software_risk_check
Should I install this package version? Known vulnerabilities for one package@version from OSV.dev (GitHub, PyPA, Go and RustSec advisories), whether any is on CISA's Known Exploited Vulnerabilities list, and the version that fixes each, with the licence and credit for every source. Absence of advisories is not proof of safety. $0.003 per call over x402 (USDC on Arc, Base or Solana, or XNT on X1). Call once without payment for the terms, sign them with your own wallet, call again with payment.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| package | Yes | package name, e.g. lodash | |
| payment | No | a signed x402 payment (the base64 payload you would put in PAYMENT-SIGNATURE). Pass it and the purchase completes inside this tool call. | |
| version | Yes | exact version, e.g. 4.17.15 | |
| ecosystem | Yes | npm, PyPI, Go, crates.io, Maven, NuGet, RubyGems, Packagist, Hex or Pub |