Skip to content
Eden Engine

npm Package Vulnerability Lookup (by Version)

omnial/npm-package-vulnerability-lookup

Given an npm package name and an exact version, lists the known security advisories that affect that version: for each, the advisory id, its alias ids (CVE and GHSA), a one-line summary, a severity label, the version that fixes it, the publish and last-modified times, and a few reference links. Also returns the advisory count and the highest severity found. The same or a related issue can be listed more than once under different ids; the aliases show the overlap.

activeper callv1
Provider
Web & Business Data Network
Category
developer-tools
Provider price
$0.081081 per call
Latency p50 / p95
— / —
Success rate
—
Verified
—

Provider list price; Omnial MCP charges provider cost plus a platform markup on top.

Contract

input_schema.json
{
  "type": "object",
  "required": [
    "ecosystem",
    "package_name",
    "version"
  ],
  "properties": {
    "version": {
      "type": "string",
      "minLength": 1,
      "description": "The exact package version to check, such as 1.2.3."
    },
    "ecosystem": {
      "enum": [
        "npm"
      ],
      "type": "string",
      "description": "The package registry. Only npm is offered."
    },
    "package_name": {
      "type": "string",
      "minLength": 1,
      "description": "The package's name as published on the npm registry."
    }
  },
  "additionalProperties": false
}
output_schema.json
{
  "type": "object",
  "properties": {
    "version": {
      "type": "string",
      "description": "The version that was checked."
    },
    "ecosystem": {
      "type": "string",
      "description": "The package registry."
    },
    "package_name": {
      "type": "string",
      "description": "The package that was checked."
    },
    "vulnerabilities": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "description": "The advisory id."
          },
          "aliases": {
            "type": "array",
            "items": {
              "type": "string"
            },
            "description": "Other ids for the same issue (CVE and GHSA ids)."
          },
          "summary": {
            "type": "string",
            "description": "A one-line summary of the issue."
          },
          "fixed_in": {
            "type": "string",
            "description": "The version that fixes the issue."
          },
          "modified": {
            "type": "string",
            "description": "When the advisory was last modified (ISO 8601)."
          },
          "severity": {
            "type": "string",
            "description": "The severity label, such as high or moderate."
          },
          "published": {
            "type": "string",
            "description": "When the advisory was published (ISO 8601)."
          },
          "references": {
            "type": "array",
            "items": {
              "type": "string"
            },
            "description": "A few reference links for the advisory, not a complete list."
          }
        }
      },
      "description": "One entry per advisory that affects the version."
    },
    "highest_severity": {
      "type": "string",
      "description": "The highest severity label among the listed advisories."
    },
    "total_vulnerabilities": {
      "type": "number",
      "description": "How many advisories are listed, counting overlapping entries separately."
    }
  },
  "description": "The advisories affecting the given package version, as returned after shaping."
}

Pricing

Every real charge, itemised. A model that quietly omits one is a slow financial leak, so nothing here is rolled up, and a charge that only applies to some inputs says so rather than being added in.

Prices in this catalog are the provider's own list price, not your bill: Omnial MCP charges provider cost plus a platform markup on top, so what you are charged is higher than the figure shown. For the exact amount a specific call will cost, run omnial_execute with dry_run: true; that number includes the markup and is what we hold while the call runs. It is a quote, not a cap on the charge.

ChargeRate
Per call
Flat, regardless of what comes back
$0.081081
Cost basis
Not recorded

This tool's catalog entry does not record how its final bill is determined, so we will not tell you whether its cost is fixed before the call or reported by the provider afterwards. Either way what is held is a quote rather than a cap: you are charged what the call actually costs, bounded at 2x the quote.

Updated
Oct 11, 2026