{"uid":"cap_s7MaUw6OH8p27mbpRhg3K","slug":"vulnerability-watch-f3538823","name":"Vulnerability Watch","description":"OSV vulnerability scan for a package with a pinned-or-upgrade verdict.","url":"https://k2so.wrong.systems/api/services/vulnerability-watch","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"type":"object","properties":{"meta":{"enum":["0","1"],"type":"string","description":"Set to 1 for free metadata JSON (no payment required)"},"package":{"type":"string","description":"Composite input parameter"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object","title":"Vulnerability Watch paid response","$schema":"https://json-schema.org/draft/2020-12/schema","required":["ok","paid","service","provider","result"],"properties":{"ok":{"type":"boolean"},"paid":{"type":"boolean"},"result":{"type":"object","required":["ok","service"],"properties":{"ok":{"type":"boolean","description":"Handler success"},"score":{"type":"number"},"service":{"type":"string","description":"Service slug"},"summary":{"type":"string"},"evidence":{"type":"object"},"strengths":{"type":"array","items":{"type":"string"}},"confidence":{"type":"string"},"generatedAt":{"type":"string","description":"ISO-8601 timestamp"},"riskFactors":{"type":"array","items":{"type":"string"}}}},"payment":{"type":"object","properties":{"code":{"type":"string"},"payer":{"type":"string"},"detail":{"type":"string"},"selfPay":{"type":"boolean"},"transaction":{"type":"string"}}},"service":{"type":"string"},"provider":{"type":"string","const":"K-2SO"}}}}}}},"responseSchema":{"type":"json","example":{"ok":true,"paid":true,"result":{"ok":true,"service":"vulnerability-watch"},"service":"vulnerability-watch","provider":"K-2SO"}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_jJ5fZ0QYRtke6T-hqj8q5","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Scans a software package for known OSV vulnerabilities and returns a pinned-or-upgrade verdict with a risk score and summary.","exampleAgentPrompt":"Can you check if the npm package lodash at version 4.17.20 has any known vulnerabilities and tell me whether I should pin it or upgrade it?","exampleUseCases":[{"title":"Pre-release dependency safety check","prompt":"Before I cut the release, scan requests version 2.28.2 from PyPI for known vulnerabilities and tell me if I should stick with that version or upgrade."},{"title":"Automated CI security gate","prompt":"Check whether express@4.18.1 on npm has any OSV-listed vulnerabilities and give me a risk score so I can decide whether to block this build."},{"title":"Legacy codebase audit","prompt":"We're using log4j 2.14.1 in our Maven project — can you pull a vulnerability report on it and give me a verdict on whether to stay pinned or force an upgrade?"}],"resultDescription":"Returns a JSON object with a boolean success flag, a numeric risk score, a plain-language summary, a pinned-or-upgrade verdict, an array of risk factors, an array of strengths, a confidence level string, structured evidence from OSV, and an ISO-8601 timestamp indicating when the assessment was generated.","failureModes":["Unrecognized package name or ecosystem returns an error or empty evidence","Network timeout reaching OSV upstream data","Missing or malformed package query parameter returns a validation error","Payment not completed results in HTTP 402 response blocking the result","Package exists but has no OSV records, yielding a low-confidence verdict"],"whenToPreferThis":"Choose this endpoint when you need a structured, machine-readable security verdict (pinned vs. upgrade) for a specific package version rather than a raw CVE list dump. It is ideal for CI/CD pipelines, agent-driven dependency audits, or any automated workflow that needs a scored recommendation rather than just raw vulnerability data. Prefer it over generic OSV API calls when you want a pre-computed confidence level and actionable verdict in a single call.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T16:25:37.356Z","isFirstParty":false}