{"uid":"cap_y4NPZh2doBTeH_Ozt-cpZ","slug":"pennyrail-osv-package-vulnerability-lookup-1623942d","name":"PennyRail OSV Package Vulnerability Lookup","description":"Machine-readable settlement service","url":"https://pennyrail.vercel.app/api/p/micro/security.osv-package--package-vulnerabilities","method":"POST","headers":{},"bodySchema":{"type":"object","required":["input"],"properties":{"input":{"type":"object"}}},"responseSchema":{"type":"object","additionalProperties":true},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.004","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.004/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.004","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.004","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_y69VUYABX8vX5o-G93-kX","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.004","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Queries the OSV (Open Source Vulnerabilities) database to return known security vulnerabilities for a given software package","exampleAgentPrompt":"Can you check the OSV vulnerability database for any known security issues in the npm package 'lodash' version 4.17.20?","exampleUseCases":[{"title":"Dependency audit before release","prompt":"Before we ship this release, check if the PyPI package 'requests' version 2.27.1 has any known vulnerabilities in the OSV database."},{"title":"CI pipeline security gate","prompt":"I need to know if the Maven package 'org.apache.log4j:log4j' version 2.14.1 has any known CVEs — we want to block the build if it does."},{"title":"Third-party library vetting","prompt":"We're considering adding 'axios' version 0.21.1 from npm to our project — can you pull up any OSV security advisories for it first?"}],"resultDescription":"Returns a list of known vulnerability records from the OSV database for the specified package, including vulnerability IDs (e.g. CVE, GHSA), affected version ranges, severity information, descriptions, and references to advisories or patches.","failureModes":["Unknown or misspelled package name returns empty results rather than an error","Unsupported ecosystem may yield no results","Very new packages may not yet have OSV entries even if vulnerabilities are known","Broad or unversioned queries may return very large result sets","Network or upstream OSV API timeout results in a 5xx error"],"whenToPreferThis":"Use this endpoint when you need a quick, pay-per-call lookup of OSV vulnerability data for a specific package without managing your own OSV API credentials or infrastructure. Ideal for agent pipelines doing on-demand dependency checks, especially when cost predictability at $0.004/call matters and you want to avoid rate-limit concerns of direct OSV API access.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T13:03:29.063Z","isFirstParty":false}