{"uid":"cap_qVGkDyU-FCNtQq-O2Nk4V","slug":"manifest-audit-faf0ea93","name":"manifest-audit","description":"Check npm packages before you install or upgrade. Send {\"packages\":[\"lodash@4.17.20\",\"express\"]} or a package.json (dependencies and devDependencies), up to 50 packages. Per package: latest version and publish date, whether a pinned version is behind, license, deprecation notice, weekly downloads, and known vulnerabilities from OSV with severity and first fixed version. Deterministic registry data, no LLM.","url":"https://audit.152-53-82-29.sslip.io/v1/npm?utm_source=zero.xyz","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"packages":{"type":"array","items":{"type":"string"},"description":"npm packages as name or name@version"},"dependencies":{"type":"object"},"devDependencies":{"type":"object"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.005","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.005/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.005","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_vD4DqJ5SdbJfCS-w65HCu","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.005","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Audits npm packages for latest version, license, deprecation, weekly downloads, and known vulnerabilities before installation or upgrade","exampleAgentPrompt":"Before I install these packages, can you audit lodash@4.17.20, express, and react@18.0.0 for known vulnerabilities, check if they're behind the latest version, and tell me their licenses?","exampleUseCases":[{"title":"Pre-deploy dependency security check","prompt":"Run a security audit on my package.json dependencies — lodash@4.17.20, express@4.18.1, and axios@1.3.0 — and tell me if any have known vulnerabilities, if they're outdated, and what licenses they use."},{"title":"Upgrading packages safely","prompt":"I'm about to upgrade my project's dependencies. Can you check if moment@2.29.1, webpack@5.75.0, and babel-core@6.26.3 are deprecated, what the latest versions are, and if there are any CVEs I should know about?"},{"title":"Open source license compliance review","prompt":"My team needs a license compliance report before we ship. Can you check the licenses for react@18.2.0, redux@4.2.0, lodash@4.17.21, and typescript@5.0.0 along with any vulnerability or deprecation warnings?"}],"resultDescription":"For each package: latest version and publish date, whether a pinned version is behind latest, SPDX license identifier, any deprecation notice, weekly download count, and a list of known OSV vulnerabilities with severity ratings and the first fixed version available.","failureModes":["More than 50 packages submitted — request will be rejected","Invalid package name format — returns error for unrecognized package identifier","Package not found in npm registry — returns not-found status for that entry","No packages or dependencies fields provided — returns validation error","Network timeout reaching npm registry or OSV database"],"whenToPreferThis":"Use this endpoint when you need deterministic, registry-sourced npm package metadata — vulnerability data, license info, version lag, and deprecation status — without LLM hallucination risk. It accepts either a flat list of package strings or a raw package.json structure, making it ideal for CI/CD automation, pre-install checks, and supply chain audits for up to 50 npm packages at once.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-02T04:35:33.534Z","isFirstParty":false,"canonicalSlug":"manifest-audit-31b155e5"}