{
  "serviceId": "taint-check",
  "displayName": "TaintCheck",
  "description": "Scan a dependency manifest for known-vulnerable and confirmed-malicious packages. POST /v1/scan with a raw lockfile or a components array and get per-dependency verdicts (malicious, vulnerable, suspicious, clean) from OSV.dev and the OpenSSF Malicious Packages feed, each with a summary and snapshot timestamp. Pay per request in USDC; no account, no API key.",
  "category": "security",
  "resourceUrl": "https://agent.pocket.network/v1/taint-check",
  "priceUsd": "0.005000",
  "priceVersion": 1,
  "rails": [
    {
      "id": "base",
      "network": "eip155:8453",
      "chainId": 8453,
      "tokenAddress": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
      "tokenDecimals": 6,
      "payToAddress": "0xF732ea490c5766071785a2310523f7fA2CEbB829"
    }
  ],
  "protocols": [
    "rest"
  ],
  "inputSchema": {
    "type": "object",
    "description": "Provide either a raw lockfile or a pre-parsed components array; body size and component limits come from GET /v1/capabilities.",
    "properties": {
      "lockfile": {
        "type": "object",
        "description": "A raw lockfile.",
        "properties": {
          "format": {
            "type": "string",
            "enum": [
              "package-lock.json",
              "pnpm-lock.yaml",
              "yarn.lock",
              "requirements.txt",
              "poetry.lock",
              "uv.lock",
              "Pipfile.lock",
              "Cargo.lock",
              "go.sum"
            ],
            "description": "Lockfile format."
          },
          "content": {
            "type": "string",
            "description": "Raw lockfile content."
          }
        }
      },
      "components": {
        "type": "array",
        "description": "Pre-parsed dependencies.",
        "items": {
          "type": "object",
          "properties": {
            "ecosystem": {
              "type": "string",
              "description": "e.g. npm, pypi, go, cargo."
            },
            "name": {
              "type": "string",
              "description": "Package name."
            },
            "version": {
              "type": "string",
              "description": "Package version."
            }
          }
        }
      },
      "options": {
        "type": "object",
        "description": "Scan options.",
        "properties": {
          "since": {
            "type": "string",
            "description": "Only advisories newer than this timestamp (monitor mode)."
          },
          "heuristics": {
            "type": "boolean",
            "description": "Add typosquat, install-script and dormancy signals."
          }
        }
      }
    },
    "required": []
  },
  "outputSchema": {
    "type": "object",
    "description": "For POST /v1/scan, a JSON object with a `findings` array — each dependency's verdict (malicious, vulnerable, suspicious, clean), a summary, and a data_as_of timestamp. Findings vary by each supplier's snapshot freshness and converge as mirrors sync. The exact shape is the service's own and is not pinned here; errors return a JSON object with an `error` field, and the GET routes return their own small JSON documents."
  },
  "methods": {
    "GET /healthz": "read",
    "GET /v1/capabilities": "read",
    "GET /v1/openapi.json": "read",
    "GET /v1/version": "read",
    "POST /v1/scan": "read"
  },
  "firstParty": true,
  "networks": [
    "eip155:8453"
  ],
  "serving": true,
  "page": "https://agent.pocket.network/services/taint-check",
  "descriptor": "https://agent.pocket.network/services/taint-check/descriptor.json"
}