# manifest-audit

> manifest-audit is a paid API for AI agents from audit.152-53-82-29.sslip.io, paid per call via x402, $0.01/call, status healthy (last checked 2026-10-01, last successful call 2026-09-25).

Audits npm or PyPI dependency manifests for outdated versions, licenses, deprecations, download stats, and known vulnerabilities in one API call

## Facts

- Endpoint: POST https://audit.152-53-82-29.sslip.io/v1/audit?utm_source=zero.xyz
- Price: $0.01/call
- Payment: x402
- Status: healthy
- Last checked: 2026-10-01
- Last successful call: 2026-09-25
- Activations on Zero: 1
- Tags: x402
- Canonical page: https://www.zero.xyz/c/manifest-audit-31b155e5
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_gK4VnmYd35FSgSB7xy4cU

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability manifest-audit-31b155e5 -d '<json body>'
```

Example prompt: Before I run npm install, can you audit these packages for vulnerabilities, outdated versions, and license issues: lodash@4.17.20, express@4.18.0, and axios?

## When to prefer this

Use this endpoint when you need a comprehensive, multi-signal dependency health check in a single call — combining version staleness, license data, deprecation/yanked status, popularity (npm downloads), and OSV vulnerability data together. Prefer it over single-purpose vulnerability scanners when you need the full picture before installing, upgrading, or approving a lockfile diff. Best suited for CI/CD pre-checks, code review automation, and agent-driven dependency management workflows where deterministic (non-LLM) results are required.

## Known failure modes

- More than 50 packages submitted — batch size limit exceeded
- Invalid package name or version string format causing lookup failure
- Package not found on npm or PyPI registry
- ecosystem field missing when manifest is a requirements.txt
- Network or registry timeout causing incomplete results for some packages

## How this service works

Audit a whole dependency manifest in one call before installing or upgrading. Send a package.json, a requirements.txt, or npm and PyPI package lists (up to 50 packages). Per dependency: latest version and publish date, whether your pin is behind, license, deprecation or yanked status, weekly npm downloads, and known vulnerabilities from OSV with severity and first fixed version. Deterministic, no LLM. Use before adding or bumping deps or when reviewing a lockfile change.

## Output

For each submitted package: the latest available version and its publish date, whether the submitted pin is behind latest, the package license, deprecation or yanked status, weekly npm download count (for npm packages), and a list of known OSV vulnerabilities with severity levels and the first version where each was fixed.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "npm": {
   "type": "array",
   "items": {
    "type": "string"
   },
   "description": "npm packages as name or name@version"
  },
  "pypi": {
   "type": "array",
   "items": {
    "type": "string"
   },
   "description": "PyPI requirement lines, for example requests==2.25.0"
  },
  "manifest": {
   "type": "string",
   "description": "Raw package.json or requirements.txt text"
  },
  "ecosystem": {
   "enum": [
    "npm",
    "pypi"
   ],
   "type": "string",
   "description": "Required with `manifest` when it is a requirements.txt"
  },
  "dependencies": {
   "type": "object",
   "description": "package.json dependencies map"
  },
  "devDependencies": {
   "type": "object",
   "description": "package.json devDependencies map"
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/manifest-audit-31b155e5/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from audit.152-53-82-29.sslip.io](https://www.zero.xyz/host/audit.152-53-82-29.sslip.io/llms.txt)
