{
  "protocolVersion": "0.3.0",
  "name": "Depmoor by CyberMax",
  "description": "Dependency vulnerability scanner API: send a lockfile or package list, get findings ranked by real-world risk (OSV advisories, CISA Known Exploited Vulnerabilities, FIRST EPSS) as JSON, SARIF, CSV or Markdown for CI. Also a free CORS-enabled CISA KEV catalogue endpoint.",
  "url": "https://depmoor.cybermaxtools.com",
  "preferredTransport": "HTTP+JSON",
  "version": "1.0.0",
  "provider": {
    "organization": "CyberMax",
    "url": "https://cybermaxtools.com"
  },
  "documentationUrl": "https://depmoor.cybermaxtools.com/llms.txt",
  "capabilities": {
    "streaming": false,
    "pushNotifications": false,
    "stateTransitionHistory": false
  },
  "securitySchemes": {
    "bearer": {
      "type": "http",
      "scheme": "bearer",
      "description": "Depmoor Pro/Team key as Authorization: Bearer DEPMOOR-... (https://depmoor.cybermaxtools.com/#pricing). Required for /api/scan; /api/kev is free with no key."
    },
    "licenceHeader": {
      "type": "apiKey",
      "in": "header",
      "name": "x-licence",
      "description": "Same key in a header."
    }
  },
  "security": [
    {},
    {
      "bearer": []
    },
    {
      "licenceHeader": []
    }
  ],
  "defaultInputModes": [
    "application/json"
  ],
  "defaultOutputModes": [
    "application/json"
  ],
  "skills": [
    {
      "id": "scan_dependencies",
      "name": "Scan a lockfile for exploitable vulnerabilities",
      "description": "POST /api/scan[?format=json|sarif|csv|md] with JSON {\"filename\",\"lockfile\"} or {\"packages\":[{\"ecosystem\",\"name\",\"version\"}]}, or the raw lockfile with ?filename=. Returns findings ranked by KEV status and EPSS. Needs a Pro/Team key (daily scan caps per plan).",
      "tags": [
        "sca",
        "vulnerability scanner",
        "lockfile",
        "cisa kev",
        "epss",
        "sarif"
      ],
      "inputModes": [
        "application/json"
      ],
      "outputModes": [
        "application/json"
      ]
    },
    {
      "id": "cisa_kev",
      "name": "CISA Known Exploited Vulnerabilities catalogue",
      "description": "GET /api/kev returns the CISA KEV catalogue in compact JSON with CORS enabled, cached for 1 hour. Free, no key.",
      "tags": [
        "sca",
        "vulnerability scanner",
        "lockfile",
        "cisa kev",
        "epss",
        "sarif"
      ],
      "examples": [
        "https://depmoor.cybermaxtools.com/api/kev"
      ],
      "inputModes": [
        "application/json"
      ],
      "outputModes": [
        "application/json"
      ]
    }
  ],
  "additionalInterfaces": [
    {
      "url": "https://depmoor.cybermaxtools.com",
      "transport": "HTTP+JSON"
    },
    {
      "url": "https://depmoor.cybermax-tools.workers.dev",
      "transport": "HTTP+JSON"
    }
  ],
  "x-pricing": "https://depmoor.cybermaxtools.com/pricing.json"
}
