# manifest-audit

> manifest-audit is a paid API for AI agents from audit.152-53-82-29.sslip.io, paid per call via x402, $0.005/call, status unknown (last checked 2026-10-02).

Audits npm packages for latest version, license, deprecation, weekly downloads, and known vulnerabilities before installation or upgrade

## Facts

- Endpoint: POST https://audit.152-53-82-29.sslip.io/v1/npm?utm_source=zero.xyz
- Price: $0.005/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/manifest-audit-faf0ea93
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_qVGkDyU-FCNtQq-O2Nk4V

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability manifest-audit-faf0ea93 -d '<json body>'
```

Example prompt: Before I install these packages, can you audit lodash@4.17.20, express, and react@18.0.0 for known vulnerabilities, check if they're behind the latest version, and tell me their licenses?

## When to prefer this

Use this endpoint when you need deterministic, registry-sourced npm package metadata — vulnerability data, license info, version lag, and deprecation status — without LLM hallucination risk. It accepts either a flat list of package strings or a raw package.json structure, making it ideal for CI/CD automation, pre-install checks, and supply chain audits for up to 50 npm packages at once.

## Known failure modes

- More than 50 packages submitted — request will be rejected
- Invalid package name format — returns error for unrecognized package identifier
- Package not found in npm registry — returns not-found status for that entry
- No packages or dependencies fields provided — returns validation error
- Network timeout reaching npm registry or OSV database

## How this service works

Check npm packages before you install or upgrade. Send {"packages":["lodash@4.17.20","express"]} or a package.json (dependencies and devDependencies), up to 50 packages. Per package: latest version and publish date, whether a pinned version is behind, license, deprecation notice, weekly downloads, and known vulnerabilities from OSV with severity and first fixed version. Deterministic registry data, no LLM.

## Output

For each package: latest version and publish date, whether a pinned version is behind latest, SPDX license identifier, any deprecation notice, weekly download count, and a list of known OSV vulnerabilities with severity ratings and the first fixed version available.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "packages": {
   "type": "array",
   "items": {
    "type": "string"
   },
   "description": "npm packages as name or name@version"
  },
  "dependencies": {
   "type": "object"
  },
  "devDependencies": {
   "type": "object"
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/manifest-audit-faf0ea93/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from audit.152-53-82-29.sslip.io](https://www.zero.xyz/host/audit.152-53-82-29.sslip.io/llms.txt)
