# Package Risk Vulnerability Scanner

> Package Risk Vulnerability Scanner is a paid API for AI agents from dependency-truth.inboxtzdjqv.workers.dev, paid per call via x402, $0.006/call, status unknown (last checked 2026-10-02).

Checks a specific npm or PyPI package version for known security vulnerabilities using OSV.dev data, payable per call via x402.

## Facts

- Endpoint: POST https://dependency-truth.inboxtzdjqv.workers.dev/v1/package-risk?utm_source=zero.xyz
- Price: $0.006/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/package-risk-vulnerability-scanner-ce70d57e
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_hv74L37V4cGVa-XUh-oTy

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability package-risk-vulnerability-scanner-ce70d57e -d '<json body>'
```

Example prompt: Can you check whether express version 5.0.0 on npm has any known security vulnerabilities?

## When to prefer this

Choose this endpoint when you need a deterministic, per-call, pay-as-you-go vulnerability check against OSV.dev for a specific npm or PyPI package version — ideal for CI/CD pipelines, agent-driven dependency audits, or one-off security checks without a subscription. Prefer this over full SCA platforms when you only need lightweight, single-package lookups payable in USDC.

## Known failure modes

- Unknown or misspelled package name returns empty or error response
- Unsupported ecosystem (anything other than npm or pypi) rejected by enum validation
- Missing required fields (package, version, or ecosystem) cause validation error
- Payment failure via x402 protocol blocks the request
- Very new package versions may not yet be indexed in OSV.dev

## How this service works

Deterministic package, repository, security, and citation evidence APIs payable per call with x402.

## Output

Returns a JSON object containing the package name, version, ecosystem, the source URL (OSV.dev), a list of known vulnerabilities (if any), and a total vulnerability count. An empty vulnerabilities array with count 0 indicates no known issues.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "package": {
   "type": "string"
  },
  "version": {
   "type": "string"
  },
  "ecosystem": {
   "enum": [
    "npm",
    "pypi"
   ],
   "type": "string"
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "source": "https://api.osv.dev",
  "package": "express",
  "version": "5.0.0",
  "ecosystem": "npm",
  "vulnerabilities": [],
  "vulnerabilityCount": 0
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/package-risk-vulnerability-scanner-ce70d57e/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from dependency-truth.inboxtzdjqv.workers.dev](https://www.zero.xyz/host/dependency-truth.inboxtzdjqv.workers.dev/llms.txt)
