{"slug":"agent-pocket-network-v1-taint-check-9fa3f0","title":"Scan a dependency manifest for known-vulnerable and confirmed-malicious packages","host":"agent.pocket.network","method":"POST","resource":"https://agent.pocket.network/v1/taint-check","category":"other","description":"Scan a dependency manifest for known-vulnerable and confirmed-malicious packages. POST /v1/scan with a raw lockfile or a components array and get per-dependency verdicts (malicious, vulnerable, suspicious, clean) from OSV.dev and the OpenSSF Malicious Packages feed, each with a summary and snapshot ","price_listed":0.005,"price_asked":0.005,"state":"answering","state_label":"Answering","checks_7d":1,"answered_7d":1,"latency_ms_median":1006,"reported_calls_30d":7,"reported_payers_30d":3,"networks":["eip155:8453"],"badge":"unverified","paid_checks_7d":0,"paid_ok_7d":0,"example_input":{"body":{"components":[{"ecosystem":"npm","name":"minimist","version":"1.2.0"}],"options":{"heuristics":false}},"bodyType":"json","method":"POST","type":"http"},"output_schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"body":{"description":"Provide either a raw lockfile or a pre-parsed components array; body size and component limits come from GET /v1/capabilities.","properties":{"components":{"description":"Pre-parsed dependencies.","items":{"properties":{"ecosystem":{"description":"e.g. npm, pypi, go, cargo.","type":"string"},"name":{"description":"Package name.","type":"string"},"version":{"description":"Package version.","type":"string"}},"type":"object"},"type":"array"},"lockfile":{"description":"A raw lockfile.","properties":{"content":{"description":"Raw lockfile content.","type":"string"},"format":{"description":"Lockfile format.","enum":["package-lock.json","pnpm-lock.yaml","yarn.lock","requirements.txt","poetry.lock","uv.lock","Pipfile.lock","Cargo.lock","go.sum"],"type":"string"}},"type":"object"},"options":{"description":"Scan options.","properties":{"heuristics":{"description":"Add typosquat, install-script and dormancy signals.","type":"boolean"},"since":{"description":"Only advisories newer than this timestamp (monitor mode).","type":"string"}},"type":"object"}},"required":[],"type":"object"},"bodyType":{"enum":["json","form-data","text"],"type":"string"},"method":{"enum":["POST","PUT","PATCH"],"type":"string"},"type":{"const":"http","type":"string"}},"required":["type","method","bodyType","body"],"type":"object"},"output":{"properties":{"example":{"properties":{"data":{"description":"For POST /v1/scan, a JSON object with a `findings` array — each dependency's verdict (malicious, vulnerable, suspicious, clean), a summary, and a data_as_of timestamp. Findings vary by each supplier's snapshot freshness and converge as mirrors sync. The exact shape is the service's own and is not pinned here; errors return a JSON object with an `error` field, and the GET routes return their own small JSON documents.","type":"object"},"portal":{"properties":{"provenance":{"const":"third-party-supplier"},"schemaCheck":{"enum":["passed","undeclared","unchecked"]},"serviceId":{"const":"taint-check"}},"required":["provenance","serviceId","schemaCheck"],"type":"object"}},"required":["portal","data"],"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"},"history":[{"day":"2026-09-24","reachable":true,"status":402,"valid_402":true,"asked_usdc":0.005,"price_match":true,"latency_ms":1006,"error":null}],"description_full":"Scan a dependency manifest for known-vulnerable and confirmed-malicious packages. POST /v1/scan with a raw lockfile or a components array and get per-dependency verdicts (malicious, vulnerable, suspicious, clean) from OSV.dev and the OpenSSF Malicious Packages feed, each with a summary and snapshot timestamp. Pay per request in USDC; no account, no API key.","last_updated":"2026-09-24T04:30:26.43Z","schemes":["exact"]}