
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@m2msentinel/sdk
Advanced tools
JavaScript client for M2M Sentinel Base bytecode capability, proxy and market observations
Production API Base URL: https://api.m2msentinel.com (with fallback https://m2msentinel.com).
Deterministic EVM bytecode and proxy capability intelligence on Base. Factual static capability observation — not a formal reachability audit, safety guarantee, or transaction advice. Live latency depends on RPC availability and deployment geography; transaction middleware requires a caller-defined policy and has no built-in decision threshold.
Autonomous agents handling value must never rely on a single oracle or heuristic. M2M Sentinel can supply static observations as Layer 1 of a caller-owned pipeline:
[Agent Intent]
│
▼
[Transaction Builder]
│
▼
[Stage 1: M2M Sentinel Observation] ── (Bytecode hash, proxy target, selected opcode/selector evidence)
│
▼
[Stage 2: Local Policy Engine] ── (Caller-defined rules: Check spending bounds, reject DELEGATECALL, verify allowlist)
│
▼
[Stage 3: Execution Simulation] ── (eth_call / Tenderly / Trace state simulation)
│
▼
[Stage 4: Sub-Wallet Signing] ── (Scoped ephemeral wallet signs & broadcasts on Base)
# Scoped package (recommended)
npm install @m2msentinel/sdk
# Or unscoped package
npm install m2m-sentinel-sdk@1.2.0
pip install m2m-sentinel==1.2.0
npx -y @m2msentinel/sdk
# or
npx -y m2m-sentinel-sdk
const { M2MSentinelClient, X402SignerClient } = require('@m2msentinel/sdk');
// 1. Standard API Client (Header Authentication)
const client = new M2MSentinelClient({
apiKey: process.env.M2M_SENTINEL_API_KEY,
baseUrl: 'https://api.m2msentinel.com'
});
// Inspect contract capabilities before transaction
const audit = await client.auditContract('0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913');
console.log('Contract capabilities:', audit.audit.verdict.executableCapabilities);
console.log('Capability evidence:', audit.audit.dissection.capabilities);
console.log('Proxy Target:', audit.audit.proxyResolution.targetAddress);
console.log('Reachability:', audit.audit.reachability || 'NOT_ESTABLISHED');
// 2. Autonomous Headless x402 Micropayments (EIP-3009 Local Signing)
const x402Client = new X402SignerClient({
walletSigner: myAgentWallet, // ethers / viem signer
baseUrl: 'https://api.m2msentinel.com',
maxPriceUsd: 0.01 // Optional: strict spending limit (default $0.05)
});
const res = await x402Client.fetchWithAutoPayment('/v1/audit/0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913');
console.log('Paid analysis result:', res.json);
To prevent autonomous AI agents from blindly signing arbitrary or spoofed HTTP 402 challenges from untrusted sources, X402SignerClient enforces 4 strict client-side invariants locally before generating any cryptographic signature:
| Client Invariant | Enforced Value | Security Protection |
|---|---|---|
| Chain ID | 8453 (Base Mainnet) | Rejects signing on any unapproved EVM chain. |
| Asset Contract | 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 | Rejects signing for unapproved tokens (Base USDC only). |
| Payout Recipient | 0x6d6c398390cfb88f1cd42715b84906a0bd6652aa | Rejects signing payments to unexpected recipient addresses. |
| Price Ceiling | maxPriceUsd (Default: $0.05) | Throws if remote challenge requests funds exceeding caller's authorized ceiling. |
import { X402SignerClient } from '@m2msentinel/sdk';
// Fully policy-constrained autonomous signer with immutable recipient & domain constants
const signer = new X402SignerClient({
wallet: agentWallet,
maxPriceUsd: 0.005 // Strict spending limit: 0.5 cents max per decision (default $0.05)
});
Send API keys only in x-api-key (or Authorization: Bearer). Query-string credentials are rejected with HTTP 401. Payable routes also support x402 v2 on Base USDC. An unpaid call returns a base64 PAYMENT-REQUIRED challenge; a successful settlement returns PAYMENT-RESPONSE.
GET /v1/statusGET /v1/stats (public privacy envelope; exact aggregate commercial counters are operator-only)GET /v1/plansGET /v1/demo/audit/:address for the published sample allowlistGET /v1/audit/:address (requires API key or x402 payment)The JavaScript, TypeScript, and Python clients expose multi-period purchase/renewal and wallet recovery without requiring callers to hand-build requests:
await client.createSubscriptionIntent('GROWTH', wallet, {
durationDays: 90,
renewExistingKey: true,
apiKey: existingPaidKey
});
const challenge = await client.createRecoveryChallenge(wallet, { txHash });
await client.claimRecoveredKey(challenge.intent.id, walletSignature);
Deterministic EVM bytecode and proxy capability intelligence on Base. Factual static capability observation — not a formal reachability audit, safety guarantee, or transaction advice. Live latency depends on RPC availability and deployment geography.
FAQs
JavaScript client for M2M Sentinel Base bytecode capability, proxy and market observations
The npm package @m2msentinel/sdk receives a total of 25 weekly downloads. As such, @m2msentinel/sdk popularity was classified as not popular.
We found that @m2msentinel/sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.