# Aayat AI Package Dependency Audit

> Aayat AI Package Dependency Audit is a paid API for AI agents from aayatai.com, paid per call via x402, $0.02/call, status unknown (last checked 2026-10-02).

Bulk-audits up to 200 npm, PyPI, crates, or Go package versions in a single call against OSV.dev for known vulnerabilities and malware, returning affected packages, severities, fix versions, and an overall verdict.

## Facts

- Endpoint: POST https://aayatai.com/package/audit?utm_source=zero.xyz
- Price: $0.02/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/aayat-ai-package-dependency-audit-e0b31cf8
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_65AWPrrWBf0D4V9jlMvu2

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability aayat-ai-package-dependency-audit-e0b31cf8 -d '<json body>'
```

Example prompt: Can you audit these npm packages for known vulnerabilities — express@4.17.1, lodash@4.17.15, and axios@0.21.0 — and tell me which ones need to be upgraded and how severe the issues are?

## When to prefer this

Use this endpoint when you need to audit a batch of up to 200 packages in a single API call across npm, PyPI, Rust crates, or Go modules. It is ideal for CI/CD pipelines, pre-deploy checks, or agent workflows that need a fast, structured security verdict with fix recommendations. Prefer it over single-package lookup endpoints when dealing with lockfiles or requirements files. It is backed by OSV.dev, which aggregates CVEs, GitHub Security Advisories, and ecosystem-specific advisories, making it more comprehensive than registry-only checkers.

## Known failure modes

- Invalid ecosystem value returns validation error
- Package version string not in expected name@version format causes parse failure
- More than 200 packages in a single call exceeds limit
- OSV.dev upstream unavailability causes service degradation
- Malformed requirements.txt input may cause parsing errors
- Unknown or unpublished package versions may return no vulnerability data
- Payment failure (x402) blocks the request

## How this service works

Audit a whole dependency list in one call: up to 200 exact npm, PyPI, crates or Go package versions checked against OSV.dev for known vulnerabilities and malware. Returns which packages are affected, severity, fixed versions and an overall verdict. POST {ecosystem, packages:["name@version"]} or {ecosystem:"pypi", requirements:"requests==2.31.0\n..."}.

## Output

Returns a JSON object with: a verdict string (e.g. 'fix' or 'clean'), a list of vulnerable packages each with vulnerability IDs, CVE aliases, severity levels, summary, published date, and the version that fixes the issue; a list of clean packages; counts broken down by severity (critical, high, moderate, low, unknown); total number of packages checked; the ecosystem; timestamp; and a flag indicating if details were truncated.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "packages": {
   "type": "array",
   "items": {
    "type": "string",
    "maxLength": 300
   },
   "maxItems": 200,
   "description": "Exact versions, e.g. [\"express@4.17.1\", \"lodash@4.17.15\"]."
  },
  "ecosystem": {
   "enum": [
    "npm",
    "pypi",
    "crates",
    "go"
   ],
   "type": "string",
   "default": "npm",
   "description": "Package ecosystem: npm, pypi, crates (Rust) or go (Go modules)."
  },
  "requirements": {
   "type": "string",
   "maxLength": 60000,
   "description": "Alternative: requirements.txt-style text, one name==version (or name@version) per line."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "clean": [
   "express@4.21.2"
  ],
  "counts": {
   "low": 0,
   "high": 3,
   "unknown": 0,
   "critical": 1,
   "moderate": 2
  },
  "source": "OSV.dev",
  "checked": 2,
  "verdict": "fix",
  "packages": [
   {
    "name": "lodash",
    "version": "4.17.15",
    "upgradeTo": "4.17.21",
    "vulnerabilities": [
     {
      "id": "GHSA-p6mc-m468-83gw",
      "url": "https://osv.dev/vulnerability/GHSA-p6mc-m468-83gw",
      "aliases": [
       "CVE-2020-8203"
      ],
      "fixedIn": [
       "4.17.19"
      ],
      "summary": "Prototype Pollution in lodash",
      "severity": "high",
      "published": "2020-07-15T19:15:48Z"
     }
    ]
   }
  ],
  "checkedAt": "2026-09-28T12:00:00.000Z",
  "ecosystem": "npm",
  "detailsTruncated": false,
  "vulnerablePackages": 1
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/aayat-ai-package-dependency-audit-e0b31cf8/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from aayatai.com](https://www.zero.xyz/host/aayatai.com/llms.txt)
