{"slug":"api-agentstools-dev-cve-scan-d24665","title":"Vulnerability scan for a software package by ecosystem, name and version, or by ","host":"api.agentstools.dev","method":"GET","resource":"https://api.agentstools.dev/cve/scan","category":"code","description":"Vulnerability scan for a software package by ecosystem, name and version, or by package-URL (purl). Queries OSV.dev for known advisories, collects their CVE ids and enriches them with NVD CVSS, CISA KEV and EPSS, then returns a prioritized list of advisories with exact fixed versions. Risk indicator","price_listed":0.02,"price_asked":0.02,"state":"answering","state_label":"Answering","checks_7d":1,"answered_7d":1,"latency_ms_median":1010,"reported_calls_30d":1,"reported_payers_30d":1,"networks":["eip155:8453"],"badge":"unverified","paid_checks_7d":0,"paid_ok_7d":0,"example_input":{"method":"GET","queryParams":{"ecosystem":"PyPI","name":"jinja2","version":"2.4.1"},"type":"http"},"output_schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"method":{"enum":["GET","HEAD","DELETE"],"type":"string"},"queryParams":{"properties":{"ecosystem":{"description":"Package ecosystem","enum":["npm","PyPI","Maven","crates.io","Go","Packagist","RubyGems","NuGet"],"type":"string"},"name":{"description":"Package name (Maven uses group:artifact)","type":"string"},"purl":{"description":"Package-URL instead of ecosystem/name/version, e.g. pkg:pypi/jinja2@2.4.1","type":"string"},"version":{"description":"Package version, e.g. 2.4.1","type":"string"}},"required":[],"type":"object"},"type":{"const":"http","type":"string"}},"required":["type","method"],"type":"object"},"output":{"properties":{"example":{"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"},"history":[{"day":"2026-09-24","reachable":true,"status":402,"valid_402":true,"asked_usdc":0.02,"price_match":true,"latency_ms":1010,"error":null}],"description_full":"Vulnerability scan for a software package by ecosystem, name and version, or by package-URL (purl). Queries OSV.dev for known advisories, collects their CVE ids and enriches them with NVD CVSS, CISA KEV and EPSS, then returns a prioritized list of advisories with exact fixed versions. Risk indicators, not advice.","last_updated":"2026-09-19T15:58:51.482Z","schemes":["exact"]}