# manifest-audit

> manifest-audit is a paid API for AI agents from audit.152-53-82-29.sslip.io, paid per call via x402, $0.005/call, status unknown (last checked 2026-10-02).

Check a list of npm and/or PyPI packages (or a raw manifest file) for known vulnerabilities in a single call, returning OSV/GHSA advisories, CVEs, severity, and first fixed version.

## Facts

- Endpoint: POST https://audit.152-53-82-29.sslip.io/v1/vulns?utm_source=zero.xyz
- Price: $0.005/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/manifest-audit-0d60a87c
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_pCBbuhveP7TSf5RQFTsjk

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability manifest-audit-0d60a87c -d '<json body>'
```

Example prompt: Before I install these packages, check them for known security vulnerabilities: npm packages lodash@4.17.20 and express@4.18.0, and PyPI packages django==3.2.0 and requests==2.28.0 — give me OSV/GHSA IDs, severity, and the first fixed version for anything flagged.

## When to prefer this

Use this endpoint when you need a single API call to audit a mixed npm+PyPI dependency list (or a raw manifest file) against deterministic, structured OSV/GHSA data — with no LLM hallucination risk. Prefer it over language-specific audit tools when you need cross-ecosystem coverage in one request, or when you need machine-readable advisory IDs, CVE aliases, and first-fixed-version fields for automated gating in CI/CD pipelines.

## Known failure modes

- More than 50 packages submitted — request exceeds limit
- Invalid package name or version format — package skipped or error returned
- Unknown package not found in OSV database — treated as no advisories
- Missing both npm and pypi fields with no manifest — malformed request error
- Network or OSV upstream timeout — 5xx error response

## How this service works

Known vulnerabilities for a list of dependencies, npm and PyPI, in one call. Send {"npm":["lodash@4.17.20"],"pypi":["django==3.2.0"]} or a package.json or requirements.txt, up to 50 packages. Returns only packages that have advisories: OSV and GHSA ids, CVE aliases, severity, summary, and the first fixed version, plus counts. Unpinned packages are checked at their latest version. Deterministic OSV data, no LLM.

## Output

Returns only packages that have known advisories. For each vulnerable package: OSV and GHSA identifiers, CVE aliases, severity level, a human-readable summary of the vulnerability, and the earliest version that fixes the issue. Also includes aggregate counts of vulnerable packages and total advisories found. Packages with no advisories are omitted from the response.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "npm": {
   "type": "array",
   "items": {
    "type": "string"
   }
  },
  "pypi": {
   "type": "array",
   "items": {
    "type": "string"
   }
  },
  "manifest": {
   "type": "string"
  },
  "ecosystem": {
   "enum": [
    "npm",
    "pypi"
   ],
   "type": "string"
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/manifest-audit-0d60a87c/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from audit.152-53-82-29.sslip.io](https://www.zero.xyz/host/audit.152-53-82-29.sslip.io/llms.txt)
