Skip to content
clusters: prooflayer · edgemarket · edgefinance · synthforge · mediakit · wordmint · webprobe · locale · comppoint
$ man pypi-package-risk

/pypi-package-risk(1)

agentutility / prooflayer / pypi-package-risk
PRICE / CALL
$0.01
USDC · base mainnet · scheme: exact
METHOD
POST
CLUSTER
prooflayer
CATEGORY
ai
STATUS
live
NAME
pypi-package-risk pypi package risk score / python supply-chain scanner
SYNOPSIS
POST https://x402.org/v1/pypi-package-risk
     Content-Type: application/json
     X-PAYMENT:    <signed-transferWithAuthorization>

     { ... }
↳ first call → 402 Payment Required. Sign USDCtransferWithAuthorization, retry with theX-PAYMENT header.
DESCRIPTION

PyPI package risk score / Python supply-chain scanner. Age, monthly downloads, install-script hooks (cmdclass/setup.py), dependency depth, deprecation, typosquat distance to 50 popular Python packages. Plus LLM risk summary.

INPUTrequest schema
propertytypedescriptionreq?
package_namestringPyPI package distribution name (e.g. 'requests', 'django'). Case-insensitive; resolved via pypi.org/pypi/{name}/json.required
versionstringOptional specific version (e.g. '2.31.0'). Default: latest stable release.optional
OUTPUTresponse shape
fieldtypedescription
package_namestringPyPI package name that was scanned.
versionstringPackage version evaluated for the risk score, usually the latest release on PyPI.
scorenumberOverall risk score from 0 (safe) to 100 (high risk) combining all supply-chain signals.
risk_levelstringCategorical risk bucket like low, medium, high, or critical derived from the score.
summarystringLLM-written plain-English risk summary covering the main red flags found in the package.
signalsobjectPer-check signals: age, monthly downloads, install-script hooks, dep depth, deprecation, typosquat distance.
metadataobjectPyPI metadata snapshot: author, upload date, homepage, license, project URLs, and release count.
EXAMPLEStwo ways to call
EXAMPLE 1 · curl
curl -X POST https://x402.org/v1/pypi-package-risk \
  -H 'Content-Type: application/json' \
  -d '{ }'
first response = 402 Payment Required with payment requirements; sign + retry with X-PAYMENT.
EXAMPLE 2 · mcp
# install once
claude mcp add x402 --command "npx x402-deployer-mcp"

# then ask Claude Code:
# "use the pypi-package-risk tool to ..."
MCP server handles payment automatically — your coding agent just calls the tool by name.
METADATA
tags
pypipythonsupply-chainsecurityrisk
env
VENICE_API_KEY
methods
POST
cluster
prooflayer
price
$0.01 USDC per call
ADJACENTother endpoints in prooflayer
endpointdescriptionprice
cveCVE lookup / vulnerability database.$0.005
cve-lookupCVE lookup / vulnerability database.$0.005
db-migration-riskDB migration risk audit / SQL migration safety check / DROP COLUMN detector / unsafe ALTER TABLE detector / Postgres CREATE INDEX CONCURR…$0.02
deploy-config-riskdeploy config audit / Dockerfile lint / vercel.json hardening / wrangler.toml review / docker-compose.yml safety / fly.toml secrets check…$0.02
secrets-exposure-checksecrets exposure scan / hardcoded API key detector / .env-committed-key audit / Next.js client env leak detector / pre-deploy secret gate.$0.02
ai-content-detectorAI content detector / GPT detector / ChatGPT plagiarism checker.$0.03
dep-risk-summaryrepo dependency risk audit / package.json + lockfile vetter / unpinned dep detector / transitive dep counter / requirements.txt audit / p…$0.03
github-repo-healthGitHub repo health score / open-source maintainability checker.$0.03
SEE ALSO
agentutility(7) · prooflayer(7) · x402(7) · mcp(7) · llms.txt · registry.json · bazaar.x402.org