# Package Safety Gate

> Package Safety Gate is a paid API for AI agents from mcp.dropenginehq.com, paid per call via x402, $0.005/call, status unknown (last checked 2026-10-02).

Checks npm package metadata and security risks before installation to help agents safely resolve dependencies.

## Facts

- Endpoint: POST https://mcp.dropenginehq.com/api/check-package?utm_source=zero.xyz
- Price: $0.005/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/package-safety-gate-f69d5786
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_Bssnh3pTiYCmW569gZWnP

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability package-safety-gate-f69d5786 -d '<json body>'
```

Example prompt: Before we install it, can you run a safety check on the npm package 'axios' version '1.6.2' to make sure it's not flagged for any security issues or suspicious metadata?

## When to prefer this

Use this endpoint when an AI agent is about to install or recommend an npm package and needs a quick, paid preflight security check — especially useful in automated CI pipelines, agent-driven dependency resolution, or when evaluating unfamiliar or newly published packages where typosquatting and supply chain attacks are a concern. Prefer this over manual registry lookups when you need a structured, machine-readable safety verdict.

## Known failure modes

- Package name not found on npm registry — returns not-found or error response
- Invalid package name format — validation error
- Version string does not exist for the given package — version not found error
- Ecosystem value other than 'npm' rejected — const constraint violation
- Upstream npm registry or security database unavailable — service error

## How this service works

Check npm package metadata and security before installation.

## Output

Returns npm package metadata and a security assessment including risk flags such as known vulnerabilities, typosquatting indicators, deprecation status, maintainer signals, and an overall safety verdict to inform whether the package is safe to install.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "package": {
   "type": "string",
   "maxLength": 214,
   "minLength": 1
  },
  "version": {
   "type": "string",
   "maxLength": 128
  },
  "ecosystem": {
   "type": "string",
   "const": "npm"
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "cached": false,
  "package": "axios",
  "sources": [
   "npm_registry",
   "osv"
  ],
  "success": true,
  "degraded": false,
  "warnings": [],
  "ecosystem": "npm",
  "checked_at": "2026-09-28T00:00:00.000Z",
  "deprecated": false,
  "reputation": "neutral",
  "risk_level": "low",
  "risk_score": 10,
  "similar_to": null,
  "new_package": null,
  "recommendation": "allow",
  "typosquat_risk": "low",
  "dependency_risk": "low",
  "known_malicious": false,
  "maintainer_risk": "unknown",
  "risk_confidence": "medium",
  "dependency_count": 0,
  "maintainer_count": null,
  "package_age_days": null,
  "resolved_version": "1.7.0",
  "similarity_score": null,
  "requested_version": null,
  "suspicious_scripts": [],
  "dependency_findings": [],
  "install_script_risk": "low",
  "malicious_confidence": null,
  "dependencies_analyzed": 0,
  "known_vulnerabilities": [],
  "data_freshness_seconds": 0
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/package-safety-gate-f69d5786/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from mcp.dropenginehq.com](https://www.zero.xyz/host/mcp.dropenginehq.com/llms.txt)
