@oceanalt/mcp-guard
v0.2.0
Published
Payment-runtime guard for MCP clients: wraps callTool so that payment-shaped tool calls (pay / transfer / send / approve / sign) get a pre-settlement decision, a calldata intent check and a secret-exfiltration scan before they run. Everything else passes
Maintainers
Readme
@oceanalt/mcp-guard
Wrap an MCP client's callTool. Only payment-shaped tools (pay, transfer, send, withdraw, approve, sign, swap, bridge, settle) are inspected; everything else passes through untouched.
For a payment-shaped call: secrets in the arguments are blocked (private keys, API keys, mnemonics) → the data is decoded and compared with the declared payment (EVM calldata, or a whole base64 Solana transaction) → the payee gets a pre-settlement decision → the tool runs and the outcome is recorded.
import { OceanAltClient } from "@oceanalt/core";
import { guardToolCall } from "@oceanalt/mcp-guard";
const client = new OceanAltClient();
const callTool = guardToolCall(mcp.callTool.bind(mcp), { client, mode: "block" });
await callTool("send_payment", { to: "0x…", amount: "10000000", contract: "0x833589…", data: "0xa9059cbb…" });An approve(spender, MAX) dressed as a payment, or a Solana SetAuthority / CloseAccount, throws with the decoded explanation. Undecodable data is held, not allowed. OceanAlt holds no keys and moves no money.
