# Forest Gas Station – Package Security Vulnerability Lookup

> Forest Gas Station – Package Security Vulnerability Lookup is a paid API for AI agents from http--forest-gas-station-mainnet--lcjl27p8lmjs.code.run, paid per call via x402, $0.003/call, status unknown (last checked 2026-10-02).

Returns known vulnerabilities for a specified package and version in npm or PyPI ecosystems, providing normalized evidence without issuing a safety verdict.

## Facts

- Endpoint: POST https://http--forest-gas-station-mainnet--lcjl27p8lmjs.code.run/package/security?utm_source=zero.xyz
- Price: $0.003/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/forest-gas-station-package-security-vulnerability-lookup-eb4a5419
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap__ZD6ldDLNE9sFr1Mp35Hc

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability forest-gas-station-package-security-vulnerability-lookup-eb4a5419 -d '<json body>'
```

Example prompt: Can you look up known vulnerabilities for the npm package lodash at version 4.17.20 and give me the normalized evidence?

## When to prefer this

Use this endpoint when you need raw, normalized vulnerability evidence for a specific package+version combination in npm or PyPI, and you want factual CVE/advisory data rather than a pass/fail security verdict. Prefer this over general-purpose security scanners when you need programmatic, per-package evidence to feed into your own risk assessment logic or CI/CD pipeline.

## Known failure modes

- Package or version not found in the ecosystem — returns empty or error response
- Invalid ecosystem value (not 'npm' or 'pypi') — schema validation error
- Package name or version exceeds length limits — rejected by schema
- No vulnerability data available for an obscure or very new package — returns empty result
- Network or upstream data source unavailable — service error

## How this service works

Known vulnerabilities for package+version; normalized evidence, not a safety verdict. Base mainnet USDC

## Output

A normalized list of known vulnerabilities (e.g. CVEs, security advisories) associated with the specified package and version, structured as evidence records without a binary safe/unsafe verdict. Includes metadata such as vulnerability IDs, descriptions, and severity signals where available.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "package": {
   "type": "string",
   "maxLength": 214,
   "minLength": 1,
   "description": "Public package name to inspect."
  },
  "version": {
   "type": "string",
   "maxLength": 128,
   "minLength": 1,
   "description": "Package version whose public metadata should be checked."
  },
  "ecosystem": {
   "enum": [
    "npm",
    "pypi"
   ],
   "description": "Public ecosystem value used to scope this lookup."
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/forest-gas-station-package-security-vulnerability-lookup-eb4a5419/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from http--forest-gas-station-mainnet--lcjl27p8lmjs.code.run](https://www.zero.xyz/host/http--forest-gas-station-mainnet--lcjl27p8lmjs.code.run/llms.txt)
