
Research
/Security News
77 Firefox Extensions Linked to Crypto Wallet and Credential Theft
Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.
@operon/plugin-publisher-sdk
Advanced tools
ElizaOS plugin for Operon - monetize agent responses with quality-weighted sponsored placements
ElizaOS plugin for Operon - the protocol-level monetization layer for AI agents. Add quality-weighted sponsored placements to your agent's responses with zero prompt engineering.
The plugin runs a Provider that fires on every message. It sends the user's query to Operon's placement API, which runs a quality-weighted auction across registered advertisers. In v1, context fields (category, asset, intent) are configurable via settings with empty defaults - the Operon server handles matching and returns blocked when nothing fits. If a relevant, trustworthy service matches:
If nothing matches, the agent responds normally. No degradation, no empty ad slots.
The plugin includes a circuit breaker - if Operon is unreachable, it stops calling after 5 consecutive failures and retries after 30 seconds.
npx @elizaos/cli plugins add @operon/plugin-publisher-sdk
Or manually:
npm install @operon/plugin-publisher-sdk
Set your environment variables:
OPERON_URL=https://api.operon.so # Operon network endpoint (HTTPS required)
OPERON_API_KEY=your-publisher-key # Your publisher API key from Operon
OPERON_PUBLISHER_NAME=my-agent # Optional - defaults to character name
OPERON_DEFAULT_CATEGORY=defi # Optional - default category for placements
OPERON_DEFAULT_INTENT=research # Optional - default intent for placements
import operonPublisherPlugin from "@operon/plugin-publisher-sdk";
export const character: Character = {
name: "MyResearchAgent",
plugins: [operonPublisherPlugin],
settings: {
secrets: {
OPERON_URL: process.env.OPERON_URL,
OPERON_API_KEY: process.env.OPERON_API_KEY,
},
},
// ...
};
{
"name": "MyResearchAgent",
"plugins": ["@operon/plugin-publisher-sdk"],
"settings": {
"secrets": {
"OPERON_URL": "https://api.operon.so",
"OPERON_API_KEY": "your-publisher-key"
}
}
}
When a sponsored placement fills:
[Sponsored] Relevant service available: Jupiter Aggregator
- Best-rate DEX aggregation across Solana
- Trust score: 82/100
When nothing matches, the response is clean - no mention of Operon or sponsorship.
The plugin sends the following data to the Operon API on every message:
No wallet addresses, private keys, or credentials are extracted or sent separately, but any content in the user's message text will be included in the API request. Publishers should consider this when deciding whether to integrate the plugin.
If you want to use the Operon SDK outside ElizaOS:
import { createOperonPublisherSDK } from "@operon/plugin-publisher-sdk";
const sdk = createOperonPublisherSDK("https://api.operon.so", "your-key");
const result = await sdk.requestPlacement({
publisher: "my-agent",
slotType: "agent-response",
requestContext: {
query: "best way to swap ETH to USDC",
category: "defi",
asset: "ETH",
amount: "5",
intent: "swap",
},
responseContext: {
actions: ["swap", "compare"],
sentiment: "neutral",
},
});
See operon-otaku for a complete example of an ElizaOS agent with the Operon plugin integrated.
FAQs
ElizaOS plugin for Operon - monetize agent responses with quality-weighted sponsored placements
The npm package @operon/plugin-publisher-sdk receives a total of 22 weekly downloads. As such, @operon/plugin-publisher-sdk popularity was classified as not popular.
We found that @operon/plugin-publisher-sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.

Security News
NIST disclosed an unreleased AI tool called V-etalon and opened a broad inquiry into NVD modernization after years of automation plans produced no public enrichment system.

Security News
In his AI Council 2026 talk, Feross Aboukhadijeh covers recent package compromises, vulnerability discovery, and a more automated security model.