New:Socket for Asana Is Now Available.Learn more
Get Started

@dingdawg/agent-spend-policy-mcp

Package Overview
Dependencies
Maintainers
1
Versions
2
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@dingdawg/agent-spend-policy-mcp

A local, deterministic MCP evaluator for agent spend-policy eligibility. It never holds funds, keys, or payment credentials.

latest
Source
npmnpm
Version
0.1.1
Version published
Maintainers
1
Created
Source

DingDawg Agent Spend Policy MCP

A small, local MCP server that deterministically evaluates whether a proposed agent spend action matches a supplied policy.

It returns one of ELIGIBLE, DENY, or STEP_UP, with a stable reason code. ELIGIBLE is local policy evidence only. It is not payment authorization.

Safety boundary

This package does not hold funds, private keys, payment credentials, customer data, or settlement authority. It does not sign, send, settle, custody, or record payments. It makes no network requests.

A production payment adapter needs separate, independently verified controls for authenticated policy/action provenance, canonical payload hashing, durable atomic budget reservation and replay protection, customer-controlled signing, rail validation, and settlement reconciliation.

Install

npx -y @dingdawg/agent-spend-policy-mcp

Configure it as a local stdio MCP server:

{
  "mcpServers": {
    "dingdawg-agent-spend-policy": {
      "command": "npx",
      "args": ["-y", "@dingdawg/agent-spend-policy-mcp"]
    }
  }
}

Tool

evaluate_spend_policy accepts an evaluation time, a policy, a proposed action, and the already-spent amount. All money is passed as integer micro-unit strings, never JavaScript floating-point numbers.

The caller supplies the clock and already-spent value; therefore this tool is safe for dry runs and local evidence, not a replacement for a trusted payment or accounting system.

Agent contract

The versioned machine-readable contract is capabilities.json. It describes the only tool this package exposes, its required inputs, its three possible outcomes, and its non-negotiable safety boundary.

  • Transport: local stdio MCP
  • Tool: evaluate_spend_policy
  • Required inputs: evaluationTime, policy, action, and alreadySpentMicros
  • Outputs: ELIGIBLE, DENY, or STEP_UP, each with a stable reason code
  • Side effects: none
  • Credentials, payment execution, custody, signing, settlement, and network access: not supported

The manifest is package-source evidence for this release, not a promise of a hosted agent-discovery endpoint. ELIGIBLE remains local policy evidence only, not payment authorization.

Development

npm install
npm test
npm run pack:check

FAQs

Package last updated on 05 Aug 2026

Related posts