npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@seshat_oracle/kronos-mcp

v0.3.0

Published

MCP server for Seshat Kronos Quant Signal — multi-asset financial forecasts via x402 micropayments

Readme

@seshat_oracle/kronos-mcp

MCP stdio server for Seshat Kronos Quant Signal.

Tools

Free (no wallet required)

| Tool | Description | |------|-------------| | kronos_catalog | Symbols, timeframes, model config, products, prices | | kronos_sample | Delayed real BTC model output for testing | | kronos_risk | Current operational risk state, streak, cooldown | | kronos_accuracy_preview | Aggregate hit rate and Brier score (rounded) | | kronos_conviction_signals | Top 3 non-BTC symbols by prediction strength | | kronos_composite_preview | Quant vs Crowd divergence preview | | kronos_benchmark_preview | Leaderboard preview (fixed 7-day window) | | kronos_decision | Single auditable decision record by ID |

Paid (requires x402 buyer wallet)

| Tool | Price | Description | |------|-------|-------------| | kronos_predict | $0.01/TF | Fresh on-demand forecast (cap $0.04) | | kronos_forecast_distribution | $0.01/TF | Full sample distribution with percentiles | | kronos_accuracy | $0.001 | Model accuracy with baselines | | kronos_accuracy_candles | $0.005 | Per-timeframe MAPE and MAE | | kronos_risk_history | $0.02 | Historical streak analytics | | kronos_decisions | $0.001 | Browse recent predictions | | kronos_forecast_evolution | $0.005 | How forecasts change over time | | kronos_historical_analogs | $0.01 | Past similar situations and outcomes | | kronos_regime | $0.02 | Cross-symbol market regime detection | | kronos_agent_track_record | $0.001 | Kronos as market voter — win rate, Brier | | kronos_agent_votes | $0.003 | Recent votes with market context | | kronos_agent_signals | $0.005 | Open markets with vote status | | kronos_composite | $0.01 | Quant vs Crowd divergence analysis | | kronos_confluence | $0.01 | Quant vs sentiment vs crowd tags | | kronos_benchmark | $0.02 | Full leaderboard with accuracy and Brier | | kronos_digest | $0.03 | AI cross-referenced digest (7 sources) | | kronos_market_brief | $0.05 | AI narrative with sourced news and events | | kronos_market_context | $0.03 | Cross-venue funding, OI, liquidations, IV | | kronos_similar_markets | $0.005 | Semantic similar markets by text query | | kronos_outcome_stats | $0.01 | Outcome distribution of similar markets | | kronos_behavioral_correlations | $0.01 | How similarly agents reason | | kronos_rationale_novelty | $0.01 | Detect templated vs genuine reasoning |

Run locally

npm install
npm start

Override the API for local testing:

KRONOS_API_URL=http://127.0.0.1:8787 npm start

All diagnostics must use stderr; stdout is reserved for MCP JSON-RPC traffic.

Enable buyer-side x402 payments

Free tools work without a wallet. To let paid tools sign x402 authorizations automatically, configure one or both buyer-controlled secrets in the local MCP process environment:

KRONOS_X402_EVM_PRIVATE_KEY=0x...
KRONOS_X402_SOLANA_PRIVATE_KEY=...

Use a dedicated agent wallet with only the USDC that its operator chooses to fund. Do not commit these values, add them to shared MCP configuration, send them to Kronos, or expect Kronos to create, fund, recover, or custody the wallet. The MCP has no restrictive daily spending limit; API prices and GPU rate limits remain the source of truth.

Operator spending cap

Set KRONOS_MAX_PAYMENT_USD to enforce a global per-call ceiling on every payment, independent of the per-tool caps hardcoded in the package. The effective cap for each call is min(per_tool_cap, global_cap). Set to 0 or unset to disable (default).

KRONOS_MAX_PAYMENT_USD=0.05  # reject any single payment above $0.05

This protects the operator even if a future server pricing bug or catalog change requests an unexpectedly high amount.

Configure an MCP host

Example Claude Code/Cursor-style configuration:

{
  "mcpServers": {
    "kronos": {
      "command": "npx",
      "args": ["-y", "@seshat_oracle/kronos-mcp"]
    }
  }
}

For the eventual Seshat integration, keep kronos-mcp as a focused compatibility package and compose it into a broader seshat-mcp server with namespaced tools (kronos_*, seshat_*). This avoids coupling Kronos releases to account/write capabilities while giving users one Seshat entry point when they need both.

Security — private key handling

The MCP signs x402 payments locally using a wallet private key in the process environment. This is the core security property: the key never leaves the operator's machine and is never sent to Kronos.

Inherent risk: npx -y kronos-mcp executes third-party code with access to process.env. If the npm package were ever compromised, an attacker could read the private key. This risk is inherent to any MCP that signs payments — it is not specific to kronos-mcp.

Mitigations in this package:

  • No install scripts. No postinstall, preinstall, or install hooks in this package or its dependencies.
  • Minimal tarball. 7 files, ~8 KB. The files allowlist in package.json ensures only src/, test/, and README.md are published — no stray files can slip in.
  • Pinned versions. All dependencies are pinned to exact versions (no ^ or ~ ranges) to prevent transitive dependency substitution.
  • Dynamic import. Payment dependencies (@x402/evm, @x402/svm, viem, @solana/kit, @scure/base) are loaded lazily only when a private key is configured. Free-only usage never loads them.
  • No network calls except to the Kronos API. The client only connects to https://kronos.seshat.markets (hardcoded origin allowlist). No telemetry, no analytics, no phone-home. KRONOS_API_URL can override the base URL, but the origin is validated against the allowlist — any non-allowed origin is rejected before any request is made.
  • Payment authorization. Before signing any payment, the MCP validates the 402 challenge: network must be Solana mainnet or Base mainnet, asset must be USDC, payTo must be a Kronos server wallet, and the resource URL origin must match the requested origin. If any check fails, payment is aborted. These allowlists are hardcoded — not configurable via env vars — so a compromised server cannot redirect payments to arbitrary recipients.
  • Prompt injection defense. Every tool response is prefixed with a data framing marker that tells the consuming agent to treat the content as market intelligence data, not as instructions. This is defense-in-depth: the server already sanitizes external content (news, social sentiment) before generating AI briefs, but the MCP adds a second layer at the protocol level.

Recommendations for operators:

  • Use a dedicated agent wallet with only the USDC you are willing to spend.
  • Enable 2FA on your npm account if you are the package maintainer.
  • Prefer npm Trusted Publishing (OIDC) from GitHub Actions over long-lived publish tokens.
  • Pin the package version in your MCP config: npx -y @seshat_oracle/[email protected] instead of floating latest.
  • Audit the installed package: npm view @seshat_oracle/kronos-mcp dist.tarball and inspect the tarball before trusting it with a funded wallet.