{"uid":"cap_eIBTtGa8W2XE_naHJyUme","slug":"pennyrail-osv-package-vulnerability-check-d9d3af38","name":"PennyRail OSV Package Vulnerability Check","description":"Machine-readable settlement service","url":"https://pennyrail.vercel.app/api/p/micro/security.osv-package--is-package-version-vulnerable","method":"POST","headers":{},"bodySchema":{"type":"object","required":["input"],"properties":{"input":{"type":"object"}}},"responseSchema":{"type":"object","additionalProperties":true},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.004","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.004/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.004","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.004","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_s-SybSvhY4i4-BIZJ32OO","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.004","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks whether a specific package version is vulnerable according to the OSV (Open Source Vulnerabilities) database","exampleAgentPrompt":"Can you check the OSV database to see if lodash version 4.17.15 is vulnerable to any known security issues?","exampleUseCases":[{"title":"CI pipeline dependency safety gate","prompt":"Before we merge this PR, check whether numpy version 1.21.0 has any known vulnerabilities in the OSV database — we need to know if it's safe to ship."},{"title":"Audit legacy application dependencies","prompt":"We're running requests 2.18.4 in our Python app — can you look it up in the OSV vulnerability database and tell me if that version is known to be vulnerable?"},{"title":"Developer security onboarding check","prompt":"I'm about to add minimist 1.2.5 as a dependency in my Node project — is that version listed as vulnerable in OSV?"}],"resultDescription":"Returns a boolean or structured indicator of whether the specified package version is vulnerable, along with associated vulnerability IDs (e.g. CVE, GHSA), severity ratings, affected version ranges, and any available fix recommendations from the OSV database.","failureModes":["Unknown package name or ecosystem returns empty or not-found response","Invalid version string format may cause lookup failure","OSV database may not cover all ecosystems — niche or private packages may return no results","Network timeout or upstream OSV API unavailability","Malformed input object missing required package fields"],"whenToPreferThis":"Use this endpoint when you need a fast, per-package vulnerability check against the OSV database without running a full dependency scanner. Ideal for validating a single dependency version during CI, before adding a new package, or when auditing a specific known-risky library. Prefer this over full SBOM scanners when you have an exact package name and version to check and want a lightweight, pay-per-call approach.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T13:02:52.233Z","isFirstParty":false}