{"uid":"cap_eHzi0NfAxJYOxDa6lvl7W","slug":"defi-shield-hazel-vercel-app-1f238cf0","name":"DeFi Shield Package Risk Assessment","description":"","url":"https://defi-shield-hazel.vercel.app/api/dev/package-risk","method":"POST","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","bodyType","body","method"],"properties":{"body":{"properties":{"ecosystem":{"type":"string","description":"Package ecosystem (default: npm)"},"package_name":{"type":"string","description":"Package name to assess"}}},"type":{"type":"string","const":"http"},"method":{"enum":["POST"],"type":"string"},"bodyType":{"enum":["json","form-data","text"],"type":"string"}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":{"request":{"input":{"body":{"ecosystem":"npm","package_name":"lodash"},"type":"http","method":"POST","bodyType":"json"}},"response":{"cves":[{"id":"GHSA-29mw-wpgm-hmr9","summary":"Regular Expression Denial of Service (ReDoS) in lodash","severity":"MODERATE"},{"id":"GHSA-35jh-r3h4-6jhm","summary":"Command Injection in lodash","severity":"HIGH"},{"id":"GHSA-4xc9-xhrj-v574","summary":"Prototype Pollution in lodash","severity":"HIGH"},{"id":"GHSA-f23m-r3pf-42rh","summary":"lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`","severity":"MODERATE"},{"id":"GHSA-fvqr-27wr-82fm","summary":"Prototype Pollution in lodash","severity":"MODERATE"},{"id":"GHSA-jf85-cpcp-j695","summary":"Prototype Pollution in lodash","severity":"CRITICAL"},{"id":"GHSA-p6mc-m468-83gw","summary":"Prototype Pollution in lodash","severity":"HIGH"},{"id":"GHSA-r5fr-rjxr-66jc","summary":"lodash vulnerable to Code Injection via `_.template` imports key names","severity":"HIGH"},{"id":"GHSA-x5rq-j2xg-h7qm","summary":"Regular Expression Denial of Service (ReDoS) in lodash","severity":"MODERATE"},{"id":"GHSA-xxjr-mmjv-4gpg","summary":"Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions","severity":"MODERATE"}],"license":"MIT","ecosystem":"npm","risk_score":55,"analyzed_at":"2026-06-16T01:18:30.518Z","package_name":"lodash","latest_version":"4.18.1","recommendation":"RISKY — significant concerns, consider alternatives","maintainer_count":1,"response_time_ms":321,"weekly_downloads":161341623}},"exampleRequest":{"ecosystem":"npm","package_name":"lodash"},"tags":["x402"],"displayCostAmount":"0.1","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"settled","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.1/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.1","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_NzP3OgjxsU6xNCJ6opO3s","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.1","costPer":"request","priority":0,"asset":null,"unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Assesses the security and reliability risk of software packages via CVE lookup, maintainer analysis, and download trend evaluation","exampleAgentPrompt":"Can you run a full risk assessment on the npm package 'lodash' version 4.17.21 — I need to know about any CVEs, whether the maintainers look trustworthy, and if the download trends suggest it's being abandoned?","exampleUseCases":null,"resultDescription":"Returns a structured risk assessment including CVE findings, maintainer credibility analysis, download trend data, and an overall risk score or flags for the queried package","failureModes":["Package not found in registry — returns 404 or error payload","Unknown or unsupported registry — endpoint may not support non-npm registries","Rate limiting or payment failure — x402 payment not processed correctly","Incomplete CVE data if vulnerability database is temporarily unavailable","Stale data if cache is not refreshed for a recently patched package"],"whenToPreferThis":"Use this endpoint when you need a comprehensive, multi-dimensional risk assessment of a software package combining vulnerability (CVE), maintainer trust, and usage trend signals in a single call — especially useful before adding a new dependency to a production project or auditing an existing one. Prefer this over generic CVE databases when you also care about supply chain signals like maintainer activity and download health.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T12:32:24.749Z","isFirstParty":false}