
Research
/Security News
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.
@agonx402/agentic
Advanced tools
Agent-facing tools for discovering and calling Agon Gateway routes.
Install all Agon skills into the default agent skill directory, ~/.agents/skills:
npx -y @agonx402/agentic install-skills
Other install targets:
npx -y @agonx402/agentic install-skills --target codex
npx -y @agonx402/agentic install-skills --target all
npx -y @agonx402/agentic list
npx -y @agonx402/agentic doctor
npx -y @agonx402/agentic setup
The installer copies only the Agon skill folders, creates the target directory if needed, and overwrites only these Agon-owned skill names:
agon-gatewayagon-protocolagon-gateway-payment-channelsIt does not store private keys, sign transactions, broadcast transactions, or edit MCP/client config files.
Run the CLIs directly with npx:
npx -y @agonx402/gateway-cli catalog
npx -y @agonx402/gateway-cli agent-prompt
npx -y @agonx402/gateway-cli auth prepare GET /v1/x402/tokens/assets/search --query q=bitcoin --query limit=1 --json
npx -y @agonx402/gateway-cli auth call GET /v1/x402/tokens/assets/search --query q=bitcoin --query limit=1 --auth-driver my-wallet-auth-driver
npx -y @agonx402/protocol-cli config
npx -y @agonx402/protocol-cli token show
MCP servers are separate packages:
{
"mcpServers": {
"agon-gateway": {
"command": "npx",
"args": ["-y", "@agonx402/gateway-mcp"]
},
"agon-protocol": {
"command": "npx",
"args": ["-y", "@agonx402/protocol-mcp"]
}
}
}
Payment-channel flows are devnet-only in v1. Tokens SIWX routes do not use payment channels. Gateway auth drivers are wallet-agnostic helper commands. The Gateway CLI sends normalized auth request JSON to the driver over stdin and accepts returned headers or SIWX address/signature JSON over stdout. Drivers can wrap browser wallets, local keypairs, MPC, custody systems, x402 payment services, or Agon channel commitment builders. The Agon CLI/MCP packages do not keep keys or mutate wallet/MCP configuration.
package root publishes @agonx402/agentic, a one-step skill installer.cli/ publishes @agonx402/gateway-cli, a zero-dependency CLI.mcp/ publishes @agonx402/gateway-mcp, a stdio MCP server.protocol-cli/ publishes @agonx402/protocol-cli, a read-only and prepare-only Agon Protocol CLI.protocol-mcp/ publishes @agonx402/protocol-mcp, a read-only and prepare-only Agon Protocol MCP server.skills/agon-gateway/ is a Codex-style skill for agent workflows.skills/agon-protocol/ is a Codex-style skill for protocol accounts, channels, settlement, and BLS caveats.skills/agon-gateway-payment-channels/ is a Codex-style skill for gateway payment-channel authorization.llm.txt and llms.txt are LLM-readable gateway docs for websites.node cli/agon-gateway.js health
node cli/agon-gateway.js catalog --provider helius
node cli/agon-gateway.js auth prepare GET /v1/x402/tokens/assets/search --query q=bitcoin --query limit=1 --json
node protocol-cli/agon-protocol.js token show
node mcp/server.js
node protocol-mcp/server.js
The CLI and MCP server do not store wallet private keys. They can issue x402/SIWX challenges and retry with payment/auth headers produced by the caller's wallet layer. The protocol CLI and MCP server are read + prepare only; they do not sign or broadcast transactions.
FAQs
Installer for Agon Gateway and Agon Protocol agent skills, default SIWX signer wallet, MCP servers, and signer hooks.
The npm package @agonx402/agentic receives a total of 12 weekly downloads. As such, @agonx402/agentic popularity was classified as not popular.
We found that @agonx402/agentic demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.