Local agent spend-policy checks. No funds, keys, payment authority, or network access.
MCPpedia last refreshed this data
io.github.dingdawg/agent-spend-policy-mcp is an MCP server that local agent spend-policy checks. No funds, keys, payment authority, or network access. Its tool list has not been published yet over stdio and sse, requires no API key, and scores 87/100 on MCPpedia's security, maintenance and efficiency rubric.
Config is the same across clients — only the file and path differ.
{
"mcpServers": {
"dingdawg-agent-spend-policy": {
"args": [
"-y",
"@dingdawg/agent-spend-policy-mcp"
],
"command": "npx"
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
A small, local MCP server that deterministically evaluates whether a proposed agent spend action matches a supplied policy.
Run this in your terminal to verify the server starts. Then let us know if it worked — your result helps other developers.
npx -y '@dingdawg/agent-spend-policy-mcp' 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
Five weighted categories — click any category to see the underlying evidence.
No known CVEs.
Checked @dingdawg/agent-spend-policy-mcp against OSV.dev.
Click any tool to inspect its schema.
Be the first to review
Have you used this server?
Share your experience — it helps other developers decide.
Sign in to write a review.
Others in finance
Real-time financial market data: stocks, forex, crypto, commodities, and economic indicators
HoneyBook client-portal MCP server for Claude — view contracts and invoices from wedding vendors
Self-custody Ethereum agent wallet (MCP/stdio). Keys stay in a local Docker volume.
MCP server for QuickBooks Online — accounts, customers, invoices, bills, and reports.
MCP Security Weekly
Get CVE alerts and security updates for io.github.dingdawg/agent-spend-policy-mcp and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.
A small, local MCP server that deterministically evaluates whether a proposed agent spend action matches a supplied policy.
It returns one of ELIGIBLE, DENY, or STEP_UP, with a stable reason code.
ELIGIBLE is local policy evidence only. It is not payment authorization.
This package does not hold funds, private keys, payment credentials, customer data, or settlement authority. It does not sign, send, settle, custody, or record payments. It makes no network requests.
A production payment adapter needs separate, independently verified controls for authenticated policy/action provenance, canonical payload hashing, durable atomic budget reservation and replay protection, customer-controlled signing, rail validation, and settlement reconciliation.
npx -y @dingdawg/agent-spend-policy-mcp
Configure it as a local stdio MCP server:
{
"mcpServers": {
"dingdawg-agent-spend-policy": {
"command": "npx",
"args": ["-y", "@dingdawg/agent-spend-policy-mcp"]
}
}
}
evaluate_spend_policy accepts an evaluation time, a policy, a proposed action,
and the already-spent amount. All money is passed as integer micro-unit strings,
never JavaScript floating-point numbers.
The caller supplies the clock and already-spent value; therefore this tool is safe for dry runs and local evidence, not a replacement for a trusted payment or accounting system.
The versioned machine-readable contract is
capabilities.json. It describes the only tool this
package exposes, its required inputs, its three possible outcomes, and its
non-negotiable safety boundary.
evaluate_spend_policyevaluationTime, policy, action, and
alreadySpentMicrosELIGIBLE, DENY, or STEP_UP, each with a stable reason codeThe manifest is package-source evidence for this release, not a promise of a
hosted agent-discovery endpoint. ELIGIBLE remains local policy evidence only,
not payment authorization.
npm install
npm test
npm run pack:check