Skip to content
onelayer.
All tools

Tool detail

Pocket Network

Scans a dependency lockfile or parsed component list and returns per-dependency malicious/vulnerable/suspicious/clean verdicts from OSV.dev and OpenSSF.

Categories: Security

Use when

  • scan a package-lock.json or requirements.txt for malicious dependencies
  • check a list of package name/version pairs for known vulnerabilities

Not for

  • not a build-time SCA tool — one-shot scan, no CI integration built in

Inputs

POST JSON body, all optional: components[] (ecosystem/name/version) or lockfile {content, format enum}; options.heuristics

Admitted input schema

{
  "type": "object",
  "properties": {
    "components": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "ecosystem": {
            "type": "string",
            "minLength": 0,
            "maxLength": 4096,
            "description": "e.g. npm, pypi, go, cargo."
          },
          "name": {
            "type": "string",
            "minLength": 0,
            "maxLength": 4096,
            "description": "Package name."
          },
          "version": {
            "type": "string",
            "minLength": 0,
            "maxLength": 4096,
            "description": "Package version."
          }
        },
        "required": [],
        "additionalProperties": false
      },
      "minItems": 0,
      "maxItems": 100,
      "description": "Pre-parsed dependencies."
    },
    "lockfile": {
      "type": "object",
      "properties": {
        "content": {
          "type": "string",
          "minLength": 0,
          "maxLength": 4096,
          "description": "Raw lockfile content."
        },
        "format": {
          "type": "string",
          "minLength": 0,
          "maxLength": 4096,
          "enum": [
            "package-lock.json",
            "pnpm-lock.yaml",
            "yarn.lock",
            "requirements.txt",
            "poetry.lock",
            "uv.lock",
            "Pipfile.lock",
            "Cargo.lock",
            "go.sum"
          ],
          "description": "Lockfile format."
        }
      },
      "required": [],
      "additionalProperties": false,
      "description": "A raw lockfile."
    },
    "options": {
      "type": "object",
      "properties": {
        "heuristics": {
          "type": "boolean",
          "description": "Add typosquat, install-script and dormancy signals."
        },
        "since": {
          "type": "string",
          "minLength": 0,
          "maxLength": 4096,
          "description": "Only advisories newer than this timestamp (monitor mode)."
        }
      },
      "required": [],
      "additionalProperties": false,
      "description": "Scan options."
    }
  },
  "required": [],
  "additionalProperties": false,
  "description": "Provide either a raw lockfile or a pre-parsed components array; body size and component limits come from GET /v1/capabilities."
}

Endpoint

Method
POST
URL
https://agent.pocket.network/v1/taint-check

Payment

Protocol
x402
Listed price
0.005 USDC per call on Base
Payment method
exact
Network
eip155:8453
Asset
0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913

Listed terms are catalog metadata. The caller supplies inputs and calls the tool outside Onelayer. If payment is required, the caller uses a compatible wallet to pay.

Source

Record
POST https://agent.pocket.network/v1/taint-check
Retrieved
2026-09-30T20:37:07.382Z
Catalog file SHA-256
6837ccddf886f0007cf3727ea9d27faaa5047b51b4f425345c554ce1c271a524
Catalog built
2026-09-30T22:31:58.034Z