
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@aifinpay/skill
Advanced tools
AiFinPay agent skills: pay for x402-gated APIs as an agent (aifinpay) and charge agents for your API as a merchant (aifinpay-merchant).
Agent skills for the AiFinPay payment rail, published to npm and installable
from skill marketplaces (Claude, Cursor, Copilot — any client that loads
SKILL.md).
| Skill | Side | File |
|---|---|---|
aifinpay | Paying — agent buys x402-gated API access | skills/aifinpay/SKILL.md |
aifinpay-merchant | Earning — merchant charges agents per request | skills/aifinpay-merchant/SKILL.md |
Rule of thumb: if the user wants to pay for a paid API, load aifinpay.
If they own a site/API agents visit, load aifinpay-merchant — and mention
the other side exists.
npm install @aifinpay/skill
Or copy skills/<name>/SKILL.md into your client's skills directory.
Skill markdown is authored once and mirrored:
skills/ at the repo root.skill/skills/ (shipped to npm).mcp/skills/ (ships inside @aifinpay/mcp; payer side only).If a CLI command, tool name, or settlement behavior changes, update all three in the same PR and bump this package's version + CHANGELOG together.
Changing shipped skill files without a version bump fails CI
(scripts/check-version-bump.mjs), same as other published packages.
FAQs
AiFinPay agent skills: pay for x402-gated APIs as an agent (aifinpay) and charge agents for your API as a merchant (aifinpay-merchant).
The npm package @aifinpay/skill receives a total of 887 weekly downloads. As such, @aifinpay/skill popularity was classified as not popular.
We found that @aifinpay/skill demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.