{"_id":"@allen-saji/praxis","name":"@allen-saji/praxis","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@allen-saji/praxis","version":"0.1.0","description":"Security, simulation, and audit layer for AI agent spending on Sui. Simulate before you sign, explain after you spend.","type":"module","license":"MIT","author":{"name":"Allen Saji","email":"allensaji04@gmail.com","url":"https://allensaji.dev"},"homepage":"https://github.com/Allen-Saji/praxis#readme","repository":{"type":"git","url":"git+https://github.com/Allen-Saji/praxis.git","directory":"packages/sdk"},"bugs":{"url":"https://github.com/Allen-Saji/praxis/issues"},"keywords":["sui","ai-agents","agent-security","wallet-security","transaction-simulation","risk-engine","walrus","seal","audit-trail","web3"],"sideEffects":false,"main":"./dist/index.cjs","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"}},"publishConfig":{"access":"public"},"scripts":{"build":"tsup","typecheck":"tsc --noEmit","test":"vitest run","prepublishOnly":"npm run build"},"dependencies":{"@mysten/sui":"^2.18.0","@mysten/walrus":"^1.2.0","@noble/hashes":"^2.2.0"},"devDependencies":{"@types/node":"^25.9.3","tsup":"^8.5.1","typescript":"^5.9.3","vitest":"^4.1.9"},"_id":"@allen-saji/praxis@0.1.0","gitHead":"250ff73b8e998a3bb1c087e38b7478836a577c44","_nodeVersion":"23.11.0","_npmVersion":"11.3.0","dist":{"integrity":"sha512-4ftVzuXlYtBVHNTMgb4lJ6zVZ2e0FSRum6GPIX+zZlFEFoHKQPYgwK1duN1KLfse9y2eNjoi/MnkC6IdfAxyWA==","shasum":"0cee9f1a9ada12548a0d77cbbc2f8503d4683192","tarball":"https://registry.npmjs.org/@allen-saji/praxis/-/praxis-0.1.0.tgz","fileCount":8,"unpackedSize":192057,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCgabfDh3seBD83qqytTGd/IptbZHXVudiVNASxq0ge6QIgUTUl/mvM21mTQcAW754M68TDcVPPUVEc+VEyrZYyNmY="}]},"_npmUser":{"name":"allen-saji","email":"allentheone1@gmail.com"},"directories":{},"maintainers":[{"name":"allen-saji","email":"allentheone1@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/praxis_0.1.0_1782071631800_0.02854178589805212"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-21T19:53:51.613Z","0.1.0":"2026-06-21T19:53:51.927Z","modified":"2026-06-21T19:53:52.075Z"},"maintainers":[{"name":"allen-saji","email":"allentheone1@gmail.com"}],"description":"Security, simulation, and audit layer for AI agent spending on Sui. Simulate before you sign, explain after you spend.","homepage":"https://github.com/Allen-Saji/praxis#readme","keywords":["sui","ai-agents","agent-security","wallet-security","transaction-simulation","risk-engine","walrus","seal","audit-trail","web3"],"repository":{"type":"git","url":"git+https://github.com/Allen-Saji/praxis.git","directory":"packages/sdk"},"author":{"name":"Allen Saji","email":"allensaji04@gmail.com","url":"https://allensaji.dev"},"bugs":{"url":"https://github.com/Allen-Saji/praxis/issues"},"license":"MIT","readme":"# @allen-saji/praxis\n\nSecurity, simulation, and audit layer for AI agent spending on Sui.\n\n**Simulate before you sign, explain after you spend.**\n\nPraxis sits between an AI agent and its wallet. Before every spend it dry-runs\nthe transaction on Sui, risk-scores the result against a rule engine, and hands\nthe report back to the agent to confirm or abort. Only on proceed does the\nwallet sign. Every decision, including the ones it blocks, is written to Walrus\nwith a tamper-evident on-chain receipt.\n\nThree parties, clean separation:\n\n- **Agent** decides and holds no keys.\n- **Praxis** simulates, risk-scores, and gates.\n- **Wallet** signs only what Praxis forwards.\n\nThe novel part: the simulation and risk report flow back to the agent *before*\nsigning, so it can self-correct. No wallet provider or agent framework does this.\n\n## Install\n\n```bash\nnpm install @allen-saji/praxis @mysten/sui\n```\n\n## Quickstart\n\n```typescript\nimport { Praxis, KeypairAdapter } from \"@allen-saji/praxis\";\nimport { Ed25519Keypair } from \"@mysten/sui/keypairs/ed25519\";\n\nconst praxis = new Praxis({\n  network: \"testnet\",\n  wallet: new KeypairAdapter(Ed25519Keypair.fromSecretKey(process.env.KEY!)),\n});\n\nconst result = await praxis.spend({\n  to: recipient,\n  amount: 1_000_000_000n, // 1 SUI, in MIST\n  reasoning: { prompt, decision, model },\n});\n\n// result.status is \"confirmed\", \"aborted\", or \"policy_block\"\n```\n\n## The gate\n\nBy default Praxis proceeds only when the simulation recommends `proceed`. Pass\n`onReport` to inspect the report and decide for yourself:\n\n```typescript\nconst result = await praxis.spend({\n  to: recipient,\n  amount: 5_000_000_000n,\n  reasoning: { prompt, decision, model },\n  onReport: (report) => report.recommendation === \"proceed\",\n});\n\nif (result.status === \"aborted\") {\n  console.log(\"blocked:\", result.abortReason, result.simulationReport);\n}\n```\n\nA blocked spend never signs and never moves funds, and the block itself is\nlogged to Walrus and counted on-chain. That is the point: an auditor can prove\nwhat was stopped, not just what went through.\n\n## Reading the audit trail\n\n`PraxisReader` is a read-only view over the on-chain `AgentIndex` and the Walrus\nreasoning blobs. No wallet required.\n\n```typescript\nimport { PraxisReader } from \"@allen-saji/praxis\";\n\nconst reader = new PraxisReader({ network: \"testnet\" });\nconst stream = await reader.stream(50); // confirmed + aborted, interleaved\n```\n\n## Wallet adapters\n\n- `KeypairAdapter` wraps a Sui `Ed25519Keypair` for server-side agents.\n- `GenericAdapter` adapts any `{ address, signTransaction }` pair, so Praxis is\n  wallet-agnostic and never custodies a key itself.\n\n## What runs on Sui\n\n- `sui_dryRunTransactionBlock` for pre-flight simulation of every spend.\n- Walrus for the reasoning and simulation blobs (spends and blocks alike).\n- Move objects: `SpendingReceipt`, `AgentIndex`, `SpendingPolicy`.\n- The coin transfer, receipt creation, and index update happen atomically in one\n  programmable transaction block, so a receipt can never exist without its spend.\n\n## Scope\n\nv1 is testnet and SUI-denominated. The sealed-reasoning path uses a local\nencryption stand-in with the same shapes as Seal; swapping in Seal key servers\nis drop-in. Real wallet-provider adapters (Privy, Turnkey), multi-coin, and\nmainnet are post-v1.\n\n## License\n\nMIT\n","readmeFilename":"README.md","_rev":"1-9ce1efc232c64bd9882b4513b826a413"}