{"uid":"cap_mDjsEcxn2b_kHAUEDycI4","slug":"cra-agent-package-vulnerability-lookup-ef84d07c","name":"CRA AGENT Package Vulnerability Lookup","description":"Known advisories for a package, or for one exact version, with severity and the versions that fix them. npm, PyPI, Go, crates.io, Maven, RubyGems, NuGet, Packagist.","url":"https://api.cra-agent.tech/v1/paid/packages/vulns?utm_source=zero.xyz","method":"GET","headers":{},"bodySchema":{"type":"object","properties":{"required":{"type":"string"},"properties":{"type":"string"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.004","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.004/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.004","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.004","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_S8BDN5YnvjZvLgelv3wxN","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.004","costPer":"request","priority":0,"asset":"0x3600000000000000000000000000000000000000","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns known security advisories, severity ratings, and fix versions for a package (or specific version) across npm, PyPI, Go, crates.io, Maven, RubyGems, NuGet, and Packagist.","exampleAgentPrompt":"Check if lodash version 4.17.20 on npm has any known security vulnerabilities and tell me which versions fix them.","exampleUseCases":[{"title":"Auditing a Python dependency before release","prompt":"Before we ship, can you check if the requests package version 2.28.1 on PyPI has any known vulnerabilities and what severity they are?"},{"title":"Checking a Go module for CVEs","prompt":"We're using github.com/gin-gonic/gin in our Go project — do you know if there are any security advisories against it and what versions patch them?"},{"title":"Maven library security review","prompt":"Our Java app depends on log4j from Maven — can you pull up all known advisories for it, including severity and which versions fix the issues?"}],"resultDescription":"A list of security advisories for the queried package (and optionally a specific version), each including advisory ID, severity level, affected version ranges, and the versions that resolve the vulnerability.","failureModes":["Package not found in the specified ecosystem returns empty advisory list","Unknown ecosystem value results in a 400 bad request error","Exact version string mismatch (e.g. wrong format) may return no results","Network timeout on upstream advisory database queries","Rate limiting or payment failure returns 402 Payment Required"],"whenToPreferThis":"Use this endpoint when you need fast, pay-per-call vulnerability lookups across multiple package ecosystems without maintaining your own advisory database. Prefer this over OSV or Snyk integrations when you need a simple REST lookup with x402 micropayment support and multi-ecosystem coverage in a single API.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T03:46:51.392Z","isFirstParty":false,"canonicalSlug":"cra-agent-package-vulnerability-lookup-ef84d07c"}