npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@true402.dev/agentkit

v1.4.2

Published

true402 actions for Coinbase AgentKit — pay-per-call on-chain rug/honeypot & address safety plus backlink/keyword SEO data for Base AI agents over x402 (USDC, no account, no API key).

Readme

@true402.dev/agentkit

npm version   Stable · production-ready — semver-stable public API (v1.0).

true402 actions for Coinbase AgentKit — give your Base agent pay-per-call on-chain safety and search/SEO data over x402: rug/honeypot checks, address safety, and deployer reputation, plus backlink profiles and keyword research. No account, no API key — the wallet is the identity (USDC on Base, gas sponsored by the facilitator).

npm i @true402.dev/agentkit @coinbase/agentkit
import { AgentKit } from '@coinbase/agentkit';
import { createTrue402ActionProviders } from '@true402.dev/agentkit';

const agentKit = await AgentKit.from({
  walletProvider, // your configured WalletProvider (Base)
  actionProviders: createTrue402ActionProviders({
    payerPrivateKey: process.env.PAYER_PRIVATE_KEY!,
  }),
});
// → surface to your LLM with getLangChainTools(agentKit) or getVercelAITools(agentKit)

The agent can now call, before it trades:

| Action | What it does | ~price | |---|---|---| | true402_token_report | Primary — pre-trade gate. Composite avoid / caution / ok verdict for a Base ERC-20 (buy/sell honeypot sim + liquidity + ownership + deployer) | $0.01 | | true402_token_safety | Structural safety score 0–100 + flags | $0.005 | | true402_address_safety | Profile + risk for any address before you send/approve/call it (proxy detection) | $0.005 | | true402_tx_preflight | Check an unsigned transaction before signing: does it revert, does it grant an unlimited approval, has the counterparty been draining liquidity. Takes no key and no signature | $0.008 | | true402_liquidity_history | What already happened to a token's liquidity — every removal with amount/block/tx, plus the tokens drained in the same transaction | $0.005 | | true402_deployer_check | Deployer reputation — who made the token + their track record | $0.008 | | true402_backlinks | A domain's backlink profile — referring domains/pages, dofollow split, authority rank, spam score | $0.10 | | true402_keyword_volume | Search volume/CPC/competition for up to 200 keywords in one call — priced per call, not per keyword | $0.15 | | true402_ranked_keywords | Keywords a domain already ranks for, with position and the ranking URL — self-audit or competitor research | $0.05 | | true402_keyword_ideas | Related/long-tail keyword ideas for a seed term, with volume and search intent | $0.05 |

These are built with AgentKit's customActionProvider (function form), so there are no decorators and no tsconfig changes. Each action's invoke ignores the walletProvider — payment is signed inside the bundled x402 payer using payerPrivateKey — and returns a JSON string.

payerPrivateKey is a Base wallet holding a little USDC. Payments are signed with EIP-3009; the client refuses to sign anything that isn't USDC-on-Base or exceeds maxAmountUsd (default 0.25, above the server's own $0.20 per-request ceiling so a legitimately-priced stall is never blocked). Safety stalls have a small free daily trial, so a call may return 200 without paying. Override baseUrl / rpcUrl in the options if self-hosting.

FAQ

Which action should the agent call before buying a token? true402_token_report — the composite avoid/caution/ok verdict. It is the pre-trade gate and is listed first.

How does it differ from a static scanner? true402 runs a real on-chain buy/sell honeypot simulation (state-override eth_call), so it proves sellability rather than only reading contract bytecode.

Do I need an account or API key? No. The wallet is the identity. Payment is per-call over x402 (USDC on Base); the facilitator sponsors gas.

Do I need experimentalDecorators in tsconfig? No. This package uses the customActionProvider function form, not the @CreateAction class form, so no decorator settings are required.

What stops a rogue endpoint from draining the payer? The bundled payer only signs a USDC-on-Base charge within maxAmountUsd (default $0.25) and checks the payer balance first; anything else is refused.

Checking tokens by hand? Send any Base token address to @True402bot on Telegram — same on-chain checks, free, no wallet.

Powered by true402 — the machine-native x402 marketplace on Base. Browse every stall at /catalog.

Also available for

MCP (Claude Code / Desktop, Cursor, Hermes) · Hermes Agent · OpenClaw · ElizaOS · LangChain · CrewAI · Vercel AI SDK · Coinbase AgentKit · Virtuals GAME · CLI — same on-chain checks, one install command each: true402.dev/integrations

Paying, exactly

The rules below are the service's, not this package's — they bite whatever client you use, and they are the ones that surprise people writing their own payer.

  • Pay the EXACT amount quoted in the 402. Underpaying is rejected. Overpaying is refused with 403 and never credited — settlement submits the signed value and there is no refund path, so a surplus would simply be swept. Equality is also what binds an authorization to the resource it was quoted for.
  • One authorization buys exactly one response. A replay is refused, not double-charged.
  • You are charged on success only. Settlement is submitted only when the endpoint returns 2xx; if it errors or times out, your signed authorization is never submitted, so there is nothing to refund.
  • Some endpoints serve a few free calls per day per client IP, with no wallet. The per-operation description in the OpenAPI spec says which.

Full rules: true402.dev/terms · what is logged and kept: true402.dev/privacy