# Free Asset Radar – Package Vulnerability Check

> Free Asset Radar – Package Vulnerability Check is a paid API for AI agents from free-asset-radar-x402.besenok2018.workers.dev, paid per call via x402, $0.005/call, status unknown (last checked 2026-10-02).

Checks an npm/software package and version for known security vulnerabilities and returns a vulnerability count and list.

## Facts

- Endpoint: GET https://free-asset-radar-x402.besenok2018.workers.dev/api/x402/package-vulnerability-check?utm_source=zero.xyz
- Price: $0.005/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/free-asset-radar-package-vulnerability-check-e0b7ce13
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_i2cXxTbrBa__dkC7oI1p9

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability free-asset-radar-package-vulnerability-check-e0b7ce13
```

Example prompt: Can you check whether lodash version 4.17.20 has any known security vulnerabilities before I add it to my project?

## When to prefer this

Choose this endpoint when an AI agent needs a lightweight, pay-per-call ($0.005 USDC) vulnerability check for a specific package and version without requiring a full npm audit environment or a subscription-based security API. It is well-suited for agents automating dependency vetting in CI workflows, code review assistants, or any scenario where a quick, serverless vulnerability lookup is needed on the fly.

## Known failure modes

- Unknown or misspelled package name returns empty or error response
- Version string not found in vulnerability database returns zero vulnerabilities even if unsafe
- Missing required query parameters (package name or version) may return a 400 or malformed response
- Rate limiting or payment failure (x402) may block the request
- Edge worker downtime may return 5xx errors

## How this service works

Stable edge-hosted x402 utilities for autonomous agents.

## Output

Returns a JSON object containing the package name, version queried, a list of detected vulnerabilities (if any), and a total vulnerability count. An empty vulnerabilities array indicates no known issues for that package/version combination.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "required": {
   "type": "string"
  },
  "properties": {
   "type": "string"
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "package": "example",
  "version": "1.0.0",
  "vulnerabilities": [],
  "vulnerabilityCount": 0
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/free-asset-radar-package-vulnerability-check-e0b7ce13/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from free-asset-radar-x402.besenok2018.workers.dev](https://www.zero.xyz/host/free-asset-radar-x402.besenok2018.workers.dev/llms.txt)
