Package check ($0.005)
package-checkShould a coding agent install this package? Checks one npm, PyPI, crates or Go package version for known vulnerabilities and malware (OSV.dev), deprecation, typosquat look-alike names, install scripts, licence, downloads, release activity and OpenSSF Scorecard, then gives a verdict (ok/caution/avoid), a 0-100 score and every reason. Price: $0.005 in USDC per call (x402 or prepaid credits). In the free trial.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | Package name, e.g. express, requests, serde or github.com/gin-gonic/gin. | |
| version | No | Exact version to check (default: the latest release). | |
| ecosystem | No | Package ecosystem: npm, pypi, crates (Rust) or go (Go modules). | npm |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | ||
| repo | No | GitHub stars, forks, open issues and OpenSSF Scorecard (0-10). | |
| flags | Yes | Every reason behind the verdict. | |
| score | Yes | 0-100, higher is safer. | |
| sources | No | ||
| verdict | Yes | ||
| version | Yes | Version checked. | |
| isLatest | No | ||
| licences | Yes | ||
| releases | No | latest, latestPublishedAt, firstPublishedAt, versions, releasesLast365Days. | |
| checkedAt | No | ||
| ecosystem | Yes | ||
| deprecated | No | ||
| repository | No | ||
| description | No | ||
| licenceKind | No | ||
| lookalikeOf | No | Popular packages this name resembles (typosquat check). | |
| maintainers | No | ||
| latestVersion | No | ||
| installScripts | No | npm install hooks that run code on install. | |
| vulnerabilities | Yes | Known vulnerabilities in this version (most severe first, up to 25). | |
| weeklyDownloads | No | ||
| vulnerabilityCounts | No |