# Pocket Network Package Advisories

> Pocket Network Package Advisories is a paid API for AI agents from agent.pocket.network, paid per call via x402, $0.005/call, status unknown (last checked 2026-10-02).

Returns dependency health data for a given package and ecosystem, including versions, licenses, and known vulnerabilities sourced from deps.dev and OSV

## Facts

- Endpoint: POST https://agent.pocket.network/v1/package-advisories?utm_source=zero.xyz
- Price: $0.005/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/pocket-network-package-advisories-357a840f
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_1HLZymRzNJKhGBh6J3k4E

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability pocket-network-package-advisories-357a840f -d '<json body>'
```

Example prompt: Can you check if the npm package lodash has any known vulnerabilities or security advisories?

## When to prefer this

Choose this endpoint when you need a pay-per-request, no-account vulnerability and license check across multiple ecosystems (PyPI, npm, Go, Cargo, Maven, Composer, NuGet) without setting up API keys. It is ideal for agents performing automated dependency audits, supply chain risk checks, or license compliance screening as part of a CI/CD or code review workflow. Prefer it over manual OSV or deps.dev queries when you want a unified, USDC-metered interface callable directly by an AI agent.

## Known failure modes

- Unknown package name returns empty or not-found response
- Unsupported ecosystem value causes a validation error
- Specific version not found in registry returns error or empty advisory list
- Network timeout from upstream deps.dev or OSV data source
- Malformed request body missing required package or ecosystem fields

## How this service works

Dependency health across PyPI, npm, Go, Cargo, Maven, Composer, and NuGet via deps.dev and OSV: versions, licenses, and known vulnerabilities. POST /v1/tool with {package, ecosystem}, or GET /v1/package for the Bazaar listing. Deterministic per advisory state. Pay per request in USDC; no account, no API key.

## Output

Returns structured dependency health data for the requested package including known vulnerability advisories (CVEs, OSV IDs), license type(s), available versions, and overall health signals sourced from deps.dev and the OSV database. Results are deterministic relative to the current advisory state.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "package": {
   "type": "string",
   "description": "Package name, e.g. requests."
  },
  "version": {
   "type": "string",
   "description": "Optional specific version."
  },
  "ecosystem": {
   "type": "string",
   "description": "Ecosystem, e.g. pypi, npm, go, cargo, maven, composer, nuget."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "data": {},
  "portal": {
   "serviceId": "package-advisories",
   "provenance": "third-party-supplier",
   "schemaCheck": "passed"
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/pocket-network-package-advisories-357a840f/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from agent.pocket.network](https://www.zero.xyz/host/agent.pocket.network/llms.txt)
