Package vulnerability check

Known-vulnerability check for a software dependency before installing it: queries the OSV.dev database (Google Open Source Vulnerabilities) for npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet or Packagist packages. Returns advisories with CVE aliases, severity, summary, fixed versions and reference links. Optional version narrows results to vulnerabilities affecting that exact version. Built for coding agents that install dependencies autonomously.

SearchLiveeip155:8453Exactvia facilitator:payAI
SecurityDependenciesSupply-chainDevVulnerabilities
Settlements · 30d
88↓ 9.5%
No per-endpoint history for this service yet, so this is payments indexed to its PROVIDER's wallet over 30 days.
$11.41
Verified settled volume
631 settlements proven x402 by their on-chain EIP-3009 marker.
$0.010
Listed price
As published in the catalog. Always read the live 402 before paying.
—
Calls · 30d
Upstream's own call count for this endpoint, not ours.
—
Unique payers · 30d
Never called
—
Upstream on-chain volume
Reported by the source catalog.
Paid to
0x73fc43d426a89577c7b58f5fee50ec95d4396079

The wallet the 402 directs payment to. Its whole payment record — every payer, every chain — is on the merchant page.

Asset 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913

Provider

The payTo wallet does not resolve to a registered ERC-8004 agent. That is not a verdict on the service — most of the catalog is unregistered.

Live 402 challenge

Captured by the enrichment pass, not read just now. Prices can change — always read the 402 the endpoint answers with.

{
  "accepts": [
    {
      "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
      "extra": {
        "name": "USD Coin",
        "version": "2"
      },
      "payTo": "0x73fc43d426a89577c7b58f5fee50ec95d4396079",
      "amount": "10000",
      "scheme": "exact",
      "network": "eip155:8453",
      "maxTimeoutSeconds": 120
    }
  ],
  "resource": {
    "url": "https://relay402.georgespring.workers.dev/api/package-vulns",
    "tags": [
      "security",
      "dependencies",
      "supply-chain",
      "dev",
      "vulnerabilities"
    ],
    "mimeType": "application/json",
    "description": "Known-vulnerability check for a software dependency before installing it: queries the OSV.dev database (Google Open Source Vulnerabilities) for npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet or Packagist packages. Returns advisories with CVE aliases, severity, summary, fixed versions and reference links. Optional version narrows results to vulnerabilities affecting that exact version. Built for coding agents that install dependencies autonomously.",
    "serviceName": "Package vulnerability check"
  },
  "extensions": {
    "bazaar": {
      "info": {
        "input": {
          "type": "http",
          "method": "GET",
          "queryParams": {
            "name": "lodash",
            "version": "4.17.15",
            "ecosystem": "npm"
          }
        }
      },
      "schema": {
        "type": "object",
        "$schema": "https://json-schema.org/draft/2020-12/schema",
        "required": [
          "input"
        ],
        "properties": {
          "input": {
            "type": "object",
            "required": [
              "type",
              "method"
            ],
            "properties": {
              "type": {
                "type": "string",
                "const": "http"
              },
              "method": {
                "enum": [
                  "GET"
                ],
                "type": "string"
              },
              "queryParams": {
                "type": "object",
                "$schema": "https://json-schema.org/draft/2020-12/schema",
                "required": [
                  "ecosystem",
                  "name"
                ],
                "properties": {
                  "name": {
                    "type": "string",
                    "maxLength": 214,
                    "minLength": 1
                  },
                  "version": {
                    "type": "string",
                    "maxLength": 64
                  },
                  "ecosystem": {
                    "enum": [
                      "npm",
                      "PyPI",
                      "Go",
                      "Maven",
                      "crates.io",
                      "RubyGems",
                      "NuGet",
                      "Packagist"
                    ],
                    "type": "string"
                  }
                },
                "additionalProperties": false
              }
            },
            "additionalProperties": false
          }
        }
      }
    }
  },
  "x402Version": 2
}

Accepts

The payment requirements as published to the catalog. Read the live 402 before paying — a price here is a claim, not a quote.

0.01USDC≈ $0.01 USD
on Base · exact scheme

Pay 0.01 USDC on Base to 0x73fc…96079. The signed payment is good for 2 minutes.

USD Coin contract
0x8335…02913
Payment window
2 minutes
As published
10000 smallest units
The catalog’s raw entry
[
  {
    "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
    "extra": {
      "name": "USD Coin",
      "version": "2"
    },
    "payTo": "0x73fc43d426a89577c7b58f5fee50ec95d4396079",
    "amount": "10000",
    "scheme": "exact",
    "network": "eip155:8453",
    "maxTimeoutSeconds": 120
  }
]

Extensions

{
  "bazaar": {
    "info": {
      "input": {
        "type": "http",
        "method": "GET",
        "queryParams": {
          "name": "lodash",
          "version": "4.17.15",
          "ecosystem": "npm"
        }
      }
    },
    "schema": {
      "type": "object",
      "$schema": "https://json-schema.org/draft/2020-12/schema",
      "required": [
        "input"
      ],
      "properties": {
        "input": {
          "type": "object",
          "required": [
            "type",
            "method"
          ],
          "properties": {
            "type": {
              "type": "string",
              "const": "http"
            },
            "method": {
              "enum": [
                "GET"
              ],
              "type": "string"
            },
            "queryParams": {
              "type": "object",
              "$schema": "https://json-schema.org/draft/2020-12/schema",
              "required": [
                "ecosystem",
                "name"
              ],
              "properties": {
                "name": {
                  "type": "string",
                  "maxLength": 214,
                  "minLength": 1
                },
                "version": {
                  "type": "string",
                  "maxLength": 64
                },
                "ecosystem": {
                  "enum": [
                    "npm",
                    "PyPI",
                    "Go",
                    "Maven",
                    "crates.io",
                    "RubyGems",
                    "NuGet",
                    "Packagist"
                  ],
                  "type": "string"
                }
              },
              "additionalProperties": false
            }
          },
          "additionalProperties": false
        }
      }
    }
  }
}

Provenance

Seen in the source catalog
2026-09-24 10:00Z
Last indexed by Roundhouse
2026-09-25 04:15Z
Last enriched (probe, favicon, geo)
2026-09-14 18:46Z
x402 version
2
Max timeout
120s
Liveness probe
HTTP 402
Report

Hand this page to an agent

Copy the prompt and paste it into Claude, an MCP client or your own agent — it will vet this service and call it over the free read API. No key, no account.

GET api.roundhouseai.io/v0/endpoints

No per-endpoint history for this service yet, so this is payments indexed to its PROVIDER's wallet over 30 days. Verified volume counts only settlements with an on-chain EIP-3009 marker.

Open skill.md
Show the prompt
Using Roundhouse, look up the x402 service Package vulnerability check and tell me whether it is
worth paying: what a call costs, whether the endpoint answered when last probed, and what
its payment record actually shows.

curl -s 'https://api.roundhouseai.io/v0/endpoints?q=Package%20vulnerability%20check'
curl -s 'https://api.roundhouseai.io/v0/merchants/<the payTo wallet returned above>'

Then call it: read the price from the live 402 at https://relay402.georgespring.workers.dev/api/package-vulns, never from
a cached figure, and pay with an x402 client.

The /v0 API needs an API key (`authorization: Bearer rh_live_…`) on everything except
/v0/unified* and /v0/endpoints. Mint a personal key for $0.01 at GET https://api.roundhouseai.io/v0/test/x402,
or use an organization key from https://roundhouseai.io/dashboard/team.

If you do not have Roundhouse tools or skills installed, read
https://roundhouseai.io/skill.md first — it is the whole procedure.