M2M Sentinel

io.github.M2M-Sentinelv1.2.5更新於 Oct 10, 2026

Base bytecode capability observations, proxy resolution, gas, DEX, and transfer telemetry.

已驗證Streamable HTTP可網頁執行Developer ToolsSecurity & MonitoringFinance

概覽

AI 產生的概覽

讓助理檢查 Base/EVM 合約位元碼的可執行能力、代理解析、gas、DEX 與轉帳遙測資料。

功能
M2M Sentinel 提供 Base 上合約的確定性 EVM 位元碼觀測結果。它會回報代理解析情形(合約是否為代理及其目標位址)、附解剖證據的可執行能力判定,以及 gas、DEX 和轉帳遙測資料。它以 MCP 伺服器、JavaScript/TypeScript 與 Python 用戶端,以及 Coinbase AgentKit 動作提供者的形式提供;SDK 另含一個守衛輔助函式,依呼叫方自有原則預檢 Base Account 的 EIP-5792 批次呼叫。
適用情境
當助理或代理需要確認某個 Base 合約實際能執行什麼、把代理解析到其實作位址,或在採取行動前蒐集位元碼層級的遙測資料時適用。也適合想為 Base Account 批次呼叫加上原則檢查邊界的代理。
執行需求
可作為遠端 streamable HTTP 端點執行,也可透過 npm 套件以 stdio 在本機執行(需要 Node.js)。選用憑證:用於預付存取的 M2M_SENTINEL_API_KEY 環境變數或 x-api-key 標頭,以及重試需付費的 x402 v2 呼叫時的 PAYMENT-SIGNATURE 標頭。即時觀測需要連線至 M2M Sentinel API 的網路存取。
安裝前請注意
選用的 M2M_SENTINEL_API_KEY、x-api-key 與 PAYMENT-SIGNATURE 都是機密,應透過環境變數或標頭提供,切勿寫死在程式碼中。x402 微支付流程可能從呼叫方提供的錢包簽署器支出資金。守衛輔助函式不簽署、不廣播、不保管資金,也不作安全性聲明,交易原則由呼叫方負責;文件中的範例除非明確啟用即時模式,否則僅為模擬。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 M2M Sentinel,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "m2m-sentinel-sdk": {
      "type": "http",
      "url": "https://api.m2msentinel.com/mcp"
    }
  }
}

README

M2M Sentinel SDK & MCP Server

Official multi-language client library, Model Context Protocol (MCP) server, and Coinbase AgentKit ActionProvider for M2M Sentinel — deterministic EVM bytecode capability observations and common-proxy resolution for autonomous applications operating on Base. Callers own transaction policy.

[npm version] [PyPI version] [License: MIT] [Smithery]


⚡ 1. Model Context Protocol (MCP) Server

Connect M2M Sentinel directly to Claude Desktop, Cursor, Windsurf, or any MCP-compliant LLM agent.

Option A: 1-Click via Smithery

bash
npx -y @smithery/cli mcp add M2M-Sentinel/m2m-sentinel-sdk --client claude

Option B: Local Stdio (claude_desktop_config.json)

json
{  "mcpServers": {    "m2m-sentinel": {      "command": "npx",      "args": ["-y", "m2m-sentinel-sdk"],      "env": {        "M2M_SENTINEL_API_KEY": ""      }    }  }}

Option C: Remote Streamable HTTP

  • Current MCP endpoint: https://api.m2msentinel.com/mcp
  • Legacy HTTP+SSE compatibility: https://api.m2msentinel.com/sse with messages at https://api.m2msentinel.com/messages

🤖 2. Coinbase AgentKit Integration

typescript
import { AgentKit } from "@coinbase/agentkit";import { m2mSentinelActionProvider } from "m2m-sentinel-sdk";
const agentKit = await AgentKit.from({  walletProvider,  actionProviders: [    m2mSentinelActionProvider({      apiKey: process.env.M2M_SENTINEL_API_KEY    })  ]});

📦 3. JavaScript / TypeScript Client

bash
npm install m2m-sentinel-sdk
javascript
const { M2MSentinelClient } = require('m2m-sentinel-sdk');
const client = new M2MSentinelClient();
async function main() {  const audit = await client.auditContract('0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913');  console.log('Proxy Detected:', audit.audit.proxyResolution.isProxy);  console.log('Proxy Target:', audit.audit.proxyResolution.targetAddress);  console.log('Capabilities:', audit.audit.verdict.executableCapabilities);  console.log('Evidence:', audit.audit.dissection.capabilities);}
main().catch(console.error);

🛡️ Base Account wallet_sendCalls Guard

The public SDK includes guardWalletSendCalls, a customer-side execution-identity boundary for Base Account / EIP-5792 batches. It preflights the anchor call and evaluates its caller policy before scheduling any remaining call, then pins remaining calls to the first trusted block identity in waves of at most four. Each settled wave is validated and policy-checked in ascending request-index order before a later wave starts; a failure or rejection stops later scheduling. The original detached request is forwarded only after all checks pass. It does not sign, broadcast, custody funds, infer inner UserOperation semantics, or make a safety claim. See examples/base_account_paymaster_guard.js for a no-network fixture.


🐍 4. Python Client

bash
pip install m2m-sentinel
python
from m2m_sentinel import M2MSentinelClient
client = M2MSentinelClient()audit = client.audit_contract("0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913")print("Proxy detected:", audit["audit"]["proxyResolution"]["isProxy"])print("Proxy target:", audit["audit"]["proxyResolution"].get("targetAddress"))print("Capabilities:", audit["audit"]["verdict"]["executableCapabilities"])print("Evidence:", audit["audit"]["dissection"]["capabilities"])

Transaction-specific preflight example

The public repository includes a standalone, mock-only transaction boundary example at examples/transaction_preflight.js. From this repository root, run:

bash
node examples/transaction_preflight.js

It observes one caller-supplied Base transaction, passes the observation to a caller-owned policy, and reaches only a mock signing/send callback. It refuses to continue on unverified evidence, unresolved execution, an observation mismatch, or a missing Diamond selector mapping. It never signs or sends a transaction; optional live mode uses only a caller-supplied API-key header and remains the caller's responsibility.


💳 5. Autonomous x402 Micropayments (Headless M2M)

typescript
import { x402SignerClient } from "m2m-sentinel-sdk";
const client = new x402SignerClient({  walletSigner: myAgentWallet,  baseUrl: "https://api.m2msentinel.com"});
const result = await client.request("/v1/audit/0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913");

📜 License

MIT License. Copyright (c) 2026 M2M Sentinel.

來源:README.md,提交 becb3f7

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v1.2.5最新Sep 16, 2026