{"uid":"cap_hv74L37V4cGVa-XUh-oTy","slug":"package-risk-vulnerability-scanner-ce70d57e","name":"Package Risk Vulnerability Scanner","description":"Deterministic package, repository, security, and citation evidence APIs payable per call with x402.","url":"https://dependency-truth.inboxtzdjqv.workers.dev/v1/package-risk?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"package":{"type":"string"},"version":{"type":"string"},"ecosystem":{"enum":["npm","pypi"],"type":"string"}}},"responseSchema":{"type":"json","example":{"source":"https://api.osv.dev","package":"express","version":"5.0.0","ecosystem":"npm","vulnerabilities":[],"vulnerabilityCount":0}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.006","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.006/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.006","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.006","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_2vFNuOBsbe2q7Rwd9EgSV","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.006","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks a specific npm or PyPI package version for known security vulnerabilities using OSV.dev data, payable per call via x402.","exampleAgentPrompt":"Can you check whether express version 5.0.0 on npm has any known security vulnerabilities?","exampleUseCases":[{"title":"Pre-release dependency security audit","prompt":"Before I publish my new release, check if lodash version 4.17.21 on npm has any known CVEs or vulnerabilities I should be aware of."},{"title":"Python library safety check","prompt":"Is the PyPI package requests version 2.31.0 safe to use? I want to know if there are any reported security vulnerabilities before I add it to my project."},{"title":"Automated CI pipeline risk gate","prompt":"Check numpy version 1.24.0 on PyPI for any known security issues — I need this to decide whether to block our deployment."}],"resultDescription":"Returns a JSON object containing the package name, version, ecosystem, the source URL (OSV.dev), a list of known vulnerabilities (if any), and a total vulnerability count. An empty vulnerabilities array with count 0 indicates no known issues.","failureModes":["Unknown or misspelled package name returns empty or error response","Unsupported ecosystem (anything other than npm or pypi) rejected by enum validation","Missing required fields (package, version, or ecosystem) cause validation error","Payment failure via x402 protocol blocks the request","Very new package versions may not yet be indexed in OSV.dev"],"whenToPreferThis":"Choose this endpoint when you need a deterministic, per-call, pay-as-you-go vulnerability check against OSV.dev for a specific npm or PyPI package version — ideal for CI/CD pipelines, agent-driven dependency audits, or one-off security checks without a subscription. Prefer this over full SCA platforms when you only need lightweight, single-package lookups payable in USDC.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T04:27:02.835Z","isFirstParty":false,"canonicalSlug":"package-risk-vulnerability-scanner-ce70d57e"}