# Aayat AI Package Safety Checker

> Aayat AI Package Safety Checker is a paid API for AI agents from aayatai.com, paid per call via x402, $0.005/call, status unknown (last checked 2026-10-02).

Checks a single npm, PyPI, crates, or Go package version for vulnerabilities, malware, deprecation, typosquats, install scripts, licence, and OpenSSF Scorecard, returning a verdict (ok/caution/avoid) and 0–100 safety score.

## Facts

- Endpoint: GET https://aayatai.com/package/check?utm_source=zero.xyz
- Price: $0.005/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/aayat-ai-package-safety-checker-461a0b2d
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_VDUvbFyVjg8rsjn82DsJx

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability aayat-ai-package-safety-checker-461a0b2d
```

Example prompt: Is the npm package `lodash` version 4.17.21 safe to install? Check it for vulnerabilities, malware, deprecation, and any suspicious install scripts, and give me a verdict.

## When to prefer this

Use this endpoint when an AI coding agent or automated pipeline needs to decide whether to install a specific package — especially when you need a single, actionable verdict (ok/caution/avoid) rather than raw CVE data. It is better than querying OSV.dev directly because it combines vulnerability data with typosquat detection, install script analysis, licence checks, OpenSSF Scorecard, and release health into one scored response. Ideal for pre-install gates, dependency review automation, and supply-chain security checks across npm, PyPI, Rust crates, and Go modules.

## Known failure modes

- Package not found in the specified ecosystem — returns an error indicating the name or ecosystem is invalid
- Unknown or unsupported ecosystem value — returns a validation error
- Rate limiting or upstream registry/OSV.dev downtime — may return partial data or a 5xx error
- Very new packages with no release history may have incomplete scorecard or download data
- Version string does not exist for the given package — returns error or falls back to latest

## How this service works

Should a coding agent install this package? Checks one npm, PyPI, crates or Go package version for known vulnerabilities and malware (OSV.dev), deprecation, typosquat look-alike names, install scripts, licence, downloads, release activity and OpenSSF Scorecard, then gives a verdict (ok/caution/avoid), a 0-100 score and every reason. Pass ?ecosystem=npm&name=express.

## Output

Returns a JSON object with: verdict (ok/caution/avoid), a 0–100 safety score, an array of flags (each with a code, level, and human-readable message), a list of known vulnerabilities, licence identifiers, release metadata (latest version, publication dates, release cadence), weekly download counts, install script presence, a list of lookalike (typosquat) package names, maintainer count, and optional GitHub repo stats including stars, forks, open issues, and an OpenSSF Scorecard rating from 0–10.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET"
     ],
     "type": "string"
    },
    "queryParams": {
     "type": "object",
     "required": [
      "name"
     ],
     "properties": {
      "name": {
       "type": "string",
       "maxLength": 214,
       "minLength": 1,
       "description": "Package name, e.g. express, requests, serde or github.com/gin-gonic/gin."
      },
      "version": {
       "type": "string",
       "maxLength": 64,
       "description": "Exact version to check (default: the latest release)."
      },
      "ecosystem": {
       "enum": [
        "npm",
        "pypi",
        "crates",
        "go"
       ],
       "type": "string",
       "default": "npm",
       "description": "Package ecosystem: npm, pypi, crates (Rust) or go (Go modules)."
      }
     }
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object"
    }
   }
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "name": "express",
  "repo": {
   "forks": 16000,
   "stars": 66000,
   "scorecard": 8.1,
   "openIssues": 180
  },
  "flags": [
   {
    "code": "not-latest",
    "level": "info",
    "message": "A newer version exists: 5.1.0."
   }
  ],
  "score": 100,
  "sources": [
   "deps.dev",
   "OSV.dev",
   "npm registry"
  ],
  "verdict": "ok",
  "version": "4.21.2",
  "isLatest": false,
  "licences": [
   "MIT"
  ],
  "releases": {
   "latest": "5.1.0",
   "versions": 280,
   "firstPublishedAt": "2010-12-29T19:38:25Z",
   "latestPublishedAt": "2026-03-31T14:00:00Z",
   "releasesLast365Days": 6
  },
  "checkedAt": "2026-09-28T12:00:00.000Z",
  "ecosystem": "npm",
  "deprecated": null,
  "repository": "https://github.com/expressjs/express",
  "description": "Fast, unopinionated, minimalist web framework",
  "licenceKind": "permissive",
  "lookalikeOf": [],
  "maintainers": 5,
  "latestVersion": "5.1.0",
  "installScripts": [],
  "vulnerabilities": [],
  "weeklyDownloads": 41000000,
  "vulnerabilityCounts": {
   "low": 0,
   "high": 0,
   "unknown": 0,
   "critical": 0,
   "moderate": 0
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/aayat-ai-package-safety-checker-461a0b2d/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from aayatai.com](https://www.zero.xyz/host/aayatai.com/llms.txt)
