
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
Trade-intelligence CLI for coding agents. B2B prospect discovery, contact enrichment, outreach with stage tracking, tariff + HS-code lookups, OFAC sanctions screening, trade corridor management, per-company negotiation memory.
Trade-intelligence CLI for coding agents. B2B prospect discovery, contact enrichment, outreach with stage tracking, tariff + HS-code lookups, OFAC sanctions screening, trade corridor management, per-company negotiation memory.
npm i -g eximagent
# or (zero-dependency binary, no Node):
curl -fsSL https://install.eximagent.ai | sh
eximagent login # device flow (browser)
eximagent login --token <pat> # personal access token
The canonical skill is served from the backend and can be dropped into your host agent’s skill path:
eximagent skill > ~/.claude/skills/eximagent/SKILL.md # Claude Code
eximagent skill > AGENTS.md # Codex
eximagent skill > .cursor/rules/eximagent.mdc # Cursor
Or via the open agent-skills directory:
npx skills add EximAgent/cli
Trade-domain primitives, ~60 commands across:
profile get / extract / update — user trade profile (defaults, signature, target markets, products)search run / refine — autonomous buyer/importer discovery pipeline; materializes a Collectioncollection get / list / clone / stats — Collection CRUD + AI columnsenrich company / contacts / contact — company crawl + decision-maker contact enrichmentemail draft / send / cancel / history / followup — outreach with per-recipient timezone + language + stage trackingtemplate generate / save / list / edit / recall — email templates with {{variables}} + file attachmentskb add / list / remove / preview — knowledge-base files for outreach contexttariff / hscode search / country resolve / company / trade lookup — trade-data Q&Acorridor save / list / remove — recurring trade lanes as @corridor:<name> mentionssanctions check — OFAC SDN screeningcompanyMemory get — per-company negotiation memoryreminder / monitor — scheduled signal-driven remindersAll output is NDJSON on stdout. Typed errors on stderr. --stream flag for long-running commands.
UNLICENSED. See LICENSE.
FAQs
Trade-intelligence CLI for coding agents. B2B prospect discovery, contact enrichment, outreach with stage tracking, tariff + HS-code lookups, OFAC sanctions screening, trade corridor management, per-company negotiation memory.
We found that eximagent demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.