
Security News
The Hidden Blast Radius of the Axios Compromise
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.
@scopeblind/crewai
Advanced tools
ScopeBlind evidence wrapper for CrewAI tool calls. Automatically creates Veritas Acta receipts for every tool invocation and delegation.
Veritas Acta evidence wrapper for CrewAI multi-agent tool calls. Produces signed evidence chains for every tool invocation, plus delegation receipts for inter-agent authority transfers.
npm install @scopeblind/crewai
import { wrapCrewTool } from '@scopeblind/crewai';
const config = {
issuer: 'my-crew',
privateKey: '...', // Ed25519 hex seed (optional)
onReceipt: (receipt) => console.log('📋', receipt.receipt_type, receipt.receipt_id),
};
const protectedTool = wrapCrewTool(myTool, config, 'researcher-agent');
import { wrapCrewTools } from '@scopeblind/crewai';
const tools = wrapCrewTools(
[searchTool, writeTool, apiTool],
config,
'researcher-agent',
);
When one agent delegates work to another:
import { createDelegationReceipt } from '@scopeblind/crewai';
const delegation = createDelegationReceipt({
delegator: 'manager-agent',
delegate: 'researcher-agent',
tools: ['search', 'read_file'],
maxActions: 10,
expiresAt: '2026-04-01T00:00:00Z',
subDelegation: false,
reason: 'Research phase of task #42',
}, config);
After red-team testing or evaluation:
import { createCapabilityAttestation } from '@scopeblind/crewai';
const attestation = createCapabilityAttestation({
agentId: 'researcher-agent',
attesterId: 'red-team-suite',
assessmentType: 'injection-resistance',
result: 'pass',
scores: { 'prompt-injection': 95, 'tool-abuse': 88 },
testCount: 50,
passCount: 47,
}, config);
const config = {
issuer: 'my-crew',
indexerEndpoint: 'https://evidence-indexer.tomjwxf.workers.dev',
indexerApiKey: 'your-api-key',
};
Each tool call produces 3 linked receipts. Delegations add a 4th:
🤝 delegation (delegator → delegate, scoped tools)
└──▶ ⚖️ decision (allow/deny)
└──[caused_by]──▶ ⚡ execution (input_hash)
└──[caused_by]──▶ 📦 outcome (output_hash)
Multi-agent systems have an accountability gap: when Agent A tells Agent B to do something harmful, who's responsible? Delegation receipts close this gap by making inter-agent authority transfers cryptographically verifiable.
Built on Veritas Acta — the open evidence protocol for machine decisions.
MIT — ScopeBlind
FAQs
ScopeBlind evidence wrapper for CrewAI tool calls. Automatically creates Veritas Acta receipts for every tool invocation and delegation.
We found that @scopeblind/crewai demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.