# Pocket Network Taint Check — Dependency Security Scanner

> Pocket Network Taint Check — Dependency Security Scanner is a paid API for AI agents from agent.pocket.network, paid per call via x402, $0.005/call, status unknown (last checked 2026-10-02).

Scans a dependency lockfile or component list for known-vulnerable and malicious packages, returning per-dependency verdicts sourced from OSV.dev and the OpenSSF Malicious Packages feed.

## Facts

- Endpoint: POST https://agent.pocket.network/v1/taint-check?utm_source=zero.xyz
- Price: $0.005/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/pocket-network-taint-check-dependency-security-scanner-a6d22765
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_TKOd6KLeR-atNU4kHRoqm

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability pocket-network-taint-check-dependency-security-scanner-a6d22765 -d '<json body>'
```

Example prompt: Can you scan my package-lock.json for any malicious or vulnerable npm packages? I want verdicts for each dependency, including typosquat and install-script heuristics enabled.

## When to prefer this

Choose this endpoint when you need a fast, pay-per-call dependency security scan without setting up an account or API key — especially useful for ephemeral CI/CD pipelines, agent workflows, or one-off audits. It is ideal when you need combined coverage from both OSV.dev vulnerability data and the OpenSSF Malicious Packages feed in a single call, with optional heuristics for typosquatting and install-script signals. Prefer it over alternatives when you want to scan raw lockfiles directly without pre-processing.

## Known failure modes

- Unsupported lockfile format returns a validation error
- Malformed or unparseable lockfile content results in a parse error
- Packages not found in OSV.dev or OpenSSF are returned as clean with no advisory data
- Very large lockfiles may time out or be rejected if they exceed size limits
- Stale snapshot timestamps may mean very recent advisories are not yet reflected
- Payment not provided or insufficient USDC results in a 402 Payment Required response

## How this service works

Scan a dependency manifest for known-vulnerable and confirmed-malicious packages. POST /v1/scan with a raw lockfile or a components array and get per-dependency verdicts (malicious, vulnerable, suspicious, clean) from OSV.dev and the OpenSSF Malicious Packages feed, each with a summary and snapshot timestamp. Pay per request in USDC; no account, no API key.

## Output

A per-dependency list of verdicts (malicious, vulnerable, suspicious, or clean), each with an advisory summary, the data source (OSV.dev or OpenSSF Malicious Packages), and a snapshot timestamp indicating when the advisory data was last updated.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "options": {
   "type": "object",
   "properties": {
    "since": {
     "type": "string",
     "description": "Only advisories newer than this timestamp (monitor mode)."
    },
    "heuristics": {
     "type": "boolean",
     "description": "Add typosquat, install-script and dormancy signals."
    }
   },
   "description": "Scan options."
  },
  "lockfile": {
   "type": "object",
   "properties": {
    "format": {
     "enum": [
      "package-lock.json",
      "pnpm-lock.yaml",
      "yarn.lock",
      "requirements.txt",
      "poetry.lock",
      "uv.lock",
      "Pipfile.lock",
      "Cargo.lock",
      "go.sum"
     ],
     "type": "string",
     "description": "Lockfile format."
    },
    "content": {
     "type": "string",
     "description": "Raw lockfile content."
    }
   },
   "description": "A raw lockfile."
  },
  "components": {
   "type": "array",
   "items": {
    "type": "object",
    "properties": {
     "name": {
      "type": "string",
      "description": "Package name."
     },
     "version": {
      "type": "string",
      "description": "Package version."
     },
     "ecosystem": {
      "type": "string",
      "description": "e.g. npm, pypi, go, cargo."
     }
    }
   },
   "description": "Pre-parsed dependencies."
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "data": {},
  "portal": {
   "serviceId": "taint-check",
   "provenance": "third-party-supplier",
   "schemaCheck": "passed"
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/pocket-network-taint-check-dependency-security-scanner-a6d22765/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from agent.pocket.network](https://www.zero.xyz/host/agent.pocket.network/llms.txt)
