# Aayat AI Package Lockfile Security Audit

> Aayat AI Package Lockfile Security Audit is a paid API for AI agents from aayatai.com, paid per call via x402, $0.05/call, status unknown (last checked 2026-10-02).

Scans a dependency lockfile (npm, Yarn, pnpm, pip, Poetry, Cargo, Go, etc.) for known vulnerabilities and returns severity-graded findings with fix recommendations.

## Facts

- Endpoint: POST https://aayatai.com/package/audit/lockfile?utm_source=zero.xyz
- Price: $0.05/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/aayat-ai-package-lockfile-security-audit-9f3326a1
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_Vlxzj-vo2J4NPaL5bv6oM

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability aayat-ai-package-lockfile-security-audit-9f3326a1 -d '<json body>'
```

Example prompt: Can you audit my requirements.txt lockfile for vulnerabilities? Here's the content: requests==2.19.0\nnumpy==1.21.0 — use the requirements format and tell me what needs fixing.

## When to prefer this

Choose this endpoint when you need a fast, pay-per-use, no-account lockfile security audit across multiple ecosystems (npm, Yarn, pnpm, pip, Poetry, uv, Pipfile, Cargo, Go) without setting up a CI/CD integration. It's ideal for AI agents doing ad-hoc security checks, pre-deploy gates, or one-off audits. Prefer it over full SCA platforms like Snyk or Dependabot when you want lightweight, per-call billing via USDC and no persistent account management.

## Known failure modes

- Lockfile URL is unreachable or returns non-200 — endpoint will fail to fetch content
- Lockfile content exceeds 60 KB limit — must use URL parameter instead
- Format auto-detection fails if filename is ambiguous — use the format enum to force it
- Unknown or unsupported ecosystem returns no vulnerability data
- OSV database may not have coverage for very new or niche packages
- Malformed lockfile syntax causes parsing errors

## How this service works

Audit a whole lockfile for known vulnerabilities and malware in one call: package-lock.json, yarn.lock, pnpm-lock.yaml, requirements.txt, poetry.lock, uv.lock, Pipfile.lock, Cargo.lock or go.sum, up to 1,000 exact versions checked against OSV.dev, with affected packages, severity and versions to upgrade to. POST {url} (raw file) or {content, filename}.

## Output

A JSON object with a verdict ('fix', 'ok', etc.), total packages checked, counts of vulnerabilities by severity (critical/high/moderate/low/unknown), a list of vulnerable packages each with name, version, recommended upgrade version, and detailed vulnerability records (GHSA/CVE IDs, summary, severity, published date, fixed-in versions), plus ecosystem, format detected, and a timestamp.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "url": {
   "type": "string",
   "format": "uri",
   "maxLength": 2048,
   "description": "Raw lockfile address, e.g. https://raw.githubusercontent.com/owner/repo/main/package-lock.json."
  },
  "format": {
   "enum": [
    "package-lock",
    "yarn",
    "pnpm",
    "requirements",
    "poetry",
    "uv",
    "pipfile",
    "cargo",
    "gosum"
   ],
   "type": "string",
   "description": "Force the format if detection fails."
  },
  "content": {
   "type": "string",
   "maxLength": 60000,
   "description": "Or: the lockfile text itself (up to 60 KB; use url for bigger files)."
  },
  "filename": {
   "type": "string",
   "maxLength": 100,
   "description": "The file's name when sending content, e.g. poetry.lock (helps detect the format)."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "found": 2,
  "counts": {
   "low": 0,
   "high": 1,
   "unknown": 0,
   "critical": 0,
   "moderate": 2
  },
  "format": "requirements",
  "source": "content",
  "checked": 2,
  "verdict": "fix",
  "packages": [
   {
    "name": "requests",
    "version": "2.19.0",
    "upgradeTo": "2.32.4",
    "vulnerabilities": [
     {
      "id": "GHSA-x84v-xcm2-53pg",
      "url": "https://osv.dev/vulnerability/GHSA-x84v-xcm2-53pg",
      "aliases": [
       "CVE-2018-18074"
      ],
      "fixedIn": [
       "2.20.0"
      ],
      "summary": "Insufficiently Protected Credentials in Requests",
      "severity": "high",
      "published": "2018-10-29T19:06:39Z"
     }
    ]
   }
  ],
  "checkedAt": "2026-09-28T12:00:00.000Z",
  "ecosystem": "pypi",
  "truncated": false,
  "cleanCount": 1,
  "detailsTruncated": false,
  "vulnerablePackages": 1
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/aayat-ai-package-lockfile-security-audit-9f3326a1/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from aayatai.com](https://www.zero.xyz/host/aayatai.com/llms.txt)
