Server data from the Official MCP Registry
Local agent spend-policy checks. No funds, keys, payment authority, or network access.
About
Local agent spend-policy checks. No funds, keys, payment authority, or network access.
Security Report
Valid MCP server (2 strong, 3 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry.
5 files analyzed · 1 issue found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-dingdawg-agent-spend-policy-mcp": {
"args": [
"-y",
"@dingdawg/agent-spend-policy-mcp"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
DingDawg Agent Spend Policy MCP
A small, local MCP server that deterministically evaluates whether a proposed agent spend action matches a supplied policy.
It returns one of ELIGIBLE, DENY, or STEP_UP, with a stable reason code.
ELIGIBLE is local policy evidence only. It is not payment authorization.
Safety boundary
This package does not hold funds, private keys, payment credentials, customer data, or settlement authority. It does not sign, send, settle, custody, or record payments. It makes no network requests.
A production payment adapter needs separate, independently verified controls for authenticated policy/action provenance, canonical payload hashing, durable atomic budget reservation and replay protection, customer-controlled signing, rail validation, and settlement reconciliation.
Install
npx -y @dingdawg/agent-spend-policy-mcp
Configure it as a local stdio MCP server:
{
"mcpServers": {
"dingdawg-agent-spend-policy": {
"command": "npx",
"args": ["-y", "@dingdawg/agent-spend-policy-mcp"]
}
}
}
Tool
evaluate_spend_policy accepts an evaluation time, a policy, a proposed action,
and the already-spent amount. All money is passed as integer micro-unit strings,
never JavaScript floating-point numbers.
The caller supplies the clock and already-spent value; therefore this tool is safe for dry runs and local evidence, not a replacement for a trusted payment or accounting system.
Agent contract
The versioned machine-readable contract is
capabilities.json. It describes the only tool this
package exposes, its required inputs, its three possible outcomes, and its
non-negotiable safety boundary.
- Transport: local stdio MCP
- Tool:
evaluate_spend_policy - Required inputs:
evaluationTime,policy,action, andalreadySpentMicros - Outputs:
ELIGIBLE,DENY, orSTEP_UP, each with a stable reason code - Side effects: none
- Credentials, payment execution, custody, signing, settlement, and network access: not supported
The manifest is package-source evidence for this release, not a promise of a
hosted agent-discovery endpoint. ELIGIBLE remains local policy evidence only,
not payment authorization.
Development
npm install
npm test
npm run pack:check
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
FinAgent
Freeby mcp-marketplace · Finance
Free stock data and market news for any MCP-compatible AI assistant.
