npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

payment-guard-mcp

v1.4.0

Published

MCP server: pre-send risk check for AI agents that move money: screen a crypto address (or ENS name) and payment URLs for OFAC sanctions, scam/abuse blocklists, and on-chain risk before a transfer. Deterministic, no LLM.

Readme

payment-guard-mcp

An MCP server that checks who your agent is about to pay, before it sends anything. Give it a crypto address, an ENS name, or a payment URL and it returns a verdict. Deterministic, no LLM, free.

Agents are starting to move real money on their own, over crypto rails, x402 endpoints, and payment links. The obvious way that goes wrong is paying a sanctioned or scam address by mistake, which is usually irreversible. screen_address is the check to run first.

Install

{ "mcpServers": { "payment-guard": { "command": "npx", "args": ["-y", "payment-guard-mcp"] } } }

Tools

  • screen_address: the main guard. Takes an EVM address or ENS name and checks OFAC sanctions, scam and abuse blocklists, and on-chain signals (brand-new and unused addresses, contracts). Returns safe, caution, or block.
  • screen_payment: vet an x402 or merchant payment URL for a punycode host, a known brand name sitting outside the registrable domain, shorteners, abuse-prone TLDs, freshly registered domains, and the final URL after redirects.
  • check_sanctioned: a quick OFAC-only check for an address or ENS name.
  • resolve_name: resolve an ENS name to its address and screen that address. It catches names that don't resolve. It does not detect spoofed lookalike names.
  • screen_token: before buying, swapping, or approving a token, check the contract for honeypot behavior (you can buy but not sell), extreme sell taxes, and blocklist hits.

On-chain checks run on Ethereum, Base, Polygon, Arbitrum and Optimism. Data comes from the OFAC SDN list, community scam lists (ethereum-lists, ScamSniffer), public RPC nodes, and ENS.

ENS coverage: resolution is namehash, then resolver(node) on the mainnet ENS registry, then a direct addr(bytes32) call. The address that comes back is screened against the sanctions and scam lists. There is no confusable check and no ENSIP-15 normalization, so lookalike and homoglyph names are not detected. There is no ENSIP-10 wildcard resolution and no CCIP-Read, so offchain and L2 names — Basenames, .cb.id, gasless subnames — report as not resolving here even though a wallet resolves them.

Honeypot coverage: the buy+sell simulation is api.honeypot.is, Ethereum and Base only. It returns 400 Invalid chain for Polygon, Arbitrum and Optimism, so the honeypot and tax fields are not populated there. The response says which chains it covers, and when no simulation ran the verdict is never safe — it is caution, or block if the scam blocklist already hit.

URL coverage: the lookalike rule is a substring match on 14 brand names, flagged when the brand is not the registrable domain. paypal.com.secure-pay.xyz is caught; paypa1.com is not, because there is no edit distance or homoglyph mapping. Only the final URL after redirects is compared, not each hop.

Sanctions coverage, stated plainly: OFAC publishes sanctioned addresses by currency, not by chain, so this checks the union of every EVM-format list (ETH, ARB, BSC, ETC, USDC, USDT) and that result applies to any EVM chain. Bitcoin, Tron, Solana, Monero and other non-EVM sanctioned addresses are not checked, because only EVM addresses are accepted. Every response carries a coverage object saying so. If the list cannot be loaded the result is unknown, never clear.

Rule updates

About once a day this server asks the rules feed whether there is a newer ruleset, and applies it if there is. The request carries two things: which surface asked, which here is facade, and the rules version already installed. No machine id, no user id, no file names, nothing you scanned.

Bundles are signed with Ed25519 and verified against a public key compiled into this package, so it does not matter which mirror served one. A bundle that fails its signature, its schema, or its ReDoS check is discarded and the rules you already had stay in place. --offline turns updates off, as does AGENT_GUARDS_NO_FEED=1 or {"feed": false} in ~/.agent-guards/config.json. The bundle format and how to verify one yourself: https://github.com/mlawsonking/MCP/blob/main/rules/README.md

It calls https://payment-guard.vercel.app (set PAYMENT_GUARD_API to override). One of six agent guards in this repo. MIT.