{"uid":"cap_c4O9-zY0wmpMr2sK16-Q2","slug":"northline-npm-package-risk-analyzer-f32a95a5","name":"Northline NPM Package Risk Analyzer","description":"Pay-per-call APIs, paid downloads and work-on-request for agents. Payment: x402 (USDC on Base, eip155:8453), no accounts or API keys. Catalog: https://206-81-14-131.sslip.io/?format=json. Agent guide: https://206-81-14-131.sslip.io/llms.txt","url":"https://206-81-14-131.sslip.io/svc/npm-package-risk/risk?utm_source=zero.xyz","method":"GET","headers":{},"bodySchema":null,"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.015","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.015/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.015","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.015","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_lfWSUllh-lz13TSrwsKiV","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.015","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Assesses the security and supply-chain risk level of an npm package by name","exampleAgentPrompt":"Can you check the supply-chain risk score for the npm package 'lodash' before I add it as a dependency?","exampleUseCases":[{"title":"Vetting a new npm dependency","prompt":"Before I install 'colors' as a dependency in my Node.js project, can you assess its security and supply-chain risk so I know if it's safe to use?"},{"title":"CI pipeline dependency audit","prompt":"We're adding automated checks to our CI pipeline — can you pull the risk score for the npm package 'event-stream' to flag it if it looks suspicious or compromised?"},{"title":"Detecting typosquatted packages","prompt":"A junior dev on my team accidentally ran 'npm install lodahs' — can you check the risk level of that package to see if it's a typosquat or malicious package?"}],"resultDescription":"Returns a structured risk assessment for the specified npm package, including an overall risk score or level (e.g. low/medium/high/critical), supply-chain risk signals such as maintainer reputation, publish anomalies, dependency tree issues, and indicators of potential compromise or malicious behavior.","failureModes":["Package name not found on npm registry — returns 404 or error response","Invalid or malformed package name — returns validation error","Payment not received or insufficient — returns HTTP 402","Rate limit or service unavailability — returns 5xx error","Package exists but has no analyzable metadata — may return partial or low-confidence results"],"whenToPreferThis":"Use this endpoint when you need a quick, pay-per-call supply-chain and security risk assessment for a specific npm package without setting up an account or API key. Prefer this over heavy-weight security platforms (Snyk, Socket.dev) when you need lightweight, on-demand risk scoring for a single package, especially in agent pipelines or CI workflows that only occasionally need npm risk data and want to avoid subscription overhead.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T03:57:40.015Z","isFirstParty":false,"canonicalSlug":"northline-npm-package-risk-analyzer-f32a95a5"}