x402 census · toolcall.click · ff0fbda5f6a5 · JSON
GET /t/package/check
unprobed
Is this dependency safe to use? Pass a package name (npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet) and optional version: returns known vulnerabilities (OSV/CVE with CVSS and fixed-in version), deprecation status, license, latest version, repo health (stars, OpenSSF Scorecard) and an overall ok/caution/avoid verdict. JSON response. $0.01 USDC per call, pay via x402, no API key.
Verdict: not verified by an unpaid GET. not probed yet. This says nothing about whether the route works when called as declared.
Facts from the catalogs
| Field | Value |
|---|---|
| URL | https://toolcall.click/t/package/check |
| Method | GET |
| Price | $0.01 USDC = 10000 atomic units of 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 |
| Network | eip155:8453 (base) |
| payTo | 0x84FA7Ea8303d4f503267e2e998A3F7D980e814a5 |
| Seller | toolcall.click |
| Catalogs | cdp (row updated 2026-09-29) |
| Listed since (lower bound) | 2026-09-29 (earliest catalog timestamp; catalogs report last-update times only) |
| Last catalog update | 2026-09-29 |
| CDP quality counters | 2 calls and 2 unique payers in 30 days, last call 2026-09-29 (catalog-reported, not verified on chain) |
| Category (keyword rule) | trading-signals |
| Templated path | no |
| x402Version in catalog | 2 |
| Service name / tags | Toolsmith · dependency security, npm, pypi, cve, vulnerabilities |
Unpaid probe (census of )
| Field | Value |
|---|---|
| Probe | not probed in this build |
No hourly re-probe has reached this resource yet; the cron covers a rotating slice of 150 per hour.
On-chain facts for the payTo (public address)
| Field | Value |
|---|---|
| Distinct payers | 10 |
| Payments | 21 |
| USDC volume | $0.13 |
| Median payment | $0.002 |
| First / last payment | 2026-07-26 / 2026-09-28 |
| Sampler-shaped share of payments | 100.0% |
| Payers that are not samplers | 0 |
| Source | forensics-2026-09-30 |
| Address | 0x84FA7Ea8303d4f503267e2e998A3F7D980e814a5 |
Declared input and output (extensions.bazaar)
{
"input": {
"method": "GET",
"queryParams": {
"eco": "npm",
"name": "express",
"version": "4.16.0"
},
"type": "http"
},
"output": {
"type": "json",
"example": {
"latestVersion": "5.2.1",
"package": "express",
"project": {
"scorecard": 6.8,
"stars": 65000
},
"verdict": "caution",
"version": "4.16.0",
"vulnerabilities": [
{
"cve": "CVE-2024-...",
"cvss": 6.1,
"fixedIn": "4.19.2",
"id": "GHSA-..."
}
]
}
}
}
Try it (unpaid: shows the 402)
curl -si -X GET 'https://toolcall.click/t/package/check' -H 'accept: application/json'
The catalog declares GET. A 402 answer carries the payment requirements in the JSON body and, for x402 v2, base64 in the PAYMENT-REQUIRED header. This page never sends a payment.
Paid checks (x402, USDC on Base)
GET https://bazaar.agentexchange.work/r/ff0fbda5f6a5/probe.json re-runs this probe right now for $0.01 and writes the result here. POST https://bazaar.agentexchange.work/featured with {"id":"ff0fbda5f6a5"} places this resource at the top of the report and search pages for 30 days for $1.00, labelled. Unpaid requests answer 402 with the terms. Pricing.
Catalog references: agentic.market (CDP Bazaar front end) · this record as JSON · all resources on toolcall.click.