{"name":"DepVet","description":"NPM supply chain attack and malicious package check for npm and PyPI: typosquat detection, dependency vulnerability scan (CVE/OSV), license check, OpenSSF Scorecard. OK/REVIEW/AVOID verdict before you install. No API key: pay USDC on Base per call via x402.","payment":{"protocol":"x402 v2","network":"eip155:8453","asset":"USDC","payTo":"0xbBB1338E3990a9Ab5DB36546a28cEe06cCB03D05"},"endpoints":[{"method":"POST","path":"/report {ecosystem, name, version?}","price":"$0.02","what":"Full risk report with verdict and reasons"},{"method":"POST","path":"/check {ecosystem, name, version?}","price":"$0.005","what":"Light check: vulns, license, deprecated, verdict"},{"method":"POST","path":"/batch {ecosystem, packages:[{name, version?}]}","price":"$0.05","what":"Light check of up to 20 packages (lockfile)"}],"notes":"ecosystem is 'npm' or 'pypi'. Invalid input returns 400 and unknown packages return 404 before any payment is settled. GET with query params also works (batch: packages=a@1.0,b).","howToPay":"Call any endpoint; you get HTTP 402 with payment requirements. Use an x402 client (e.g. @x402/fetch, x402-axios, or an MCP x402 wallet) to sign and retry."}