lockfile-guardian � package-lock.json auditPOST /pro/audit · x402 API by Baneado98
Audit a package-lock.json for integrity mismatch (lockfile poisoning), hidden install scripts and fresh-version risk BEFORE npm install. For AI coding agents.
What does this x402 API do?
lockfile-guardian � package-lock.json audit. This is an x402-gated POST API resource from Baneado98. TOLL·402 did not invoke this route automatically because doing so was not considered safe. The listing records $0.02 USD-denominated per request on Base. No settled paid call has been verified.
- Published price
- $0.02 USD-denominated per request
- Networks
- Base
- Latest evidence
- TOLL·402 did not invoke this route automatically because doing so was not considered safe
- Resource ID
- 9a46f2a3cb191aed2ba57864
Start with a quote-only recipe. Payment signing stays in your project.
const response = await fetch("https://lockfile-guardian.vercel.app/pro/audit", {
method: "POST",
headers: { "content-type": "application/json" },
body: JSON.stringify({
"replace": "with provider-approved input"
}),
});
console.log(response.status);
console.log(Object.fromEntries(response.headers));
console.log((await response.text()).slice(0, 1000));
// A valid 402 is a quote, not a completed paid call.Review the provider input schema before running this non-read-only method. No payment code is included.
- Exact route checked
not safely testable · potentially-mutating-method:POST
- Origin reachable
HEAD https://lockfile-guardian.vercel.app/ returned 404.
- Observed in 402-index
Discovered through self-registered.
- Registry record checked
Registry health: degraded.
What evidence supports this listing?
Each record has an exact-route quote outcome. Unresolved templates and potentially mutating methods are labeled instead of being invoked without provider-specific test input. A quote is still separate from a settled paid call. Read the discovery and verification methodology →
Which networks and payment options does it accept?
The normalized listing price is $0.02 USD-denominated per request. Raw protocol requirements remain visible below for implementation and audit use.