
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@true402.dev/langchain
Advanced tools
true402 tools for LangChain — pay-per-call on-chain rug/honeypot & address safety plus backlink/keyword SEO data for Base AI agents over x402 (USDC, no account, no API key).
Stable · production-ready — semver-stable public API (v1.0).
true402 tools for LangChain — give your Base agent pay-per-call on-chain safety and search/SEO data over x402: rug/honeypot checks, address safety, deployer reputation, backlink profiles, and keyword research. No account, no API key — the wallet is the identity (USDC on Base, gas sponsored by the facilitator).
npm i @true402.dev/langchain @langchain/core
import { createTrue402Tools } from '@true402.dev/langchain';
const tools = createTrue402Tools({ payerPrivateKey: process.env.PAYER_PRIVATE_KEY! });
// → add `tools` to any LangChain agent (createReactAgent, AgentExecutor, …)
The agent can now call:
| Tool | What it does | ~price |
|---|---|---|
true402_token_report | Composite avoid / caution / ok verdict for a Base ERC-20 (buy/sell honeypot sim + liquidity + ownership + rug activity) | $0.01 |
true402_token_safety | Structural safety score 0–100 + flags | $0.005 |
true402_address_safety | Profile + risk for any address before you send/approve/call it (proxy detection) | $0.005 |
true402_tx_preflight | Check an unsigned transaction before signing: does it revert, does it grant an unlimited approval, has the counterparty been draining liquidity. Takes no key and no signature | $0.008 |
true402_liquidity_history | What already happened to a token's liquidity — every removal with amount/block/tx, plus the tokens drained in the same transaction | $0.005 |
true402_deployer_check | Deployer reputation — who made the token + their track record | $0.008 |
true402_backlinks | A domain's backlink profile — referring domains/pages, dofollow split, authority rank, spam score | $0.10 |
true402_keyword_volume | Search volume/CPC/competition for up to 200 keywords in one call — priced per call, not per keyword | $0.15 |
true402_ranked_keywords | Keywords a domain already ranks for, with position and the ranking URL — competitor research too | $0.05 |
true402_keyword_ideas | Related/long-tail keyword ideas for a seed term, with volume and intent | $0.05 |
payerPrivateKey is a Base wallet holding a little USDC. Without it the stalls still return their HTTP 402 price, so the agent can decide. Override baseUrl / rpcUrl in the options if self-hosting.
Checking tokens by hand? Send any Base token address to @True402bot on Telegram — same on-chain checks, free, no wallet.
Powered by true402 — the machine-native x402 marketplace on Base. Browse every stall at /catalog.
MCP (Claude Code / Desktop, Cursor, Hermes) · Hermes Agent · OpenClaw · ElizaOS · LangChain · CrewAI · Vercel AI SDK · Coinbase AgentKit · Virtuals GAME · CLI — same on-chain checks, one install command each: true402.dev/integrations
The rules below are the service's, not this package's — they bite whatever client you use, and they are the ones that surprise people writing their own payer.
Full rules: true402.dev/terms · what is logged and kept: true402.dev/privacy
FAQs
true402 tools for LangChain — pay-per-call on-chain rug/honeypot & address safety plus backlink/keyword SEO data for Base AI agents over x402 (USDC, no account, no API key).
The npm package @true402.dev/langchain receives a total of 437 weekly downloads. As such, @true402.dev/langchain popularity was classified as not popular.
We found that @true402.dev/langchain demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.