios or lodash versions, or wildcard version pins — here's the full lockfile text."},{"title":"Open source project security audit","prompt":"I'm auditing a public npm package before adopting it. Can you scan this package.json for deprecated packages, risky postinstall scripts, and any embedded secrets?"},{"title":"CI pipeline vulnerability check","prompt":"As part of our CI pipeline, scan this yarn.lock text for known CVE risk signals and flag any dependencies that look outdated or dangerous."}],"resultDescription":"Returns a structured report of dependency risk signals found in the submitted manifest or lockfile, including: identified CVE-associated packages (e.g. outdated lodash/axios versions), deprecated package warnings, wildcard version pin flags, risky postinstall script detections, and any embedded secrets found within the manifest — without exposing secret values directly.","failureModes":["Invalid or malformed manifest text returns a parsing error","Non-npm manifest formats (e.g. requirements.txt, Gemfile) may not be supported","Empty manifestText field returns a validation error","Very large lockfiles may hit payload size limits","Network timeout if the worker is cold-starting","False positives on packages with version ranges that are technically safe"],"whenToPreferThis":"Choose this endpoint when you need a quick, automated CVE and security risk assessment of npm dependency manifests (package.json, package-lock.json, yarn.lock) without running a full local npm audit or integrating with a dedicated vulnerability database. It is especially useful in agent workflows, CI pipelines, or code review contexts where you want a fast, structured signal about outdated libraries, wildcard pins, risky scripts, and embedded secrets in a single call. Prefer alternatives like Snyk or GitHub Dependabot when you need comprehensive CVE database lookups with remediation guidance or support for non-npm ecosystems.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T18:35:43.607Z","isFirstParty":false}