{"uid":"cap_zCEcri1LX-7jcSkSss8vk","slug":"pkgpulse-deps-audit-59f16874","name":"pkgpulse deps-audit","description":"Dependency intelligence for AI coding agents, paid per-call via x402 (USDC on Base): npm package health scores with a disclosed rubric, typosquat checks, dependency audits. Free index at /, free sample at /api/sample.","url":"https://pkgpulse.letom1176.workers.dev/api/deps-audit","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"dependencies":{"type":"object","description":"package.json-style dependencies map (name → version range). Or send a full package.json, or an array of names."}}},"responseSchema":{"type":"json","example":{"summary":{"clean":8,"audited":12,"deprecated":1,"with_install_scripts":2,"missing_from_registry":1},"verdict":"STOP: dependencies reference names that do not exist on npm — classic hallucination/squat vector","worst_offenders":[{"name":"leftt-pad","flags":["NOT ON REGISTRY — hallucinated or removed; install will fail or fetch a squat"]}]}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.02","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.02/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.02","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_FVI35L6_68-necT_2rdUJ","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.02","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Audits a set of npm package dependencies for health issues, typosquatting, deprecation, install scripts, and hallucinated/non-existent packages","exampleAgentPrompt":"Can you audit these npm dependencies from my AI-generated package.json — I want to know if any packages are typosquatted, deprecated, hallucinated (not on the registry), or have suspicious install scripts: { \"express\": \"^4.18.0\", \"leftt-pad\": \"^1.0.0\", \"lodash\": \"^4.17.21\" }?","exampleUseCases":[{"title":"Vetting AI-generated code dependencies","prompt":"I just had an AI write me a Node.js project and it generated a package.json — can you run the dependencies through pkgpulse to check if any of those package names are hallucinated, squatted, or otherwise sketchy before I run npm install?"},{"title":"Pre-deploy supply chain security check","prompt":"Before we ship this microservice, can you audit all the npm packages in this dependencies map for typosquats, deprecated packages, and anything with suspicious install scripts: { \"axios\": \"^1.4.0\", \"reakt\": \"^18.0.0\", \"dotenv\": \"^16.0.0\", \"colors\": \"^1.4.0\" }?"},{"title":"Detecting removed or non-existent packages","prompt":"Our CI pipeline is failing on npm install — can you check these package names against the npm registry and tell me which ones don't actually exist or may have been removed: [\"left-pad\", \"event-stream\", \"colerss\", \"express\"]?"}],"resultDescription":"Returns a JSON object with a summary count of clean, audited, deprecated, packages with install scripts, and missing-from-registry packages; a human-readable verdict string (e.g. STOP or PASS); and a worst_offenders array listing flagged packages with specific flag descriptions such as typosquat alerts, deprecation notices, registry absence, or install script warnings.","failureModes":["Invalid or empty dependencies input returns an error","Package names that are valid but newly published may not be indexed yet","Rate limiting or payment failure (x402 USDC payment not processed) blocks the request","Malformed package.json structure may cause parsing errors","Network timeouts reaching the npm registry for live checks"],"whenToPreferThis":"Use this endpoint when you need to validate npm dependencies before installation — especially for AI-generated code where hallucinated package names are a real risk, or when doing pre-deploy security checks for typosquatting and supply chain attacks. It is particularly valuable over a generic npm audit because it specifically flags non-existent registry entries (hallucination/squat vector), not just known vulnerabilities. Prefer this over manual checks when auditing many packages at once in an automated pipeline.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T06:30:40.809Z","isFirstParty":false}