{"uid":"cap_gK4VnmYd35FSgSB7xy4cU","slug":"manifest-audit-31b155e5","name":"manifest-audit","description":"Audit a whole dependency manifest in one call before installing or upgrading. Send a package.json, a requirements.txt, or npm and PyPI package lists (up to 50 packages). Per dependency: latest version and publish date, whether your pin is behind, license, deprecation or yanked status, weekly npm downloads, and known vulnerabilities from OSV with severity and first fixed version. Deterministic, no LLM. Use before adding or bumping deps or when reviewing a lockfile change.","url":"https://audit.152-53-82-29.sslip.io/v1/audit?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"npm":{"type":"array","items":{"type":"string"},"description":"npm packages as name or name@version"},"pypi":{"type":"array","items":{"type":"string"},"description":"PyPI requirement lines, for example requests==2.25.0"},"manifest":{"type":"string","description":"Raw package.json or requirements.txt text"},"ecosystem":{"enum":["npm","pypi"],"type":"string","description":"Required with `manifest` when it is a requirements.txt"},"dependencies":{"type":"object","description":"package.json dependencies map"},"devDependencies":{"type":"object","description":"package.json devDependencies map"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"healthy","priceObserved":{"p10Cents":"1.0000","medianCents":"1.0000","p90Cents":"1.0000","minCents":"1.0000","maxCents":"1.0000","p95Cents":"1.0000","sampleCount":1,"varies":false,"failureChargeRate":null},"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_DKOAZMVeXvFROMqhkhm1C","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Audits npm or PyPI dependency manifests for outdated versions, licenses, deprecations, download stats, and known vulnerabilities in one API call","exampleAgentPrompt":"Before I run npm install, can you audit these packages for vulnerabilities, outdated versions, and license issues: lodash@4.17.20, express@4.18.0, and axios?","exampleUseCases":[{"title":"Pre-install npm security check","prompt":"I'm about to add lodash@4.17.20, express@4.18.0, and chalk@4.0.0 to my project — can you check them for known vulnerabilities, whether they're behind the latest version, and what licenses they use?"},{"title":"Python requirements.txt review","prompt":"Here's my requirements.txt — can you audit it for any yanked packages, security vulnerabilities, and outdated pins before I deploy? requests==2.25.0\nflask==2.0.1\nsqlalchemy==1.4.0"},{"title":"Lockfile PR review for risky deps","prompt":"We have a pull request bumping several dependencies in our package.json. Can you check these packages for CVEs, deprecation notices, and whether the new versions are actually the latest: react@18.0.0, webpack@5.70.0, babel-core@6.26.3?"}],"resultDescription":"For each submitted package: the latest available version and its publish date, whether the submitted pin is behind latest, the package license, deprecation or yanked status, weekly npm download count (for npm packages), and a list of known OSV vulnerabilities with severity levels and the first version where each was fixed.","failureModes":["More than 50 packages submitted — batch size limit exceeded","Invalid package name or version string format causing lookup failure","Package not found on npm or PyPI registry","ecosystem field missing when manifest is a requirements.txt","Network or registry timeout causing incomplete results for some packages"],"whenToPreferThis":"Use this endpoint when you need a comprehensive, multi-signal dependency health check in a single call — combining version staleness, license data, deprecation/yanked status, popularity (npm downloads), and OSV vulnerability data together. Prefer it over single-purpose vulnerability scanners when you need the full picture before installing, upgrading, or approving a lockfile diff. Best suited for CI/CD pre-checks, code review automation, and agent-driven dependency management workflows where deterministic (non-LLM) results are required.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":1,"lastUsedAt":"2026-09-25T05:16:03.637Z","lastSuccessfullyRanAt":"2026-09-25T05:16:03.637Z","lastHealthCheckAt":"2026-10-02T00:56:12.051Z","isFirstParty":false,"canonicalSlug":"manifest-audit-31b155e5"}