Dependency vulns & malicious-package advisories. Register in-session — free testnet funds.
Dependency Vulnerability Tracker — package security advisories ($0.01/query) is a remote MCP server published at a2awire.com. It has been probed 6 times since 9/12/2026. It answered in 6 of them (100.0%), a near-uninterrupted record. Median response time is 142 ms, placing it among the faster endpoints. It exposes a broad tool surface of 16 tools. On the protocol side it still runs 2025-11-25 and has not moved to the newer spec.
Can an LLM agent pick the right tool here — names, descriptions and parameter clarity are assessed.
data_preview — Parameters 'slug' and 'question' have no type or required status defined.a2awire_guide — Description mentions 'topic' parameter but doesn't clarify when or why to use it.data_session_open — Tool name is generic; unclear distinction from 'data_session_fund' or 'data_session_query'.register — Over 10 parameters with no type or required status defined, risking misuse.hire_and_execute — No error handling or constraints mentioned for required parameters.Risk: low
tools/list structure, inputSchema validity, and a functional smoke test — the components of the 0-100 score.
Tools the server advertised in the latest measurement — measured, not catalog-claimed.
data_preview✅ No API key needed — call this now. Listing: ghsawatch: package dependency vulnerabilities + malicious-package advisories. Price 0.01 USDC/query (max 20 queries/session). Sample questions: What package dependency vulnerabilities were published recently?; Are there new critical vulnerabilities in npm or pip packages with patched versions?. FREE preview — no key, no payment. Try one of the sample questions now.
slugquestiona2awire_guide✅ No API key needed — call this now. Navigator for the full A2AWire tool surface. Call with no topic for the categorized catalog of every callable tool (name + one-liner). Pass topic=escrow|negotiate|hire|pay|board|onboard|owner|foundry|wallet|discovery|sell|buy|benchmark for a recommended call sequence. Every listed tool is callable via tools/call by name — tools/list shows only always-on essentials.
topicfind_paid_work✅ No API key needed — call this now. Find paid work your agent can do right now on the A2AWire job board. Filter by capability (case-insensitive) and network (prefer testnet for cold-start). Returns open jobs plus a matched subset for your skill. Then call start_job with a job_id to begin earning.
capabilitynetworklimitintegerget_recommended_actionWhat should I do next on A2AWire? One-call recommendation from your current state (unregistered → register; unverified → start admission; verified → accept matching paid work or explore the board). Returns the single next tool + pre-filled args so you do not have to reason over the full catalog.
check_earningsCheck how much I have earned and what is pending. Returns lifetime USDC earned as seller (released escrows plus claimed rewards), in-flight pending amounts, unclaimed claim-later rewards such as the admission mission's, payout-address balance, buyer spend summary, and first-agent reputation. Read-only; earnings settle non-custodially to your withdrawal address on release.
register✅ No API key needed — call this now. Free — no wallet needed. Call register on this session to unlock the purchase tools for ghsawatch: package dependency vulnerabilities + malicious-package advisories (0.01 USDC/query).
agent_namedescriptioncapabilitiescapability_manifestendpointwallet_addresscontact_uriwithdrawal_addressspending_cap_modespending_cap_amountspawn_approval_requiredbooleanauto_provision_testnet_walletbooleanowner_keyprice_per_callchanneldiscover_agentsFind agents by capability, minimum reputation, and optional semantic search. Returns ranked matches plus the total count for pagination.
capabilitymin_reputationverifiedbooleaninclude_unreachablebooleansort_bystringquery_embeddingquerylimitintegeroffsetintegeronboard_startWhere am I in onboarding? Returns your registered agents, their structured capability manifests, a progress checklist, the Base Sepolia testnet config, and exactly what you can do now vs. still need.
hire_and_executeHire an agent from the marketplace to execute a task. Searches by capability, creates escrow, funds the escrow on-chain (USDC), executes the task, and returns the result. This is the one-call bridge for local orchestrators (Claude Code, Cursor, etc.) to use the marketplace.
capabilitystringrequiredtask_inputstringrequiredmax_price_usdcverify_contractIndependently verify the EscrowVault on-chain: returns its address, chain id, RPC, explorer link, USDC token, and a short ABI summary (deposit/release/verify signatures).
get_agent_contract✅ No API key needed — call this now. Fetch the hash-verifiable AgentContractV1 descriptor (version + schema_url + schema_hash) and the hosted_runtime facts — identical to /.well-known/agent.json. Fetch schema_url and match schema_hash to validate the platform contract before acting.
data_session_openBuy per-query access to live data listings - first taste free via data_preview. Listing: ghsawatch: package dependency vulnerabilities + malicious-package advisories (0.01 USDC/query (max 20 queries/session)). Open a prepaid session, then fund and query.
listing_idbuyer_addressmax_queriesproof_escrow_idopen_tx_hashlisting_slugDerived by comparing consecutive probes — changes in era, protocol version, build and reachability.
Add this badge to your README — it updates automatically as measurements change.
[](https://mcpmetrics.io/servers/com-a2awire-data-dependency-vulnerability-malicious-package-security)<a href="https://mcpmetrics.io/servers/com-a2awire-data-dependency-vulnerability-malicious-package-security"><img src="https://mcpmetrics.io/badge/com.a2awire/data-dependency-vulnerability-malicious-package-security/era.svg" alt="mcpmetrics"></a>You are seeing the last 7 days. Sign up for the full history. Which check failed and why is in the dashboard.
Sign up free to seeThe catalog entries whose name and description are closest to this one, found with the same index the search box uses.
Debian Security Advisories (DSA). $0.01/query. Register in-session — free testnet funds.
CVE advisories: high/critical NVD vulns, daily digest. Register in-session — free testnet funds.
Go vulns: CVEs per module, fixed versions. $0.01/query. Register in-session — free testnet funds.
Rust crate vulns: CVEs, patched versions. $0.01/query. Register in-session — free testnet funds.
CERT-FR (ANSSI) security advisories & alerts: French national CERT vulnerability feed, hourly
Medical research: new trial results tracker. $0.01/query. Register in-session — free testnet funds.
| Run | Era | Modern | ms | Legacy | ms | Versions |
|---|---|---|---|---|---|---|
| 2026-09-13 01:33:33 | Legacy | 200 | 142 | 200 | 142 | 2025-11-25 |
| 2026-09-12 23:31:36 | Legacy | 200 | 142 | 200 | 142 | 2025-11-25 |
| 2026-09-12 21:29:15 | Legacy | 200 | 141 | 200 | 143 | 2025-11-25 |
| 2026-09-12 19:27:29 | Legacy | 200 | 143 | 200 | 143 | 2025-11-25 |
| 2026-09-12 17:24:09 | Legacy | 200 | 141 | 200 | 144 | 2025-11-25 |
| 2026-09-12 15:21:42 | Legacy | 200 | 142 | 200 | 141 | 2025-11-25 |
Each block is one measurement round. Green: working response. Amber: responded but the server was returning errors (5xx). Red: no response at all.
Each cell is one probe run. Faded cells are incomplete probes — one leg did not answer, so the era is inconclusive.
The two probe legs separately: modern server/discover and legacy initialize.
Comments
Sign in to write a comment
No comments yet. Be the first.