MCPLow riskUnclaimed

AgentGuard

Local spend caps, kill-switch blocking and Ed25519-signed receipts for AI agent tool calls.

MerchantGuardmerchantguard/agentguardUpdated Sep 21, 2026

server.json

{
  "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
  "name": "io.github.MerchantGuard/agentguard",
  "description": "Local spend caps, kill-switch blocking and Ed25519-signed receipts for AI agent tool calls.",
  "title": "AgentGuard",
  "repository": {
    "url": "https://github.com/MerchantGuard/agentguard-mcp",
    "source": "github"
  },
  "version": "0.3.1",
  "websiteUrl": "https://agentguard.run",
  "packages": [
    {
      "registryType": "npm",
      "identifier": "@agentguard-run/mcp",
      "version": "0.3.1",
      "runtimeHint": "npx",
      "transport": {
        "type": "stdio"
      },
      "environmentVariables": [
        {
          "description": "Local daily spend cap in cents. A nonnegative integer.",
          "format": "number",
          "default": "500",
          "name": "AGENTGUARD_MCP_DAILY_CAP_CENTS"
        },
        {
          "description": "Local per-call spend cap in cents. A nonnegative integer.",
          "format": "number",
          "default": "100",
          "name": "AGENTGUARD_MCP_PER_CALL_CAP_CENTS"
        },
        {
          "description": "Tenant identifier stamped into local receipts.",
          "format": "string",
          "default": "mcp-local",
          "name": "AGENTGUARD_MCP_TENANT"
        },
        {
          "description": "Local signing-key, configuration and ledger directory. Defaults to .agentguard in the operating system home directory.",
          "format": "filepath",
          "name": "AGENTGUARD_HOME"
        },
        {
          "description": "Local decision storage. ndjson persists receipts across restarts; memory retains this process only.",
          "format": "string",
          "default": "ndjson",
          "choices": [
            "ndjson",
            "memory"
          ],
          "name": "AGENTGUARD_MCP_LEDGER"
        },
        {
          "description": "Set to 1 to discard and prevent model pricing overrides for this server.",
          "format": "string",
          "default": "0",
          "choices": [
            "0",
            "1"
          ],
          "name": "AGENTGUARD_MCP_DISABLE_COST_OVERRIDE"
        },
        {
          "description": "Spend SDK startup lock. Set to 1 to prevent model pricing overrides.",
          "format": "string",
          "default": "0",
          "choices": [
            "0",
            "1"
          ],
          "name": "AGENTGUARD_LOCK_COST_OVERRIDES"
        },
        {
          "description": "Set to 1 to hash actor identifiers before they enter local receipts.",
          "format": "string",
          "default": "0",
          "choices": [
            "0",
            "1"
          ],
          "name": "AGENTGUARD_ACTOR_DIGEST"
        },
        {
          "description": "Optional AgentGuard license key for license validation and seat registration. Otherwise read from local configuration.",
          "format": "string",
          "isSecret": true,
          "name": "AGENTGUARD_LICENSE_KEY"
        },
        {
          "description": "License and seat service base URL. No prompts, tool content or receipts are sent.",
          "format": "string",
          "default": "https://agentguard.run",
          "name": "AGENTGUARD_LICENSE_ENDPOINT"
        },
        {
          "description": "Set to 1 to disable optional activation telemetry regardless of saved consent.",
          "format": "string",
          "default": "0",
          "choices": [
            "0",
            "1"
          ],
          "name": "AGENTGUARD_NO_BEACON"
        },
        {
          "description": "Set to 1 to opt in to content-free activation telemetry. Otherwise saved consent applies, default off.",
          "format": "string",
          "default": "0",
          "choices": [
            "0",
            "1"
          ],
          "name": "AGENTGUARD_TELEMETRY"
        },
        {
          "description": "Optional identifier used only by opted-in activation telemetry when no saved install identifier exists.",
          "format": "string",
          "name": "AGENTGUARD_INSTALL_ID"
        },
        {
          "description": "Legacy fallback for AGENTGUARD_INSTALL_ID in opted-in activation telemetry.",
          "format": "string",
          "name": "AGENTGUARD_ANONYMOUS_INSTALL_ID"
        },
        {
          "description": "Existing runtime marker. A nonempty value marks opted-in activation telemetry as CI; it does not enable telemetry.",
          "format": "string",
          "name": "CI"
        },
        {
          "description": "Existing runtime marker. A nonempty value marks opted-in activation telemetry as CI; it does not enable telemetry.",
          "format": "string",
          "name": "GITHUB_ACTIONS"
        },
        {
          "description": "Existing runtime marker. A nonempty value marks opted-in activation telemetry as CI; it does not enable telemetry.",
          "format": "string",
          "name": "GITLAB_CI"
        },
        {
          "description": "Existing runtime marker. A nonempty value marks opted-in activation telemetry as CI; it does not enable telemetry.",
          "format": "string",
          "name": "CIRCLECI"
        },
        {
          "description": "Existing runtime marker. A nonempty value marks opted-in activation telemetry as CI; it does not enable telemetry.",
          "format": "string",
          "name": "BUILDKITE"
        },
        {
          "description": "Existing runtime marker. A nonempty value marks opted-in activation telemetry as CI; it does not enable telemetry.",
          "format": "string",
          "name": "VERCEL"
        },
        {
          "description": "Existing runtime marker. A nonempty value marks opted-in activation telemetry as CI; it does not enable telemetry.",
          "format": "string",
          "name": "NETLIFY"
        }
      ]
    }
  ],
  "_meta": {
    "io.modelcontextprotocol.registry/publisher-provided": {
      "description": "Local spend caps, kill-switch blocking and Ed25519-signed receipts for AI agent tool calls. Runs on the developer's machine. Zero data plane: prompts and tool calls never pass through this server."
    }
  }
}

Permissions

DeclaredDetected
Runs code—node
Installs—npm:@agentguard-run/mcp@0.3.1
Runs install scripts—None
NetworkNoneNone
Needs credentialsAGENTGUARD_LICENSE_KEYAGENTGUARD_LICENSE_KEY
Outside the workspace—None
Agent tools—None

Checks

Low risk · Nothing worth a warning was found.

Not reviewed by a person · Checked by rules; the model review is not switched on yet.

Versions

  1. #10.3.1latestOct 7, 2026