
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
stillos-kya
Advanced tools
Counterparty due-diligence infrastructure for agent-native commerce. A single call returns a CLEAR / REVIEW / BLOCK compliance determination, combining OFAC sanctions-list screening with live on-chain wallet risk signals — engineered fail-closed so no tra
The trust toll for agent-to-agent commerce. Before your AI agent pays another agent, run one check: is the counterparty sanctioned? Is its wallet a scam/contract/drained? StillOS returns a fail-closed CLEAR / REVIEW / BLOCK verdict — OFAC SDN screen + live on-chain wallet signals — with an Ed25519-signed receipt you can attach to the transaction as proof-of-diligence.
a16z (Big Ideas 2026) calls "Know Your Agent" — signed agent credentials + counterparty trust — the prerequisite for merchants to let agents onto payment rails. This is a working drop-in for it.
npm install stillos-kya
const { kya } = require('stillos-kya');
const r = await kya({ name: 'Acme Agent', wallet: '0xabc...' });
if (!r.allowed) throw new Error(`counterparty ${r.verdict}`); // CLEAR | REVIEW | BLOCK
// r.receipt -> { hash, signature, verify } (signed, verifiable proof-of-screening)
const { kyaGate } = require('stillos-kya');
// Every payment through this route runs a counterparty trust-check first.
app.post('/pay-agent', kyaGate({ blockOnReview: false }), async (req, res) => {
// req.kya = { verdict, allowed, checks, receipt, ... }
// ...proceed to pay; blocked counterparties never reach here
});
xPayment or apiKey in opts.Pricing + full endpoint reference: https://nolawealthfinancial.com/notary
An unsigned "looks fine" is worthless if a counterparty later turns out sanctioned or fraudulent. A StillOS signed receipt is cryptographic proof that you screened before you paid — the audit artifact that protects you.
FAQs
Counterparty due-diligence infrastructure for agent-native commerce. A single call returns a CLEAR / REVIEW / BLOCK compliance determination, combining OFAC sanctions-list screening with live on-chain wallet risk signals — engineered fail-closed so no tra
We found that stillos-kya demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.