security · Listed · base · Found · 4 endpoints · Not used for Gateway
pkgpulse.letom1176.workers.dev
pkgpulse.letom1176.workers.dev
Audit an entire dependency map in one POST: every package checked for registry existence (hallucination guard), deprecation, install scripts, and staleness, wit
Not used for Gateway
Catalogued so agents know it is dead/unreachable — Gateway will not route it. Still catalogued — dead/unreachable knowledge is index value. (Degraded — catalogued (dead/unreachable known) · not used for Gateway)
Indexed from this operator's public /.well-known/x402.json. Found is not operator-owned and is not attested. Claim or opt out.
Agent Read · Cleared Index
SKIP
Skip until Cleared checks or settle mesh clear.
confidence
83%
source
signal
Index before you pay. Same payload for agents:
GET /api/cleared/agent-read?slug=cat-pkgpulse-letom1176-workers-dev
When to call
- Budget between $0.003 and $0.02 per call on published endpoints.
- Audit an entire dependency map in one POST: every package checked for registry existence (hallucination guard), deprecation, install scripts, and staleness, wit
Risks
- Found — not operator-owned; claim status unknown.
- No Cleared settlement receipt on file yet.
- Uptime not yet marked stable.
- No Gateway traffic yet — market share unproven.
Price posture
Published 4 endpoints from $0.003 to $0.02.
Category · Gateway
security · no Gateway routes yet — early / unproven on Cleared market share.
Endpoint hints
POST /api/deps-auditAudit an entire dependency map in one POST: every package checked for registry existence (hallucination guard), deprecation, install scripts, and staleness, wit
GET /api/package-health0-100 health score for any npm package with a fully disclosed, re-derivable rubric: maintenance recency, adoption + download trend, integrity flags (install scr
GET /api/typosquat-checkDetect whether an npm package name is imitating a popular one: edit distance + separator/affix/scope imitation patterns against curated popular packages, risk-g
GET /api/pickRank up to 5 alternative npm packages and get a recommendation with the score gap quantified: full disclosed-rubric health report per package, close calls flagg
Evidence (Cleared)
- → Intake degraded · not used for Gateway
- → Trust 15/100 · fail · tier listed
- → Protocol x402 · base
- → Manifest pending · schema partial
- → Found listing — indexed from public x402.json, not operator-attested.
Endpoints
pkgpulse: audit a whole package.json
$0.02POST https://pkgpulse.letom1176.workers.dev/api/deps-auditAudit an entire dependency map in one POST: every package checked for registry existence (hallucination guard), deprecation, install scripts, and staleness, with summary counts and worst offenders. Up to 40 packages. · Keywords: npm, dependencies, supply-chain, security, coding-agents · Built with @piprail/sdk
pkgpulse: npm package health score
$0.005GET https://pkgpulse.letom1176.workers.dev/api/package-health0-100 health score for any npm package with a fully disclosed, re-derivable rubric: maintenance recency, adoption + download trend, integrity flags (install scripts, deprecation, license, single-maintainer, archived repo), GitHub context. The call an AI coding agent makes before adding a dependency. · Keywords: dependencies, package-health, supply-chain, security, coding-agents · Built with @piprail/sdk
pkgpulse: npm typosquat / hallucination check
$0.003GET https://pkgpulse.letom1176.workers.dev/api/typosquat-checkDetect whether an npm package name is imitating a popular one: edit distance + separator/affix/scope imitation patterns against curated popular packages, risk-graded with the package's own registry facts. Catches hallucinated install commands and squat bait before npm install executes anything. · Keywords: typosquat, supply-chain, security, coding-agents · Built with @piprail/sdk
pkgpulse: pick between npm packages
$0.01GET https://pkgpulse.letom1176.workers.dev/api/pickRank up to 5 alternative npm packages and get a recommendation with the score gap quantified: full disclosed-rubric health report per package, close calls flagged honestly. The 'axios vs got vs undici' decision in one call. · Keywords: dependencies, comparison, coding-agents, developer-tools · Built with @piprail/sdk
Checks
pending
partial
2026-08-25T02:02:02.413Z
Intake degraded · Degraded — catalogued (dead/unreachable known) · not used for Gateway · probed 2/3 · Manifest HTTP 404. Listed anyway. | No settlement evidence found in chain signals.
Claim this listing to upgrade to Cleared attestation.
Claim listing