
Security News
Open VSX Unblocks Extension IDs Used in Malware Campaign
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.
@ar-agents/banking
Advanced tools
Argentine banking primitives (CBU/CVU validation + bank lookup) plus BCRA Central de Deudores AND BCRA Principales Variables (USD, CER, UVA, reservas, BADLAR, inflación) as drop-in tools for the Vercel AI SDK. Pure-algorithm out of the box; BCRA lookups v
Argentine banking primitives for Vercel AI SDK 6+ agents: CBU/CVU validation, bank/PSP lookup, and BCRA Central de Deudores.
Reading this as an agent? Skip to AGENTS.md for tool selection rules, result schemas to memorize, error patterns, and AR banking context.
| What | Value |
|---|---|
| Tools shipped | 5: validate_cbu, lookup_bank_by_code, list_banks, list_psps, lookup_credit_situation |
| Pure-algorithm | validate_cbu + lookup_bank_by_code + bank/PSP lists work with zero setup (no API key) |
| External adapter | BcraPublicApiAdapter (default: public BCRA API, no auth) for credit-situation lookups |
| Banks + PSPs covered | All 60+ AR banks (Galicia, Nación, BBVA, Santander…) + 20+ PSPs (Mercado Pago, Ualá, Naranja X, Modo, Cuenta DNI…) |
| Test coverage | 54 unit tests, 90% statements, 100% functions |
| Bundle | 5.3 KB ESM brotli'd |
| Runtime | Edge Runtime + Node 18+ (pure compute, no node:crypto) |
Built for agents that need to:
Ships with pure-algorithm tools that always work (no API key, no setup) and a pluggable BCRA adapter for credit lookups.
pnpm add @ar-agents/banking
# peer deps: ai >=6, zod >=3
import { Experimental_Agent as Agent, stepCountIs } from "ai";
import { bankingTools, BcraPublicApiAdapter } from "@ar-agents/banking";
const agent = new Agent({
model: "anthropic/claude-sonnet-4-6",
tools: bankingTools({
bcra: new BcraPublicApiAdapter(), // optional: for credit lookups
}),
stopWhen: stepCountIs(6),
});
const { text } = await agent.generate({
prompt: "Validá este CBU: 0070123145678901234564",
});
// → "Es un CBU válido. Banco: Banco Galicia, sucursal 0123, cuenta 4567890123456."
Without a BCRA adapter, the credit-lookup tool stays callable but returns
{ available: false, error: "<setup instructions>" } instead of crashing.
| Tool | Pure? | What it does |
|---|---|---|
validate_cbu | ✓ | Validate CBU/CVU + identify bank/PSP |
lookup_bank_by_code | ✓ | Resolve a 3-digit bank code or 7-digit CVU prefix → name |
list_banks | ✓ | Enumerate all known banks (for dropdowns) |
list_psps | ✓ | Enumerate all known PSPs/fintechs (for dropdowns) |
lookup_credit_situation | : | BCRA Central de Deudores lookup (requires adapter) |
See AGENTS.md for detailed selection guidance and result schemas.
CBU = Clave Bancaria Uniforme (traditional bank accounts). CVU = Clave Virtual Uniforme (PSPs / fintechs / digital wallets).
Both are 22 digits with the BCRA dual mod-10 check-digit algorithm:
BBB-SSSS-V₁: entity (3) + branch (4) + check (1)<account-13>-V₂: account (13) + check (1)The algorithm is implemented in src/cbu.ts and exposed via parseCbu(),
isValidCbu(), and computeBlockCheckDigit(). Pure functions, sub-millisecond,
no I/O.
For B2B agents that need credit-risk signal on a counterparty CUIT:
import { bankingTools, BcraPublicApiAdapter } from "@ar-agents/banking";
const tools = bankingTools({
bcra: new BcraPublicApiAdapter({
requestTimeoutMs: 15_000,
maxRetries: 2,
onCall: (e) => console.log(e), // observability hook
}),
});
The default adapter hits BCRA's public REST endpoint
(api.bcra.gob.ar/centraldedeudores/v1.0/Deudas/{cuit}): no auth required,
respect their rate limits. You can swap in your own adapter for caching, NOSIS,
Equifax, or a private mirror.
Returns a normalized BcraDeudaResult with the worst situation code (1–6),
total outstanding debt across all entities, and per-entity breakdown.
See BcraSituation in src/types.ts for the situation-code
reference (1=normal, 5=irrecuperable, etc.).
MIT © Nazareno Clemente
This package is pre-1.0. Per npm convention, 0.x minor versions may include breaking changes. We document every breaking change in CHANGELOG.md under the corresponding minor bump and flag it explicitly. To avoid surprises:
# Pin to exact version (recommended for production):
pnpm add @ar-agents/<package>@<exact-version>
We commit to no breaking changes within a patch version, and we publish 1.0.0 once the public API has stabilized across at least two consecutive minor releases.
FAQs
Argentine banking primitives (CBU/CVU validation + bank lookup) plus BCRA Central de Deudores AND BCRA Principales Variables (USD, CER, UVA, reservas, BADLAR, inflación) as drop-in tools for the Vercel AI SDK. Pure-algorithm out of the box; BCRA lookups v
The npm package @ar-agents/banking receives a total of 18 weekly downloads. As such, @ar-agents/banking popularity was classified as not popular.
We found that @ar-agents/banking demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Open VSX has removed three extension IDs from its malicious-extension list as the legitimate publishers they impersonated move to claim the names for themselves.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.