{"uid":"cap_pCBbuhveP7TSf5RQFTsjk","slug":"manifest-audit-0d60a87c","name":"manifest-audit","description":"Known vulnerabilities for a list of dependencies, npm and PyPI, in one call. Send {\"npm\":[\"lodash@4.17.20\"],\"pypi\":[\"django==3.2.0\"]} or a package.json or requirements.txt, up to 50 packages. Returns only packages that have advisories: OSV and GHSA ids, CVE aliases, severity, summary, and the first fixed version, plus counts. Unpinned packages are checked at their latest version. Deterministic OSV data, no LLM.","url":"https://audit.152-53-82-29.sslip.io/v1/vulns?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"npm":{"type":"array","items":{"type":"string"}},"pypi":{"type":"array","items":{"type":"string"}},"manifest":{"type":"string"},"ecosystem":{"enum":["npm","pypi"],"type":"string"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.005","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.005/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_kQ4h-A0SLy9vfHsMrffbN","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.005","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Check a list of npm and/or PyPI packages (or a raw manifest file) for known vulnerabilities in a single call, returning OSV/GHSA advisories, CVEs, severity, and first fixed version.","exampleAgentPrompt":"Before I install these packages, check them for known security vulnerabilities: npm packages lodash@4.17.20 and express@4.18.0, and PyPI packages django==3.2.0 and requests==2.28.0 — give me OSV/GHSA IDs, severity, and the first fixed version for anything flagged.","exampleUseCases":[{"title":"Pre-deploy dependency security gate","prompt":"I'm about to deploy — can you audit my npm packages lodash@4.17.20, axios@0.21.0, and my PyPI packages Pillow==8.3.0 and Flask==1.1.2 for any known CVEs or GHSA advisories, and tell me the severity and first fixed version for each issue?"},{"title":"CI pipeline vulnerability check","prompt":"Run a security audit on this requirements.txt content before we merge: check all listed PyPI packages for OSV advisories and tell me which ones have critical or high severity vulnerabilities and what version I should upgrade to."},{"title":"Evaluating upgrade risk before bumping versions","prompt":"We're thinking of staying on express@4.17.1 and django==3.1.0 a bit longer — do either of those have known security advisories I should know about, and if so what's the minimum version that fixes them?"}],"resultDescription":"Returns only packages that have known advisories. For each vulnerable package: OSV and GHSA identifiers, CVE aliases, severity level, a human-readable summary of the vulnerability, and the earliest version that fixes the issue. Also includes aggregate counts of vulnerable packages and total advisories found. Packages with no advisories are omitted from the response.","failureModes":["More than 50 packages submitted — request exceeds limit","Invalid package name or version format — package skipped or error returned","Unknown package not found in OSV database — treated as no advisories","Missing both npm and pypi fields with no manifest — malformed request error","Network or OSV upstream timeout — 5xx error response"],"whenToPreferThis":"Use this endpoint when you need a single API call to audit a mixed npm+PyPI dependency list (or a raw manifest file) against deterministic, structured OSV/GHSA data — with no LLM hallucination risk. Prefer it over language-specific audit tools when you need cross-ecosystem coverage in one request, or when you need machine-readable advisory IDs, CVE aliases, and first-fixed-version fields for automated gating in CI/CD pipelines.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T02:29:37.435Z","isFirstParty":false,"canonicalSlug":"manifest-audit-31b155e5"}