@helmmasters/agentvault-mcp
v0.1.0
Published
MCP server for Helm (AgentVault) — expose Solana agent-vault operations as Model Context Protocol tools. Read vault/policy state and (with a keypair) propose, approve, and execute guardian-gated transactions.
Maintainers
Readme
@helmmasters/agentvault-mcp
MCP server for Helm (AgentVault) — exposes Solana agent-vault operations
as Model Context Protocol tools. Read vault, policy, and pending
state with no wallet; with a local keypair, propose / approve / veto / execute / suspend / and
update guardian-gated transactions. Works in any MCP client: Claude Desktop, Hermes Agent, or your
own. Built on @helmmasters/agentvault-sdk.
Install
npm install -g @helmmasters/agentvault-mcpThis installs the agentvault-mcp executable (stdio MCP server).
Configuration
Configured entirely through environment variables:
| Env var | Required | Default | Purpose |
|---|---|---|---|
| HELM_RPC_URL | no | https://api.mainnet-beta.solana.com | Solana mainnet RPC (use Helius/QuickNode — the public endpoint rate-limits) |
| HELM_KEYPAIR_PATH | for write tools | — | Path to a JSON keypair file. Enables signing tools; the key never leaves the local process |
Mode A — read-only (no keypair). All read/utility tools work. Write tools return a clear error telling you to configure a keypair.
Mode B — signing (keypair path). All tools work. The keypair signs and the server simulates every transaction before sending.
Claude Desktop
Add to claude_desktop_config.json (Settings → Developer → Edit Config):
{
"mcpServers": {
"helm": {
"command": "agentvault-mcp",
"env": {
"HELM_RPC_URL": "https://api.mainnet-beta.solana.com",
"HELM_KEYPAIR_PATH": "/absolute/path/to/keypair.json"
}
}
}
}Omit HELM_KEYPAIR_PATH for read-only mode.
Hermes Agent
Hermes consumes MCP servers the same way. Add an entry to your Hermes MCP config (see the Hermes
docs for the exact file location) pointing command at agentvault-mcp with the same env block.
For remote setups, run agentvault-mcp behind your own MCP-over-HTTP bridge — but only on a host
you control (see the security note below).
Tools
Read & utility tools need no signer. Write tools require HELM_KEYPAIR_PATH and simulate before
sending.
| Tool | What it does | Signer |
|---|---|:--:|
| helm_list_vaults_for_guardian | List all vaults for a guardian wallet | — |
| helm_get_vault | Vault state + its policy | — |
| helm_get_policy | Policy: caps, whitelist, allowlist, feed, pending update | — |
| helm_list_pending_transactions | Pending txs (value, tier, status, approval) | — |
| helm_get_protocol_stats | Total vaults, SOL locked, pending count | — |
| helm_derive_vault_pda | Derive vault PDA from guardian + id | — |
| helm_derive_policy_pda | Derive policy PDA from vault | — |
| helm_derive_pending_pda | Derive pending PDA from vault + nonce | — |
| helm_create_vault | Initialize a vault (signer = guardian) | ✅ |
| helm_propose_transaction | Propose a tx as the agent | ✅ |
| helm_approve_pending | Approve a pending tx (guardian) | ✅ |
| helm_veto_pending | Veto a pending tx (guardian) | ✅ |
| helm_execute_pending | Execute an approved/timelock-elapsed pending tx | ✅ |
| helm_suspend_vault / helm_resume_vault | Suspend / resume a vault (guardian) | ✅ |
| helm_update_policy | Schedule a policy change (24h timelock) | ✅ |
| helm_commit_policy_update | Apply a scheduled policy change after the timelock | ✅ |
USD caps are valued via a Pyth oracle. Policy updates are subject to the program's 24-hour timelock. Write tools are simulated first; on failure the server returns the structured Solana program error (not a generic "failed").
Security
- Your keypair stays local.
HELM_KEYPAIR_PATHis read by the local process only and is never transmitted. Treat it like any hot wallet — fund it modestly. - Do not run this as a hosted/multi-tenant service exposing your keypair. The signing mode is designed for a local MCP client (Claude Desktop / a Hermes instance you run). If you expose it over the network, you are exposing signing authority — put it behind your own auth and run it only on a host you control.
- Helm itself is the guardrail: even with a configured keypair, the vault enforces USD caps and the guardian timelock on-chain. An agent key can only do what the vault's policy allows.
Links
- Helm: helmagent.xyz · app: app.helmagent.xyz
- SDK: @helmmasters/agentvault-sdk
- Code: github.com/HelmMasters/agentvault (
mcp/)
License
Apache-2.0
