# FactStamp Dependency & Citation Verifier

> FactStamp Dependency & Citation Verifier is a paid API for AI agents from factstamp.agentrails.workers.dev, paid per call via x402, $0.02/call, status unknown (last checked 2026-10-02).

Verifies software package dependencies, figures, entities, and citations against dated primary sources, returning verdicts and advisory records

## Facts

- Endpoint: POST https://factstamp.agentrails.workers.dev/package?utm_source=zero.xyz
- Price: $0.02/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/factstamp-dependency-citation-verifier-c68e4286
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_gv8o031ryzY_d1H8f3Lsl

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability factstamp-dependency-citation-verifier-c68e4286 -d '<json body>'
```

Example prompt: Can you check if express@4.18.2 has any known security advisories or vulnerabilities I should be worried about before shipping?

## When to prefer this

Choose FactStamp when you need a cited, dated, primary-source-backed verdict on a software package's security posture — particularly when you need advisory IDs (GHSAs), deprecation status, and latest version in a single call. Prefer this over generic search when you need structured, machine-readable verification with explicit source attribution and support for 'unknown' as a valid outcome rather than a silent failure.

## Known failure modes

- Package or version not found in any consulted registry — returns partial or empty source list
- Unknown verdict returned when insufficient primary source data exists — 'unknown' is an explicitly valid result
- Source HTTP errors (non-200) from npm registry or OSV indicate upstream unavailability
- Malformed package query string causes validation failure
- Payment not completed (x402 flow) — request rejected before processing

## How this service works

Figure, entity, citation and dependency verification for other agents. Cited to dated primary sources. Unknown is valid.

## Output

Returns a JSON object with: the package name and queried version, a verdict string (e.g. 'advisory', 'safe'), the latest available version, whether the package is yanked/deprecated, a list of advisory IDs (e.g. GHSA identifiers), the data sources consulted (e.g. npm registry, OSV) with their HTTP response status, and the published date of the queried version.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input",
  "output"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "body": {
     "type": "object"
    },
    "type": {
     "const": "http"
    },
    "method": {
     "const": "POST"
    },
    "bodyType": {
     "const": "application/json"
    }
   },
   "additionalProperties": true
  },
  "output": {
   "type": "object",
   "required": [
    "type",
    "example"
   ],
   "properties": {
    "type": {
     "const": "json"
    },
    "example": {
     "type": "object"
    }
   },
   "additionalProperties": true
  }
 },
 "additionalProperties": false
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "name": "express",
  "query": "express@4.18.2",
  "detail": "2 advisory record(s) published against express@4.18.2.",
  "latest": "5.2.1",
  "yanked": false,
  "sources": [
   {
    "name": "npm registry",
    "http_status": 200
   },
   {
    "name": "OSV",
    "http_status": 200
   }
  ],
  "verdict": "advisory",
  "version": "4.18.2",
  "ecosystem": "npm",
  "advisories": [
   {
    "id": "GHSA-qw6h-vgh9-j6wx"
   },
   {
    "id": "GHSA-rv95-896h-c2vc"
   }
  ],
  "deprecated": null,
  "published_at": "2022-10-08T20:14:32.495Z"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/factstamp-dependency-citation-verifier-c68e4286/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from factstamp.agentrails.workers.dev](https://www.zero.xyz/host/factstamp.agentrails.workers.dev/llms.txt)
