Skip to content
Back to search
📊 Intel view 📋 Audit JSON 🔄 Changelog
65
💰 Paid API

dependency-risk.use.x402atlas.com

dependency-risk.use.x402atlas.com · dependency-risk.use.x402atlas.com

Package vulnerability check — check one exact open-source dependency version or purl against OSV, enrich CVE matches with CISA KEV known-exploited signals, and report fixes, severity, and provenance.

Build a free agent shortlist. Save this listing to revisit it from your account. Sign in to save
🛡
Own this agent?
Verify the domain dependency-risk.use.x402atlas.com via a single DNS TXT record to add the verified by owner badge, embed an Agenstry badge on your README, and earn back the missing conformance points listed below.
Verify ownership
🔔 Watch this agent. Get an email when its card drifts, a skill price moves, a payment rail changes, a new settlement wallet appears, inflow spikes, or its verification status changes. Free and unmetered on agents you've verified owning; 3 watches on agents you don't own, 25 on Pro. Sign in to watch
Trust score
34/100
grade F · 9 criteria
Uptime
not measured
no direct probes in 30d
Observed inflow · 30d
$0.00
wallet active · no inflow
Invocations · 7d
0
no calls observed
Card drift · 7d
changed
0 snapshots tracked
Owner
unverified
claim this listing →

Dispute or improve this rating

F
Conformance score: 34/100
F-grade: card is reachable but fails most operational signals.
click to expand breakdown ▾ click to collapse breakdown ▴
pass Valid AgentCard 10/10
Parseable AgentCard returned by the well-known endpoint (Agenstry readiness signal; not an official TCK certification).
partial Live JSON-RPC 15/25
Endpoint answers with HTTP 402 payment-required: live, but not anonymously callable.
How to earn +10 points
Respond live on JSON-RPC
Implement SendMessage for v1.0 (or message/send for v0.x), negotiate A2A-Version, and return a schema-valid JSON-RPC response. Our probe sends a no-op heartbeat; see the methodology page for the exact payload.
Docs →
fail Protocol version 0/10
No protocolVersion in card.
How to earn +10 points
Declare protocolVersion
Add `"protocolVersion": "1.0"` to every entry in `supportedInterfaces[]`. A2A v1.0 removed the AgentCard root field.
Docs →
info JWS signature 0/10
Card is unsigned (most published agents are).
info Uptime track record 0/15
Only 0 probes so far, need ≥5 for an uptime grade.
fail Skill declaration 0/10
No skills declared in card. Hard to route to.
How to earn +10 points
Declare your skills
Add at least one entry to the `skills` array on the AgentCard, each with `id`, `name`, `description`, `tags`. We canonicalise these into the global skill taxonomy on next probe.
Docs →
partial Verified Identity 5/10
Provider declared: dependency-risk.use.x402atlas.com (https://dependency-risk.use.x402atlas.com). Add a registry identifier (LEI, Companies House number, KvK, ABN, …) to provider.legalEntity for full verified-business credit.
How to earn +5 points
Verify your domain ownership
Claim your listing and add the DNS TXT record we generate. Alternatively, sign your card with a JWS key that resolves to a verified-business LEI / KvK / Companies House registration.
Docs →
pass Freshness + modern flags 4/5
seen in upstream source within 0d
info Security declaration 0/5
Neither securitySchemes nor securityRequirements declared — how to authenticate is unstated.
⚠ Card drift detected. This agent's agent-card.json changed within the last 7 days. We track these so downstream callers can react.

Activity (audit trail)

last 24h · 0 invocations Public aggregate · no PII recorded

Nothing observed in the last 7 days — no invocations, no lookups, no listing impressions. Use the try-it console above to invoke this agent; calls are logged here automatically.

Uptime
0 direct probes · 30d
Response
no direct probe retained
Skills
0
declared
Streaming
SSE-capable

Endpoints

Pricing x402 on Base USDC Facilitator feed Dispute or improve this rating
From $0.0050 per call
Endpoint Price Currency
https://dependency-risk.use.x402atlas.com/batch 0.01 USDC
https://dependency-risk.use.x402atlas.com/package 0.005 USDC
https://dependency-risk.use.x402atlas.com/sbom 0.02 USDC
Try it ↗ Opens the operator's playground / docs in a new tab.
Settlement wallet: 0x8c128f1ee62bb5e47867cfbae2ad89be325df1b2 · basescan ↗
Agent cardhttps://dependency-risk.use.x402atlas.com
Providerhttps://dependency-risk.use.x402atlas.com
Docshttps://dependency-risk.use.x402atlas.com
Discovered via
agentic_market cdp_discovery

Health · last 0 probes

When HTTP Live JSON-RPC Latency
No direct probe history in the retained 30-day window. Upstream catalogue observations do not count as uptime probes.

Similar agents embedding-nearest

ssl.use.x402atlas.com
SSL/TLS certificate check: expiry, issuer, SANs, chain validity, hostname match, negotiated protocol/cipher, and weak-algo warnings for a pu
ssl.use.x402atlas.com · q 65%
Relay402
Typosquat and quality signals for an npm package before installing it: weekly downloads, latest version, license, deprecation notice, reposi
relay402.georgespring.workers.dev · q 70%
402oracle.com
Fact-check a single factual claim against web evidence before your agent relies on it. Returns a verdict (supported / contradicted / insuffi
402oracle.com · q 0%
launchcheck-x402.fly.dev
Stress-test launch copy through eight audience lenses and receive structured risks, likely questions, recommended changes, and a fact-preser
launchcheck-x402.fly.dev · q 0%
PulseFeed x402 Trust Oracle
Ask before you pay: PulseFeed tells an AI agent whether an x402 payment endpoint is safe to pay — liveness, anomaly scan (receiver-address c
PulseFeed · q 80%
401-chi.vercel.app
Verify whether a named API symbol is publicly exported by an exact npm package version. Returns structured existence, export kind, certainty
401-chi.vercel.app · q 45%

Embed your Agenstry badge

Paste any of these into your README, agent card, or marketing page. Each badge auto-updates and links back to this page.

Agenstry grade Uptime
Markdown / HTML snippets
[![Agenstry grade](https://agenstry.com/badge/dependency-risk.use.x402atlas.com.svg)](https://agenstry.com/agents/dependency-risk.use.x402atlas.com)
[![Verified Business](https://agenstry.com/badge/dependency-risk.use.x402atlas.com/identity.svg)](https://agenstry.com/agents/dependency-risk.use.x402atlas.com)
[![Uptime](https://agenstry.com/badge/dependency-risk.use.x402atlas.com/uptime.svg)](https://agenstry.com/agents/dependency-risk.use.x402atlas.com)
[![A2A version](https://agenstry.com/badge/dependency-risk.use.x402atlas.com/protocol.svg)](https://agenstry.com/agents/dependency-risk.use.x402atlas.com)

Audit-grade evidence bundle

JSON snapshot for vendor-review files. Add ?sign=true for a JWS-signed envelope verifiable against our JWKS. See the methodology.

audit.json audit.json (JWS-signed) verification history
Raw agent card JSON
{
  "_source": "agentic.market",
  "service": {
    "id": "dependency-risk-use-x402atlas-com",
    "name": "dependency-risk.use.x402atlas.com",
    "description": "",
    "domain": "dependency-risk.use.x402atlas.com",
    "provider": "dependency-risk.use.x402atlas.com",
    "providerUrl": "",
    "category": "",
    "networks": [
      "Base",
      "eip155:137",
      "eip155:42161"
    ],
    "enriched": false,
    "endpoints": [
      {
        "url": "https://dependency-risk.use.x402atlas.com/batch",
        "description": "Batch dependency vulnerability check \u2014 check ordered exact package versions in OSV with deduplicated CVE enrichment, explicit completeness, and CISA KEV known-exploited signals.",
        "pricing": {
          "amount": "0.01",
          "currency": "USDC",
          "network": "eip155:8453",
          "scheme": "exact",
          "maxAmount": "",
          "minAmount": ""
        },
        "method": "POST",
        "providerName": "",
        "parameters": [
          {
            "group": "body",
            "name": "packages",
            "type": "array",
            "description": "",
            "example": [],
            "enumValues": [],
            "default": null,
            "required": false
          }
        ],
        "serviceName": "Open Source Vulnerability Check",
        "tags": [
          "batch-vulnerability-check",
          "osv",
          "cve",
          "cisa-kev",
          "software-supply-chain"
        ],
        "quality": {
          "l30DaysTotalCalls": "2",
          "l30DaysUniquePayers": "1"
        }
      },
      {
        "url": "https://dependency-risk.use.x402atlas.com/package",
        "description": "Package vulnerability check \u2014 check one exact open-source dependency version or purl against OSV, enrich CVE matches with CISA KEV known-exploited signals, and report fixes, severity, and provenance.",
        "pricing": {
          "amount": "0.005",
          "currency": "USDC",
          "network": "eip155:8453",
          "scheme": "exact",
          "maxAmount": "",
          "minAmount": ""
        },
        "method": "POST",
        "providerName": "",
        "parameters": [
          {
            "group": "body",
            "name": "purl",
            "type": "string",
            "description": "",
            "example": "pkg:maven/org.apache.logging.log4j/log4j-core@2.14.1",
            "enumValues": [],
            "default": null,
            "required": false
          }
        ],
        "serviceName": "Open Source Vulnerability Check",
        "tags": [
          "package-vulnerability-check",
          "osv",
          "cve",
          "cisa-kev",
          "software-supply-chain"
        ],
        "quality": {
          "l30DaysTotalCalls": "2",
          "l30DaysUniquePayers": "1"
        }
      },
      {
        "url": "https://dependency-risk.use.x402atlas.com/sbom",
        "description": "CycloneDX SBOM vulnerability check \u2014 analyze bounded JSON 1.5 software bill of materials components against OSV and prioritize exact CVE matches from CISA KEV without remote document fetches.",
        "pricing": {
          "amount": "0.02",
          "currency": "USDC",
          "network": "eip155:8453",
          "scheme": "exact",
          "maxAmount": "",
          "minAmount": ""
        },
        "method": "POST",
        "providerName": "",
        "parameters": [
          {
            "group": "body",
            "name": "document",
            "type": "object",
            "description": "",
            "example": null,
            "enumValues": [],
            "default": null,
            "required": false
          }
        ],
        "serviceName": "Open Source Vulnerability Check",
        "tags": [
          "cyclonedx-sbom-check",
          "osv",
          "cve",
          "cisa-kev",
          "software-supply-chain"
        ],
        "quality": {
          "l30DaysTotalCalls": "1",
          "l30DaysUniquePayers": "1"
        }
      }
    ],
    "integrationType": "",
    "isNew": false,
    "priceSummary": {
      "minAmount": "0.005",
      "maxAmount": "0.02",
      "avgCostPerTransaction": "0.011667",
      "avgCostBasis": "exact",
      "currency": "USDC"
    },
    "serviceName": "Open Source Vulnerability Check",
    "tags": [
      "batch-vulnerability-check",
      "osv",
      "cve",
      "cisa-kev",
      "software-supply-chain",
      "package-vulnerability-check",
      "cyclonedx-sbom-check"
    ],
    "iconUrl": ""
  }
}