{"_id":"@bytexbyte/nxtlinq-attest","name":"@bytexbyte/nxtlinq-attest","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@bytexbyte/nxtlinq-attest","version":"1.0.0","description":"Agent signing and verification for nxtlinq attest; runs entirely locally","type":"module","main":"dist/runtime.js","types":"dist/runtime.d.ts","exports":{".":{"types":"./dist/runtime.d.ts","import":"./dist/runtime.js","default":"./dist/runtime.js"}},"bin":{"nxtlinq-attest":"bin/nxtlinq-attest.mjs"},"scripts":{"build":"tsc","prepare":"npm run build"},"keywords":["nxtlinq","attest","agent","signing","verification"],"license":"MIT","repository":{"type":"git","url":"git+https://github.com/nxtlinqit/nxtlinq-attest.git"},"bugs":{"url":"https://github.com/nxtlinqit/nxtlinq-attest/issues"},"homepage":"https://github.com/nxtlinqit/nxtlinq-attest#readme","engines":{"node":">=22"},"publishConfig":{"access":"public"},"devDependencies":{"@types/node":"^20.0.0","typescript":"^5.0.0"},"_id":"@bytexbyte/nxtlinq-attest@1.0.0","gitHead":"191bee4fdabb8484bcae81a4b02e528045c44fa7","_nodeVersion":"22.15.0","_npmVersion":"10.9.2","dist":{"integrity":"sha512-ap1wSKYd+qmAeo+ZucpFEsMxApNI91hZXXulbD9WKTd+HP4NOEqY8sSh1KC+3O9eEGC8dNGC8Al+dnbE/ye2EA==","shasum":"cd4edb375314749cdaa745a6d72f33c6955e705e","tarball":"https://registry.npmjs.org/@bytexbyte/nxtlinq-attest/-/nxtlinq-attest-1.0.0.tgz","fileCount":29,"unpackedSize":27250,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIGfBIxgKx97xZCVnRP+U+/XN6uNINMWOInFOP6zrqALYAiAO6jlZ6yeo8SzgcqGl7KpOJHZfVGjnwmPbSQxdGrxeUQ=="}]},"_npmUser":{"name":"matt.k","email":"matt.k@mydailylive.com"},"directories":{},"maintainers":[{"name":"jamesliao77","email":"james.l@mydailylive.com"},{"name":"mydailylivepeter","email":"peter.t@mydailylive.com"},{"name":"hsuchi","email":"robin.h@mydailylive.com"},{"name":"jabo1209","email":"jabo.y@mydailylive.com"},{"name":"roger.c","email":"roger.c@mydailylive.com"},{"name":"matt.k","email":"matt.k@mydailylive.com"},{"name":"kacykuo","email":"kacykuo@gmail.com"},{"name":"berifynpm","email":"berifynpm@berify.io"},{"name":"stephen.h","email":"stephen.h@mydailylive.com"},{"name":"thomas1201","email":"thomas.c@mydailylive.com"},{"name":"vincent.c","email":"vincent.c@mydailylive.com"},{"name":"tf00185077","email":"tf00185077@gmail.com"},{"name":"a6232241","email":"chester.c@mydailylive.com"},{"name":"wings.h","email":"wings.h@mydailylive.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/nxtlinq-attest_1.0.0_1773222854620_0.5480589950081429"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-11T09:54:14.544Z","1.0.0":"2026-03-11T09:54:14.768Z","modified":"2026-03-11T09:54:15.082Z"},"maintainers":[{"name":"jamesliao77","email":"james.l@mydailylive.com"},{"name":"mydailylivepeter","email":"peter.t@mydailylive.com"},{"name":"hsuchi","email":"robin.h@mydailylive.com"},{"name":"jabo1209","email":"jabo.y@mydailylive.com"},{"name":"roger.c","email":"roger.c@mydailylive.com"},{"name":"matt.k","email":"matt.k@mydailylive.com"},{"name":"kacykuo","email":"kacykuo@gmail.com"},{"name":"berifynpm","email":"berifynpm@berify.io"},{"name":"stephen.h","email":"stephen.h@mydailylive.com"},{"name":"thomas1201","email":"thomas.c@mydailylive.com"},{"name":"vincent.c","email":"vincent.c@mydailylive.com"},{"name":"tf00185077","email":"tf00185077@gmail.com"},{"name":"a6232241","email":"chester.c@mydailylive.com"},{"name":"wings.h","email":"wings.h@mydailylive.com"}],"description":"Agent signing and verification for nxtlinq attest; runs entirely locally","homepage":"https://github.com/nxtlinqit/nxtlinq-attest#readme","keywords":["nxtlinq","attest","agent","signing","verification"],"repository":{"type":"git","url":"git+https://github.com/nxtlinqit/nxtlinq-attest.git"},"bugs":{"url":"https://github.com/nxtlinqit/nxtlinq-attest/issues"},"license":"MIT","readme":"# @bytexbyte/nxtlinq-attest\n\nAgent signing and verification for nxtlinq attest; runs entirely locally (no blockchain, no external service).\n\n## Install\n\n### From npm (after publish)\n\n```bash\nnpm install -g @bytexbyte/nxtlinq-attest\n```\n\nThen run: `nxtlinq-attest init`, `nxtlinq-attest sign`, `nxtlinq-attest verify`.\n\n### From source (repo)\n\n```bash\ncd nxtlinq-attest\nnpm install\nnpm run build\n```\n\n**Option A — run via node (no global install):**\n\n```bash\nnode bin/nxtlinq-attest.mjs <command>\n# e.g. node bin/nxtlinq-attest.mjs init\n```\n\n**Option B — install globally from this repo:**\n\n```bash\nnpm link\n```\n\nThen from any directory: `nxtlinq-attest init`, `nxtlinq-attest sign`, `nxtlinq-attest verify`.\n\n**Requirements:** Node 22+\n\n## Runtime API (for Agent apps)\n\nInstall as a dependency in your Agent project to read attested scope at runtime (no need to implement file read yourself):\n\n```bash\nnpm install @bytexbyte/nxtlinq-attest\n# or before publish: npm install file:../nxtlinq-attest\n```\n\n```ts\nimport { getAttestScope, isToolInAttestScope } from '@bytexbyte/nxtlinq-attest';\n\nconst scope = getAttestScope();           // from nxtlinq/agent.manifest.json (cached by cwd)\nif (!isToolInAttestScope(toolName)) {\n  // deny: tool not in attested scope\n}\n```\n\n- `getAttestScope(cwd?)` — returns `scope` array; `[]` if no manifest. Cached per cwd.\n- `isToolInAttestScope(toolName, cwd?)` — true if tool is in scope or scope is empty (backward compatible).\n\n**Node only.** For **Python or any language**, use the **CLI** instead: run `nxtlinq-attest scope` from the agent project root; it prints the scope array as JSON to stdout (exit 0). Parse stdout once at startup and cache; use it to allow/deny tools. Same CLI works for Node if you prefer not to depend on the package.\n\nFor more detail, see the product spec (view via [README-SPEC.md](README-SPEC.md)).\n\n## Commands\n\n| Command | Description |\n|---------|-------------|\n| `nxtlinq-attest init` | Create `nxtlinq/` with keys and `agent.manifest.json` |\n| `nxtlinq-attest sign` | Compute contentHash + artifactHash, sign manifest, write `nxtlinq/agent.manifest.sig` |\n| `nxtlinq-attest verify` | Verify manifest and artifact integrity (exit 1 on failure) |\n| `nxtlinq-attest scope` | Print manifest scope as JSON to stdout (for any runtime to call) |\n\n## Quick start\n\n```bash\ncd your-agent-project\nnxtlinq-attest init\n# Edit nxtlinq/agent.manifest.json (name, version, scope)\nnxtlinq-attest sign\nnxtlinq-attest verify\n```\n\n## After init: what to edit in `nxtlinq/agent.manifest.json`\n\n| Field | You edit? | Description |\n|-------|-----------|-------------|\n| **name** | Yes | Agent identifier (e.g. `\"my-agent\"`, `\"nxtlinq-ai-agent\"`). |\n| **version** | Yes | Semantic version of this agent (e.g. `\"1.0.0\"`). |\n| **scope** | Yes | List of tools/permissions this agent is allowed to use. Each item is a string like `\"tool:ToolName\"`. Example: `[\"tool:ExampleTool\", \"tool:Search\"]`. |\n| **issuedAt** | Optional | Unix timestamp when the manifest was created. Init sets this; you can leave it or update it. |\n| **publicKey** | No | Filled by init. Do not edit. |\n| **contentHash** | No | Set by `sign`. Do not edit. |\n| **artifactHash** | No | Set by `sign`. Do not edit. |\n\n**Summary:** Before running `sign`, edit **name**, **version**, and **scope** to match your agent. Do not change `contentHash`, `artifactHash`, or `publicKey`. All attest files live under `nxtlinq/`.\n\n## Requirements\n\n- Node 22+\n- Works offline; no wallet. Verification fails (exit 1) on tampered manifest or artifact.\n\n## Files (all under `nxtlinq/`)\n\n- `nxtlinq/agent.manifest.json` — Agent declaration (name, version, scope, hashes). Do not edit `contentHash` / `artifactHash`; they are set by `sign`.\n- `nxtlinq/agent.manifest.sig` — Signature (hex). Created by `sign`.\n- `nxtlinq/private.key` — **Do not commit.** Used by `sign`.\n- `nxtlinq/public.key` — Public key for verification.\n\n## Spec and docs\n\n- Product spec (with diagrams): run `cd docs && npx serve .` then open http://localhost:3000/ (see `README-SPEC.md`). Single entry with 中文 / English switch. Source: `docs/spec/nxtlinq-attest-product-spec.md`, `docs/spec/nxtlinq-attest-product-spec.en.md`.\n- `README-SPEC.md` — How to view the spec.\n","readmeFilename":"README.md","_rev":"1-629db51a88dc5565cdc6b203a45a6a9e"}