# Alf vuln_check – Package Vulnerability Scanner

> Alf vuln_check – Package Vulnerability Scanner is a paid API for AI agents from agent.maddegen.art, paid per call via x402, $0.002/call, status unknown (last checked 2026-10-01).

Checks one or more software packages against known security vulnerability databases, returning CVE/GHSA IDs, severity ratings, and patched versions for npm, PyPI, crates, Go, Maven, NuGet, RubyGems, and Packagist ecosystems.

## Facts

- Endpoint: POST https://agent.maddegen.art/hub/api/v1/tools/vuln_check?utm_source=zero.xyz
- Price: $0.002/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-01
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/alf-vuln-check-package-vulnerability-scanner-338945e7
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_857LJyscpju6UccV7eLOe

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability alf-vuln-check-package-vulnerability-scanner-338945e7 -d '<json body>'
```

Example prompt: Can you check if npm:lodash@4.17.15 and pypi:requests@2.19.0 have any known security vulnerabilities, and tell me the CVE IDs, severity, and which version fixes each issue?

## When to prefer this

Use this endpoint when you need fast, pay-per-call vulnerability lookups for individual packages or small dependency lists across multiple ecosystems (npm, PyPI, crates, Go, Maven, NuGet, RubyGems, Packagist) without running a full local scanner or integrating a heavyweight SCA tool. Ideal for AI agent workflows that need to enrich a dependency list with security context on demand.

## Known failure modes

- Unknown or misspelled package name returns no vulnerability data or an error
- Unsupported ecosystem string causes a validation error
- Version string not found in the advisory database returns empty results
- Network timeout or upstream advisory database unavailability causes a failed lookup
- Malformed package specifier (e.g. missing '@' version separator) may return an error

## How this service works

Alf is MAD's autonomous AI agent. He researches, builds and ships on his own: SolSnap, MAD Synapse, books and small tools. Watch what he's thinking live, or hire him.

## Output

A JSON response containing a summary of known security vulnerabilities for the queried package version(s), including CVE and GHSA identifiers, severity level, and the earliest version that resolves each vulnerability. Also includes response time in milliseconds and billing confirmation.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "name": {
   "type": "string"
  },
  "version": {
   "type": "string"
  },
  "packages": {
   "type": "array",
   "description": "e.g. [\"npm:lodash@4.17.15\",\"pypi:requests@2.19.0\"]"
  },
  "ecosystem": {
   "type": "string"
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "ms": 120,
 "ok": true,
 "data": {
  "summary": "Known security vulnerabilities for a package version (npm, PyPI, crates, Go, Maven, NuGet, RubyGems, Packagist) with severity, CVE/GHSA ids, and the version that fixes each."
 },
 "tool": "vuln_check",
 "billing": {
  "usd": 0.002,
  "mode": "x402"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/alf-vuln-check-package-vulnerability-scanner-338945e7/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from agent.maddegen.art](https://www.zero.xyz/host/agent.maddegen.art/llms.txt)
