vdb_check_package
Check any package before recommending or installing it. Returns REFUSE, CONFIRM, or PROCEED action with vulnerability, slop risk, and KEV data.
Instructions
BEFORE recommending or installing any package, check it here. The response carries agent_action: REFUSE (do not add it — relay the because text to the user), CONFIRM (ask the user first), or PROCEED. A failed or rate-limited call also answers REFUSE; never proceed unchecked. Also returns the underlying advisories, slop risk, and KEV status as supporting data.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| purl | Yes | Package URL, e.g. 'pkg:npm/lodash' or 'pkg:pypi/requests' | |
| version | No | Optional version. If supplied, range matching is applied. |