New:Microsoft Teams Notifications Are Now Available in Socket.Learn more →
Get Started

@m2msentinel/sdk

Package Overview
Dependencies
Maintainers
1
Versions
8
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@m2msentinel/sdk

JavaScript client for M2M Sentinel Base bytecode capability, proxy and market observations

Source
npmnpm
Version
1.2.0
Version published
Weekly downloads
39
-40%
Maintainers
1
Weekly downloads
 
Created
Source

M2M Sentinel SDKs

Production API Base URL: https://api.m2msentinel.com (with fallback https://m2msentinel.com).

Deterministic EVM bytecode and proxy capability intelligence on Base. Factual static capability observation — not a formal reachability audit, safety guarantee, or transaction advice. Live latency depends on RPC availability and deployment geography; transaction middleware requires a caller-defined policy and has no built-in decision threshold.

Autonomous agents handling value must never rely on a single oracle or heuristic. M2M Sentinel can supply static observations as Layer 1 of a caller-owned pipeline:

[Agent Intent] 
       │
       ▼
[Transaction Builder]
       │
       ▼
[Stage 1: M2M Sentinel Observation] ── (Bytecode hash, proxy target, selected opcode/selector evidence)
       │
       ▼
[Stage 2: Local Policy Engine]    ── (Caller-defined rules: Check spending bounds, reject DELEGATECALL, verify allowlist)
       │
       ▼
[Stage 3: Execution Simulation]   ── (eth_call / Tenderly / Trace state simulation)
       │
       ▼
[Stage 4: Sub-Wallet Signing]     ── (Scoped ephemeral wallet signs & broadcasts on Base)

Installation

JavaScript / TypeScript (npm)

# Scoped package (recommended)
npm install @m2msentinel/sdk

# Or unscoped package
npm install m2m-sentinel-sdk@1.2.0

Python (PyPI)

pip install m2m-sentinel==1.2.0

MCP Server (Model Context Protocol)

npx -y @m2msentinel/sdk
# or
npx -y m2m-sentinel-sdk

Quickstart: JavaScript / TypeScript

const { M2MSentinelClient, X402SignerClient } = require('@m2msentinel/sdk');

// 1. Standard API Client (Header Authentication)
const client = new M2MSentinelClient({
  apiKey: process.env.M2M_SENTINEL_API_KEY,
  baseUrl: 'https://api.m2msentinel.com'
});

// Inspect contract capabilities before transaction
const audit = await client.auditContract('0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913');
console.log('Contract capabilities:', audit.audit.verdict.executableCapabilities);
console.log('Capability evidence:', audit.audit.dissection.capabilities);
console.log('Proxy Target:', audit.audit.proxyResolution.targetAddress);
console.log('Reachability:', audit.audit.reachability || 'NOT_ESTABLISHED');

// 2. Autonomous Headless x402 Micropayments (EIP-3009 Local Signing)
const x402Client = new X402SignerClient({
  walletSigner: myAgentWallet, // ethers / viem signer
  baseUrl: 'https://api.m2msentinel.com',
  maxPriceUsd: 0.01 // Optional: strict spending limit (default $0.05)
});

const res = await x402Client.fetchWithAutoPayment('/v1/audit/0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913');
console.log('Paid analysis result:', res.json);

🛡️ Autonomous Wallet Policy & Security Boundaries

To prevent autonomous AI agents from blindly signing arbitrary or spoofed HTTP 402 challenges from untrusted sources, X402SignerClient enforces 4 strict client-side invariants locally before generating any cryptographic signature:

Client InvariantEnforced ValueSecurity Protection
Chain ID8453 (Base Mainnet)Rejects signing on any unapproved EVM chain.
Asset Contract0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913Rejects signing for unapproved tokens (Base USDC only).
Payout Recipient0x6d6c398390cfb88f1cd42715b84906a0bd6652aaRejects signing payments to unexpected recipient addresses.
Price CeilingmaxPriceUsd (Default: $0.05)Throws if remote challenge requests funds exceeding caller's authorized ceiling.
import { X402SignerClient } from '@m2msentinel/sdk';

// Fully policy-constrained autonomous signer with immutable recipient & domain constants
const signer = new X402SignerClient({
  wallet: agentWallet,
  maxPriceUsd: 0.005 // Strict spending limit: 0.5 cents max per decision (default $0.05)
});

Authentication and x402

Send API keys only in x-api-key (or Authorization: Bearer). Query-string credentials are rejected with HTTP 401. Payable routes also support x402 v2 on Base USDC. An unpaid call returns a base64 PAYMENT-REQUIRED challenge; a successful settlement returns PAYMENT-RESPONSE.

Public Routes

  • GET /v1/status
  • GET /v1/stats (public privacy envelope; exact aggregate commercial counters are operator-only)
  • GET /v1/plans
  • GET /v1/demo/audit/:address for the published sample allowlist
  • GET /v1/audit/:address (requires API key or x402 payment)

The JavaScript, TypeScript, and Python clients expose multi-period purchase/renewal and wallet recovery without requiring callers to hand-build requests:

await client.createSubscriptionIntent('GROWTH', wallet, {
  durationDays: 90,
  renewExistingKey: true,
  apiKey: existingPaidKey
});
const challenge = await client.createRecoveryChallenge(wallet, { txHash });
await client.claimRecoveredKey(challenge.intent.id, walletSignature);

Disclaimer & Limitations

Deterministic EVM bytecode and proxy capability intelligence on Base. Factual static capability observation — not a formal reachability audit, safety guarantee, or transaction advice. Live latency depends on RPC availability and deployment geography.

Keywords

web3

FAQs

Package last updated on 24 Aug 2026

Related posts