
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@brainai/satp-client
Advanced tools
SATP v2 Client SDK — Solana Agent Token Protocol (Identity, Reviews, Reputation, Attestations, Validation)
Lightweight SDK for interacting with SATP (Solana Agent Token Protocol) programs on Solana.
cd satp-sdk && npm install
const { SATPSDK } = require('./src');
const sdk = new SATPSDK(); // mainnet by default
// const sdk = new SATPSDK({ rpcUrl: 'https://api.devnet.solana.com' });
// Check if an agent is registered
const verified = await sdk.verifyAgent('SomeWalletPubkey...');
// Get identity data
const identity = await sdk.getIdentity('SomeWalletPubkey...');
// Get reputation
const rep = await sdk.getReputation('SomeWalletPubkey...');
// Derive PDAs (offline, no RPC)
const pdas = sdk.getPDAs('SomeWalletPubkey...');
const { Keypair } = require('@solana/web3.js');
const signer = Keypair.fromSecretKey(/* your key */);
// Register identity
const sig = await sdk.registerIdentity(signer, 'my-agent', { type: 'ai', version: '1.0' });
// Add reputation (endorser signs)
const sig2 = await sdk.addReputation(endorserKeypair, targetWallet, 100);
// Get unsigned transaction for frontend signing
const { transaction, identityPDA } = await sdk.buildRegisterIdentity(
walletPublicKey, 'agent-name', { metadata: true }
);
// Sign with wallet adapter, then send
| Method | Type | Description |
|---|---|---|
getIdentity(wallet) | Read | Fetch identity data (or null) |
getReputation(wallet) | Read | Fetch reputation data (or null) |
verifyAgent(wallet) | Read | Check if wallet has SATP identity |
getPDAs(wallet) | Offline | Derive identity + reputation PDAs |
registerIdentity(signer, name, metadata) | Write | Register on-chain identity |
addReputation(endorser, target, score) | Write | Add reputation score |
buildRegisterIdentity(wallet, name, meta) | Builder | Unsigned tx for frontends |
buildAddReputation(wallet, score, endorser) | Builder | Unsigned tx for frontends |
| Program | Address |
|---|---|
| Identity | BY4jzmnrui1K5gZ5z5xRQkVfEEMXYHYugtH1Ua867eyr |
| Reputation | TQ4P9R2Y5FRyw1TZfwoWQ2Mf6XeohbGdhYNcDxh6YYh |
| Validation | AdDWFa9oEmZdrTrhu8YTWu4ozbTP7e6qa9rvyqfAvM7N |
| Escrow | STyY8w4ZHws3X1AMoocWuDYBoogVDwvymPy8Wifx5TH |
new SATPSDK({ rpcUrl: 'https://api.devnet.solana.com' })FAQs
SATP client SDK for reviewed Solana Agent Trust Protocol integrations.
The npm package @brainai/satp-client receives a total of 9 weekly downloads. As such, @brainai/satp-client popularity was classified as not popular.
We found that @brainai/satp-client demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.