Browse operation contracts · Static machine index · OpenAPI release reference · Build manifest

Review supplied dependency and release metadata

Inspect package identifiers, lockfiles, dependency choices and release or container text using caller-supplied evidence.

How to choose

Choose the operation matching the supplied manifest or metadata format. Version selection uses declared candidates; risk flags reflect explicit evidence rather than a live vulnerability database.

No package installation, registry lookup, CVE scan, image execution or legal license determination.

7 operation contracts

Package URL Inspect

Parse a bounded Package URL and normalize generic syntax: type/qualifier case, percent encoding, qualifier order. Preserves name/version case; no ecosystem rules or registry validation. Strict subset rejects empty/dot path segments, whitespace, raw reserved characters, malformed UTF-8, and duplicate qualifiers.

Choose for: Extract package type, namespace, version, qualifiers, and subpath without network access Normalize percent escapes and qualifier ordering inside the advertised subset

Outside this profile: Full ECMA-427 or ecosystem-specific PURL validation/canonicalization Registry existence checks or fetching package artifacts

Proposed nominal USD 0.003 per successful call, excluding payer wallet/network fees. Protocol definitions: x402, mpp. Static exact contract

SBOM Inventory

Extract names, versions, PURLs, declared licenses and hashes from CycloneDX JSON 1.5/1.6 or SPDX JSON 2.3. Includes nested CycloneDX components and metadata.component; excludes services, external BOMs, relationships and unconsumed fields. No full document, license, PURL or hash validation.

Choose for: Build a small auditable component inventory from caller-supplied SBOM JSON Retain source JSON pointers and distinguish declared/concluded license fields

Outside this profile: Full SBOM conformance checks, dependency resolution or vulnerability scanning XML/tag-value inputs, external document traversal or artifact verification

Proposed nominal USD 0.005 per successful call, excluding payer wallet/network fees. Protocol definitions: x402, mpp. Static exact contract

SBOM Diff

Compare two supported SBOMs by unique exact group/name (default) or versionless generic-PURL identity. Report added/removed components and version/license/hash/PURL/type changes. Duplicate identities are rejected rather than cross-paired. Reference IDs and source positions are ignored; license comparison is textual, not semantic.

Choose for: Review deterministic component changes between two caller-supplied SBOMs Reject ambiguous duplicates instead of inventing version matches

Outside this profile: License equivalence, transitive graph impact or vulnerability analysis Inventing matches across renamed packages, ecosystems or duplicate identities

Proposed nominal USD 0.01 per successful call, excluding payer wallet/network fees. Protocol definitions: x402, mpp. Static exact contract

Lockfile Inventory

Extract npm package-lock v2/v3 packages by sorted location, retaining versions, resolved sources, integrity/license strings and dev/optional/devOptional/link/install-script flags. No package installation, graph resolution or hash verification. Workspace names require a declared name; node_modules names can be inferred from location.

Choose for: Read package locations and declared metadata without installing anything Retain nested copies and workspace links as separate locations

Outside this profile: npm v1, Yarn, pnpm, Poetry or Cargo lockfiles Transitive dependency graph resolution, artifact retrieval or installation verification

Proposed nominal USD 0.005 per successful call, excluding payer wallet/network fees. Protocol definitions: x402, mpp. Static exact contract

Dependency Metadata Flags

Flag declared npm-style metadata gaps: missing/non-exact canonical SemVer pins, missing/insecure/local/unrecognized sources, missing/malformed or SHA1-only integrity, and missing license markers. Syntax/presence heuristics only; no vulnerability database, artifact verification, trust score or legal conclusion.

Choose for: Triage a bounded declared dependency list before human policy review Find missing pins, source declarations, integrity strings and license metadata

Outside this profile: Vulnerability or malware scanning, security certification, license compatibility decisions Treating absent flags as evidence a dependency is safe or authentic

Proposed nominal USD 0.005 per successful call, excluding payer wallet/network fees. Protocol definitions: x402, mpp. Static exact contract

SPDX Expression Analyze

Parse bounded SPDX-style license expression syntax into a flat indexed AST, unique identifiers/exceptions and fully parenthesized normalization. Supports AND/OR/WITH, +, LicenseRef and DocumentRef; enforces precedence and simple-left WITH. Does not validate current license/exception lists or give compliance advice; NONE/NOASSERTION document markers are rejected.

Choose for: Inspect operator precedence and identifier references in a supplied expression Perform bounded syntax preparation before a separate policy or license-list check

Outside this profile: Proving identifiers are in the current SPDX list License compatibility, legal advice or boolean expansion of all license choices

Proposed nominal USD 0.003 per successful call, excluding payer wallet/network fees. Protocol definitions: x402, mpp. Static exact contract

Bounded Dockerfile static audit

Inspect one supplied Dockerfile for 14 bounded static risk and hygiene signals with line ranges, rule IDs, redacted evidence and remediation. Understands continuations, escape directives, literal stage inheritance and JSON forms. No execution, image/CVE scan, fetch, variable evaluation or safe-image verdict; heredocs, ONBUILD and custom frontends are rejected.

Choose for: Get bounded static observations about one supplied Dockerfile's literal image references, stage/user configuration, COPY/ADD sources, secret-like names and instruction forms.

Outside this profile: Build or execute a Dockerfile, inspect an image or registry, find CVEs, certify security, analyze Compose/Kubernetes, evaluate shell commands or ARG values, or parse heredocs, ONBUILD or custom syntax frontends.

Proposed nominal USD 0.003 per successful call, excluding payer wallet/network fees. Protocol definitions: x402, mpp. Static exact contract