# manifest-audit PyPI Package Security Auditor

> manifest-audit PyPI Package Security Auditor is a paid API for AI agents from audit.152-53-82-29.sslip.io, paid per call via x402, $0.005/call, status unknown (last checked 2026-10-02).

Audits Python PyPI packages for vulnerabilities, license info, version staleness, yanked status, and Python compatibility before installation or version bumps

## Facts

- Endpoint: POST https://audit.152-53-82-29.sslip.io/v1/pypi?utm_source=zero.xyz
- Price: $0.005/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/manifest-audit-pypi-package-security-auditor-226af3ee
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_9SBk8uzLWydD0tJLLpb5J

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability manifest-audit-pypi-package-security-auditor-226af3ee -d '<json body>'
```

Example prompt: Before I run pip install, can you audit these packages for known vulnerabilities, license info, and whether any versions are outdated or yanked: requests==2.25.0, flask>=2.0, and django==3.2.1?

## When to prefer this

Use this endpoint when you need a deterministic, non-LLM audit of Python/PyPI packages specifically — covering vulnerabilities, version staleness, yanked status, license, and Python compatibility in one call. Prefer it over generic vulnerability scanners when you need structured per-package OSV data with first-fixed-version information, or when you want to validate a full requirements.txt before a deploy or dependency bump. Choose the combined npm+PyPI sibling endpoint if you have a mixed-language project.

## Known failure modes

- Package name not found on PyPI returns an error for that entry
- More than 50 packages submitted returns a 400-class error
- Malformed requirement specifier (e.g. invalid version syntax) causes parsing failure for that line
- OSV database may not have real-time coverage of very newly disclosed CVEs
- Network timeout if PyPI or OSV APIs are slow to respond

## How this service works

Check Python packages from PyPI before you pip install or bump versions. Send {"packages":["requests==2.25.0","flask>=2.0"]} or {"requirements":"<requirements.txt text>"}, up to 50 packages. Per package: latest release and date, whether a pinned version is behind, license, yanked status, requires_python, and known vulnerabilities from OSV with severity and first fixed version. Deterministic, no LLM.

## Output

A per-package breakdown including: the latest available release and its publish date, whether the specified version is behind latest, SPDX license identifier, whether the version has been yanked from PyPI, the requires_python field, and any known vulnerabilities from the OSV database with severity rating and the first version that fixes each issue.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "packages": {
   "type": "array",
   "items": {
    "type": "string"
   },
   "description": "PyPI requirement lines"
  },
  "requirements": {
   "type": "string",
   "description": "Raw requirements.txt text"
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/manifest-audit-pypi-package-security-auditor-226af3ee/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from audit.152-53-82-29.sslip.io](https://www.zero.xyz/host/audit.152-53-82-29.sslip.io/llms.txt)
