{"uid":"cap_aXed21l-xlJVnOvwrlsWM","slug":"dependency-trust-bf38917b","name":"Dependency Trust","description":"Should your agent install this package? Vulnerabilities, license, age, popularity, provenance, typosquat lookalikes and a trust score for npm, PyPI, crates.io, Go and Maven, in one call. Pay per call over x402, no API key.","url":"https://dep-trust.agent-utils.workers.dev/v1/packages","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"packages":{"type":"string"}}},"responseSchema":{"type":"json","example":{"count":2,"reports":[{"name":"lodash","found":true,"yanked":false,"license":"MIT","project":{"forks":7000,"stars":60000,"scorecard":6.2,"openIssues":120,"scorecardChecks":{"Maintained":10,"Code-Review":4}},"reasons":["1 high-severity vulnerability(ies) affect 4.17.15","2 medium-severity vulnerability(ies)","single maintainer for a very widely used package (bus factor)"],"sources":["deps.dev","osv.dev","registry.npmjs.org","api.npmjs.org"],"verdict":"review","version":"4.17.15","homepage":"https://lodash.com/","isLatest":false,"ecosystem":"npm","typosquat":{"isPopular":true,"lookalikes":[],"suspicious":false,"popularRank":34},"deprecated":false,"provenance":"none","repository":"https://github.com/lodash/lodash","trustScore":60,"vulnCounts":{"low":0,"high":1,"medium":2,"unknown":0,"critical":0},"generatedAt":"2026-09-06T19:00:00.000Z","maintainers":1,"publishedAt":"2019-07-17T19:10:23Z","latestVersion":"4.18.1","installScripts":[],"packageAgeDays":5249,"totalDownloads":null,"versionAgeDays":2608,"versionsBehind":6,"licenseCategory":"permissive","vulnerabilities":[{"id":"GHSA-29mw-wpgm-hmr9","url":"https://osv.dev/vulnerability/GHSA-29mw-wpgm-hmr9","aliases":["CVE-2020-28500"],"fixedIn":["4.17.21"],"summary":"Regular Expression Denial of Service (ReDoS) in lodash","severity":"medium","cvssScore":5,"published":"2021-02-19T00:00:00Z"}],"weeklyDownloads":173745865,"deprecatedReason":null,"firstPublishedAt":"2012-04-23T16:37:12Z"}],"summary":{"ok":["pypi:requests@2.34.2"],"avoid":[],"review":["npm:express@4.17.1"],"worstVerdict":"review"}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.03","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.03/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.03","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_5ARfio1smaI2mc4AXAIRZ","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.03","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Analyzes npm, PyPI, crates.io, Go, and Maven packages for vulnerabilities, license risk, age, popularity, provenance, typosquatting, and returns a trust score in one call.","exampleAgentPrompt":"Before I add lodash@4.17.15 from npm to the project, can you check its trust score, any known vulnerabilities, license, and whether there are any typosquatting lookalikes I should worry about?","exampleUseCases":[{"title":"Pre-install security audit for new dependency","prompt":"I'm about to add requests@2.28.0 from PyPI to our backend — can you check its vulnerability status, license, trust score, and whether it's still actively maintained before I pin it?"},{"title":"CI pipeline dependency vetting","prompt":"We're reviewing a pull request that adds three new packages: npm:axios@1.4.0, pypi:flask@2.3.2, and npm:moment@2.29.4. Can you audit all three for vulnerabilities, license issues, and typosquatting risks and tell me if any should be avoided?"},{"title":"Typosquat detection for unfamiliar package","prompt":"Someone on our team installed a package called 'crypt0' from PyPI — can you check if it looks like a typosquat of a popular package, what its trust score is, and whether it has any known security issues?"}],"resultDescription":"A JSON report per package containing: trust score (0-100), verdict (ok/review/avoid), vulnerability list with CVSS scores and fix versions, license name and category (permissive/copyleft/etc.), maintainer count, weekly and total downloads, package age, version age, versions behind latest, deprecation status and reason, provenance attestation, typosquat analysis with lookalikes list, GitHub project stats (stars, forks, open issues, OpenSSF Scorecard), and a summary object with worst-case verdict across all queried packages.","failureModes":["Package not found in registry — 'found: false' returned","Network timeout fetching from upstream registries (osv.dev, deps.dev, npmjs)","Unsupported ecosystem specified","Malformed package string input","Payment failure over x402 if USDC balance is insufficient"],"whenToPreferThis":"Choose this endpoint when an agent needs a single-call, cross-ecosystem package security assessment that combines vulnerability data, license compliance, popularity signals, provenance, and typosquat detection without managing multiple API keys. Ideal for CI/CD automation, agentic coding assistants vetting dependencies before installation, or security bots reviewing pull requests. Especially useful when payment is handled automatically via x402 per-call billing with no subscription overhead.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T12:42:45.599Z","isFirstParty":false}