Agentic Portal

Package Security Advisories

security
Serving

Dependency health across PyPI, npm, Go, Cargo, Maven, Composer, and NuGet via deps.dev and OSV: versions, licenses, and known vulnerabilities. POST /v1/tool with {package, ecosystem}, or GET /v1/package for the Bazaar listing. Deterministic per advisory state. Pay per request in USDC; no account, no API key.

Endpoint
POST https://agent.pocket.network/v1/package-advisories
Price per call
$0.005 USD
Networks payable on
Base (eip155:8453)
Protocol
rest

Calling it

The first call returns 402 Payment Required with the terms. Sign for those terms and retry the same request with the payment attached.

Example request

Derived from the published request schema.

curl -X POST https://agent.pocket.network/v1/package-advisories \
  -H 'content-type: application/json' \
  -d '{"package":"requests","ecosystem":"pypi","version":"string"}'
Example response

This service declares its response shape in prose rather than as fields, so there is nothing more specific to sample.

{}

Try it

Make one real paid call from your own wallet — about $0.005 on Base (eip155:8453). The wallet signs; nothing here holds a key. You'll see exactly what the service answers.

No browser wallet found. Install MetaMask, Rabby, or Coinbase Wallet to try a call here.

Supported methods

Methods the registry lists for this service. The portal forwards any call as sent; the supplier decides what it answers, and a delivered answer is settled.

Methods Package Security Advisories accepts, and whether each reads or writes.
MethodEffect
GET /v1/healthread
GET /v1/packageread
GET /v1/versionread
POST /v1/toolread

Schemas

Published by the service itself. The example above is generated from these.

Request schema
{
  "type": "object",
  "description": "A package to audit. On the MCP relay route POST /v1/tool these fields are wrapped under an `arguments` object; the direct route takes them at the top level. GET /v1/package is the direct Bazaar query route.",
  "properties": {
    "package": {
      "type": "string",
      "description": "Package name, e.g. requests."
    },
    "ecosystem": {
      "type": "string",
      "description": "Ecosystem, e.g. pypi, npm, go, cargo, maven, composer, nuget."
    },
    "version": {
      "type": "string",
      "description": "Optional specific version."
    }
  },
  "required": [
    "package"
  ]
}
Response schema
{
  "type": "object",
  "description": "For POST /v1/tool, a JSON object with the latest_version, versions, licenses, and known vulnerabilities. The exact shape is the service's own and is not pinned here; errors return a JSON object with an `error` field, and the GET routes return their own small JSON documents."
}

Request body used in the example: { "package": "requests", "ecosystem": "pypi", "version": "string" }