{"uid":"cap_dScMOJLmhMWD7Mv5XVMuR","slug":"sitesignal-npm-latest-release-risk-pack-a2367889","name":"SiteSignal npm Latest Release Risk Pack","description":"Combine current npm registry metadata, last-week downloads, and exact-latest-version OSV records into a bounded release review-priority pack.","url":"https://trinity-throw-thursday-gravity.trycloudflare.com/x402/npm-release-risk-pack","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["package"],"properties":{"package":{"type":"string","description":"Public scoped or unscoped npm package name."}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_Lnz8_LCIvvqIHpdQO2I8T","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.1","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Combines npm registry metadata, last-week download counts, and OSV vulnerability records for the exact latest version of an npm package into a single release review-priority report.","exampleAgentPrompt":"Can you pull the npm release risk pack for 'lodash' — I need the latest registry metadata, last week's download numbers, and any known OSV vulnerabilities for its current version before we approve it as a dependency?","exampleUseCases":[{"title":"Pre-dependency security review","prompt":"Before we add 'axios' to our project, can you check the npm release risk pack for it — I want to see its latest version info, how many downloads it got last week, and whether there are any known vulnerabilities?"},{"title":"Supply chain audit for open source package","prompt":"We're auditing our open source dependencies — can you pull a release risk pack for 'express' from npm so I can see its current registry metadata, weekly download activity, and any OSV vulnerability flags on the latest version?"},{"title":"Evaluating unfamiliar package before adoption","prompt":"I've never used 'zod' before and want to know if it's safe to adopt — can you get me the npm risk pack for it showing the latest release details, download popularity, and any security advisories?"}],"resultDescription":"A bundled JSON report containing: current npm registry metadata (version, author, description, license, publish date), last-week download count from the npm registry, and OSV (Open Source Vulnerabilities) records matched to the exact latest version — all combined into a single release review-priority pack.","failureModes":["Package not found on npm registry — returns error or empty result","Package name typo or scoping error (e.g. missing @ for scoped packages) — returns 404-style failure","OSV database has no records for the package — vulnerability list may be empty but not an error","Cloudflare tunnel availability issues causing intermittent 502/503 errors","Rate limiting or upstream npm/OSV API unavailability causing partial data"],"whenToPreferThis":"Choose this endpoint when you need a consolidated snapshot of an npm package's current health — combining registry metadata, popularity signals, and security vulnerability data — in a single call rather than querying npm, download stats, and OSV separately. Ideal for dependency review workflows, supply chain audits, or automated CI/CD gate checks where you want bounded, pre-combined risk intelligence on the latest release specifically.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T08:28:19.176Z","isFirstParty":false}