SERVICE / DETAILother

cve-scan

GET api.agentstools.dev/cve/scan

SONAR SCORE0.822
LIVE PRICE0.020000
BAZAAR LIVEcompatible
CDP INDEXEDno
DECISION EVIDENCE

Why an agent can trust this route.

19 observations in the last 24h
HANDSHAKE SUCCESS100.0%402 challenge reachable
PAID DELIVERY0.0%settlement observed
P90 LATENCY1241msrecent response window
PRICE DRIFT0.0%advertised vs observed

Sonar evidence is advisory. Paid delivery is shown as verified only when paid probes are available; otherwise route estimates use the unpaid handshake as a clearly labeled proxy.

SONAR PROBE HISTORY / 30D

Observed outcomes

JSON ↗
LIVE ENDPOINT METADATA

Vulnerability scan for a software package by ecosystem, name and version, or by package-URL (purl). Queries OSV.dev for known advisories, collects their CVE ids and enriches them with NVD CVSS, CISA KEV and EPSS, then returns a prioritized list of advisories with exact fixed versions. Risk indicators, not advice.

Resource: api.agentstools.dev/cve/scan

Network: eip155:8453 · Asset: 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 · Pay to: 0xF22e558a00D91Ee12A1F50C52186FecB8dDFf493

Payment methods: · Last validation: 2026-09-14 07:15:40.381+00

{
  "input": {
    "type": "object",
    "required": [
      "type",
      "method"
    ],
    "properties": {
      "type": {
        "type": "string",
        "const": "http"
      },
      "method": {
        "enum": [
          "GET",
          "HEAD",
          "DELETE"
        ],
        "type": "string"
      },
      "queryParams": {
        "type": "object",
        "required": [],
        "properties": {
          "name": {
            "type": "string",
            "description": "Package name (Maven uses group:artifact)"
          },
          "purl": {
            "type": "string",
            "description": "Package-URL instead of ecosystem/name/version, e.g. pkg:pypi/jinja2@2.4.1"
          },
          "version": {
            "type": "string",
            "description": "Package version, e.g. 2.4.1"
          },
          "ecosystem": {
            "enum": [
              "npm",
              "PyPI",
              "Maven",
              "crates.io",
              "Go",
              "Packagist",
              "RubyGems",
              "NuGet"
            ],
            "type": "string",
            "description": "Package ecosystem"
          }
        }
      }
    },
    "additionalProperties": false
  },
  "output": {
    "type": "object",
    "required": [
      "type"
    ],
    "properties": {
      "type": {
        "type": "string"
      },
      "example": {
        "type": "object"
      }
    }
  },
  "paymentRequirements": [
    {
      "raw": {
        "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
        "extra": {
          "name": "USD Coin",
          "version": "2"
        },
        "payTo": "0xF22e558a00D91Ee12A1F50C52186FecB8dDFf493",
        "amount": "20000",
        "scheme": "exact",
        "network": "eip155:8453",
        "maxTimeoutSeconds": 300
      },
      "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
      "payTo": "0xF22e558a00D91Ee12A1F50C52186FecB8dDFf493",
      "scheme": "exact",
      "network": "eip155:8453",
      "amountAtomic": "20000"
    }
  ]
}
METADATA PROVENANCE

Source catalog records are retained separately from live endpoint observations. Sonar score, uptime, and latency are advisory metrics. CDP indexing is not inferred from validation.