{"uid":"cap_hybeVIvSmmtpytrsKqycX","slug":"grey-ridge-signals-tech-risk-vulnerability-enrichment-api-f99e099d","name":"Grey Ridge Signals — Tech Risk & Vulnerability Enrichment API","description":"Agent-native pay-per-call data on Base (USDC via x402). No API keys, no signup. Discovery: /.well-known/x402","url":"https://x402-data-api.sigrunner.workers.dev/enrich/tech-risk","method":"GET","headers":{},"bodySchema":{"type":"object","properties":{"properties":{"type":"string"}}},"responseSchema":{"type":"json","example":{"verdict":"review","tech_stack":["nginx","PHP"],"risk_summary":"nginx, PHP — 2 high-severity CVEs. Prioritize patching.","vulnerabilities":[{"id":"CVE-2024-24989","in_kev":false,"cvss_score":7.5,"epss_score":0.0234,"description":"Description text","exploit_available":false}]}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.05","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.05/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_fPN5nD5ViO-fdtqSmy7e3","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.05","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns a vulnerability risk summary for a website's detected tech stack, including CVEs, CVSS/EPSS scores, and a pass/review/fail verdict, paid per-call via x402 on Base.","exampleAgentPrompt":"Can you check the tech risk for this site — I need to know if its stack has any high-severity CVEs, their CVSS and EPSS scores, and whether I should flag it for review?","exampleUseCases":[{"title":"Vendor security due diligence check","prompt":"Before we onboard this SaaS vendor, can you pull a tech risk report on their website and tell me if there are any critical CVEs in their stack I should worry about?"},{"title":"Acquisition target cyber risk screening","prompt":"We're evaluating acquiring this company — can you check their public-facing site for known vulnerabilities, give me the CVE details and CVSS scores, and let me know if they get a pass or review verdict?"},{"title":"Continuous third-party risk monitoring","prompt":"Run a tech risk scan on our top supplier's website and flag any new high-severity CVEs or exploits that weren't there last week."}],"resultDescription":"A JSON object with: a verdict (pass/review/fail), detected tech stack components (e.g. nginx, PHP), a plain-English risk summary, and an array of vulnerabilities each containing CVE ID, whether it's in the CISA KEV catalog, CVSS score, EPSS score, plain-text description, and exploit availability flag.","failureModes":["Missing or malformed 'properties' input returns an error or empty stack","Domain not resolvable or no tech stack detected returns empty vulnerabilities array","Payment failure via x402 returns HTTP 402 before any data is served","CVE database may not include very recent CVEs disclosed within the last few days","EPSS scores may lag NVD publish date by 1-2 days"],"whenToPreferThis":"Choose this endpoint when you need per-call, keyless vulnerability enrichment for a specific website's tech stack without committing to a subscription. Ideal for one-off due diligence, ad-hoc security checks, or agentic workflows that need to assess third-party risk programmatically. Prefer over full DAST scanners when you only need passive CVE/CVSS/EPSS intelligence rather than active probing.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-16T06:42:46.000Z","isFirstParty":false}