{"uid":"cap_w6HH1J0j9WTwLu6YLjlVP","slug":"pennyrail-osv-package-lookup-26bad178","name":"PennyRail OSV Package Lookup","description":"Machine-readable settlement service","url":"https://pennyrail.vercel.app/api/p/micro/security.osv-package--osv-package-lookup","method":"POST","headers":{},"bodySchema":{"type":"object","required":["input"],"properties":{"input":{"type":"object"}}},"responseSchema":{"type":"object","additionalProperties":true},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.004","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.004/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.004","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.004","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_IHGngrRk6sdsqpafqu0Wu","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.004","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Looks up known security vulnerabilities for a software package using the OSV (Open Source Vulnerabilities) database","exampleAgentPrompt":"Can you check if there are any known security vulnerabilities for the npm package 'axios' version 1.4.0?","exampleUseCases":[{"title":"Dependency vulnerability audit before release","prompt":"Before we ship, can you check the OSV database for any known vulnerabilities in the 'log4j' package version 2.14.1 in the Maven ecosystem?"},{"title":"CI pipeline security gate check","prompt":"I need to know if 'requests' version 2.27.0 in the PyPI ecosystem has any open CVEs or security advisories I should be aware of."},{"title":"Open source library vetting","prompt":"We're thinking of adding 'minimist' version 1.2.5 from npm to our project — can you look it up in the vulnerability database first to see if it's safe?"}],"resultDescription":"Returns structured vulnerability data from the OSV database for the queried package, including vulnerability IDs (CVE/GHSA), severity ratings, affected version ranges, descriptions, and references to advisories or patches.","failureModes":["Package not found in OSV database returns empty results or 404","Invalid or unrecognized ecosystem name may cause lookup failure","Unversioned queries may return broad or incomplete results","Upstream OSV API downtime causes service unavailability","Malformed input object causes 400-level error"],"whenToPreferThis":"Use this endpoint when you need a pay-per-call, agent-friendly OSV package vulnerability lookup without managing your own OSV API credentials or infrastructure. Prefer this over self-hosted OSV queries when building lightweight AI agents or pipelines that need on-demand security checks at low cost ($0.004/call) with x402 micropayment settlement.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T13:02:16.820Z","isFirstParty":false}