Ask Koot: Is My Stack Safe?
brief_stackRead-onlyIdempotent
One call answers 'is my project safe?'. Checks every package for known vulnerabilities, tells you which are being EXPLOITED IN THE WILD right now (CISA KEV) or likely to be (EPSS), flags abandoned/deprecated packages, and returns a ranked fix-first list. Accepts a package list or a pasted package.json / requirements.txt.
Input Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| manifest | No | Or paste a whole package.json or requirements.txt here. | |
| packages | No | Packages as 'name' or 'name@version' strings (or {name, version, ecosystem} objects), e.g. ["lodash@4.17.15", "express"]. | |
| ecosystem | No | Registry for string packages (default npm). |
Output Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| koot | Yes | Koot's one-line answer. |