# Aayat AI Dependency Verdict

> Aayat AI Dependency Verdict is a paid API for AI agents from aayatai.com, paid per call via x402, $0.03/call, status unknown (last checked 2026-10-02).

Performs a comprehensive safety and health check on an npm, PyPI, crates, or Go package and returns a clear use/use-with-care/avoid decision with plain-English advice.

## Facts

- Endpoint: GET https://aayatai.com/dependency/verdict?utm_source=zero.xyz
- Price: $0.03/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/aayat-ai-dependency-verdict-49c98e7e
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_I4YXUL0BmCJhfvCQxogZG

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability aayat-ai-dependency-verdict-49c98e7e
```

Example prompt: Can you check whether it's safe to use the 'express' npm package — I need to know if it has any vulnerabilities, if it's actively maintained, what licence it uses, and whether I should go ahead and add it?

## When to prefer this

Choose this endpoint when an AI agent needs a single-call, opinionated answer about whether to use a software dependency, combining vulnerability data, repo health, licence, and typosquat analysis into one structured verdict. Prefer it over raw OSV or deps.dev queries when you want pre-synthesized reasoning rather than raw data, and when you need coverage across npm, PyPI, crates, and Go in a unified interface.

## Known failure modes

- Package not found in the specified ecosystem — returns error indicating unknown package
- Invalid or unsupported ecosystem value — schema validation error
- Version string specified does not exist — falls back to latest or returns not-found
- GitHub repository data unavailable — repository field returned as null
- Rate limit or upstream registry timeout — transient 5xx error
- Payment not received or insufficient — 402 Payment Required

## How this service works

"Should I use this dependency?" in one call for npm, PyPI, crates or Go: full package safety check (vulnerabilities, malware, typosquats, deprecation, licence, downloads) plus its GitHub repository health (activity, bus factor, releases, Scorecard), a clear decision (use / use-with-care / avoid) with reasons, and plain-English advice. ?ecosystem=npm&name=express

## Output

A JSON object containing: the decision enum (use, use-with-care, or avoid), an array of human-readable reasons, a plain-English advice string, a full package report (vulnerabilities, licence, download counts, maintainer count, deprecation, install scripts, lookalike flags), and a GitHub repository health report (stars, forks, open issues, OpenSSF Scorecard score, commit activity, bus factor, latest release).

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET"
     ],
     "type": "string"
    },
    "queryParams": {
     "type": "object",
     "required": [
      "name"
     ],
     "properties": {
      "name": {
       "type": "string",
       "maxLength": 214,
       "minLength": 1,
       "description": "Package name, e.g. express, requests, serde or github.com/gin-gonic/gin."
      },
      "version": {
       "type": "string",
       "maxLength": 64,
       "description": "Exact version to check (default: the latest release)."
      },
      "ecosystem": {
       "enum": [
        "npm",
        "pypi",
        "crates",
        "go"
       ],
       "type": "string",
       "default": "npm",
       "description": "Package ecosystem: npm, pypi, crates (Rust) or go (Go modules)."
      }
     }
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object"
    }
   }
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "name": "express",
  "advice": "Express is safe to use: no known vulnerabilities in 5.1.0, active maintenance and an MIT licence.",
  "package": {
   "name": "express",
   "repo": {
    "forks": 16000,
    "stars": 66000,
    "scorecard": 8.1,
    "openIssues": 180
   },
   "flags": [
    {
     "code": "not-latest",
     "level": "info",
     "message": "A newer version exists: 5.1.0."
    }
   ],
   "score": 100,
   "sources": [
    "deps.dev",
    "OSV.dev",
    "npm registry"
   ],
   "verdict": "ok",
   "version": "4.21.2",
   "isLatest": false,
   "licences": [
    "MIT"
   ],
   "releases": {
    "latest": "5.1.0",
    "versions": 280,
    "firstPublishedAt": "2010-12-29T19:38:25Z",
    "latestPublishedAt": "2026-03-31T14:00:00Z",
    "releasesLast365Days": 6
   },
   "checkedAt": "2026-09-28T12:00:00.000Z",
   "ecosystem": "npm",
   "deprecated": null,
   "repository": "https://github.com/expressjs/express",
   "description": "Fast, unopinionated, minimalist web framework",
   "licenceKind": "permissive",
   "lookalikeOf": [],
   "maintainers": 5,
   "latestVersion": "5.1.0",
   "installScripts": [],
   "vulnerabilities": [],
   "weeklyDownloads": 41000000,
   "vulnerabilityCounts": {
    "low": 0,
    "high": 0,
    "unknown": 0,
    "critical": 0,
    "moderate": 0
   }
  },
  "reasons": [
   "No known vulnerabilities, maintained, permissive licence."
  ],
  "version": "5.1.0",
  "decision": "use",
  "checkedAt": "2026-09-28T12:00:00.000Z",
  "ecosystem": "npm",
  "repository": {
   "url": "https://github.com/honojs/hono",
   "repo": "honojs/hono",
   "flags": [],
   "forks": 1346,
   "score": 100,
   "stars": 32361,
   "isFork": false,
   "licence": "MIT",
   "partial": false,
   "sources": [
    "GitHub REST API",
    "deps.dev (OpenSSF Scorecard)"
   ],
   "verdict": "healthy",
   "archived": false,
   "checkedAt": "2026-09-28T12:00:00.000Z",
   "createdAt": "2021-12-14T20:05:30Z",
   "scorecard": {
    "date": "2026-09-22",
    "score": 7.4,
    "checks": [
     {
      "name": "Maintained",
      "score": 10
     }
    ]
   },
   "lastPushAt": "2026-09-27T03:11:53Z",
   "openIssues": 391,
   "description": "Web framework built on Web Standards",
   "defaultBranch": "main",
   "latestRelease": {
    "tag": "v4.13.9",
    "publishedAt": "2026-09-24T01:32:14Z"
   },
   "releasesLastYear": 30,
   "commitsLast90Days": 100,
   "communityHealthPercent": 87,
   "activeCommittersLast90Days": 24
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/aayat-ai-dependency-verdict-49c98e7e/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from aayatai.com](https://www.zero.xyz/host/aayatai.com/llms.txt)
