Skip to main content
Glama
dingdawg

DingDawg Agent Spend Policy MCP

Official
by dingdawg

DingDawg Agent Spend Policy MCP

A small, local MCP server that deterministically evaluates whether a proposed agent spend action matches a supplied policy.

It returns one of ELIGIBLE, DENY, or STEP_UP, with a stable reason code. ELIGIBLE is local policy evidence only. It is not payment authorization.

Safety boundary

This package does not hold funds, private keys, payment credentials, customer data, or settlement authority. It does not sign, send, settle, custody, or record payments. It makes no network requests.

A production payment adapter needs separate, independently verified controls for authenticated policy/action provenance, canonical payload hashing, durable atomic budget reservation and replay protection, customer-controlled signing, rail validation, and settlement reconciliation.

Related MCP server: dingdawg-agent-wallet

Install

npx -y @dingdawg/agent-spend-policy-mcp

Configure it as a local stdio MCP server:

{
  "mcpServers": {
    "dingdawg-agent-spend-policy": {
      "command": "npx",
      "args": ["-y", "@dingdawg/agent-spend-policy-mcp"]
    }
  }
}

Tool

evaluate_spend_policy accepts an evaluation time, a policy, a proposed action, and the already-spent amount. All money is passed as integer micro-unit strings, never JavaScript floating-point numbers.

The caller supplies the clock and already-spent value; therefore this tool is safe for dry runs and local evidence, not a replacement for a trusted payment or accounting system.

Agent contract

The versioned machine-readable contract is capabilities.json. It describes the only tool this package exposes, its required inputs, its three possible outcomes, and its non-negotiable safety boundary.

  • Transport: local stdio MCP

  • Tool: evaluate_spend_policy

  • Required inputs: evaluationTime, policy, action, and alreadySpentMicros

  • Outputs: ELIGIBLE, DENY, or STEP_UP, each with a stable reason code

  • Side effects: none

  • Credentials, payment execution, custody, signing, settlement, and network access: not supported

The manifest is package-source evidence for this release, not a promise of a hosted agent-discovery endpoint. ELIGIBLE remains local policy evidence only, not payment authorization.

Development

npm install
npm test
npm run pack:check

Available Tools

1 tool
evaluate_spend_policyEvaluate agent spend-policy eligibilityA
Read-onlyIdempotent

Deterministically evaluates a proposed action against caller-supplied policy. This is local policy evidence only: it never authorizes, signs, sends, settles, custodies, or records a payment.

ParametersJSON Schema
NameRequiredDescriptionDefault
actionYes
policyYes
evaluationTimeYes
alreadySpentMicrosYes

Output Schema

ParametersJSON Schema
NameRequiredDescription
outcomeYes
reasonCodeYes

TDQS

A4.1/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description goes well beyond annotations by stating 'deterministically' and enumerating all the things it never does: 'never authorizes, signs, sends, settles, custodies, or records a payment.' This is critical behavioral context that annotations (readOnly, idempotent, non-destructive) do not fully convey, especially the deterministic nature and the explicit non-authorization boundary.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two sentences long, with the primary action in the first sentence and critical boundary statements in the second. It is front-loaded with the main purpose and wastes no words. Every clause adds value.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The tool has complex nested parameters and no parameter descriptions, but the output schema exists (not shown) and annotations provide safety hints. The description clearly conveys the tool's role as a local, deterministic policy check and its non-payment-execution boundary. It could add more detail about the evaluation result (e.g., what the response contains), but the output schema likely covers that, so the description is reasonably complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema has 0% description coverage for its 4 parameters, so the description must compensate. It only loosely references 'proposed action' and 'caller-supplied policy' (mapping to 'action' and 'policy'), but it does not explain 'evaluationTime' or 'alreadySpentMicros'. The description adds minimal parameter-level meaning, leaving users to infer the rest from schema structure alone.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool 'deterministically evaluates a proposed action against caller-supplied policy,' specifying the exact verb and resource. It distinguishes the tool's purpose from typical payment execution by explicitly listing what it never does (authorize, sign, send, settle, custody, record). This makes it distinct even without sibling tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage for policy evaluation ('Deterministically evaluates a proposed action against caller-supplied policy') and adds the context 'local policy evidence only.' However, it does not explicitly state when to use this tool versus other potential approaches, nor does it provide exclusions or alternatives (though no siblings exist). The guidance is present but mostly implicit.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 1 tool updatev0.1.0
    • First observedevaluate_spend_policy

TDQS

A4.3/5.0

Scored across 1 tool

Disambiguation5/5

With only one tool, there is no possibility of overlap or ambiguity. The tool's purpose is clearly defined and distinct.

Naming Consistency5/5

The sole tool name 'evaluate_spend_policy' follows a clear verb_noun pattern, and with no other tools, there are no inconsistent conventions.

Tool Count4/5

A single tool is slightly thin, but it is well-scoped for the server's narrow purpose of evaluating spend policies. The count is reasonable and not trivial.

Completeness5/5

The tool fully covers its domain: it deterministically evaluates a proposed action against policy and explicitly avoids out-of-scope actions. No obvious gaps exist for the stated purpose.

Maintenance

ActivitySlowing
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    Enforces deterministic policies on AI agent tool calls, evaluating actions against compliance modules (SOC 2, HIPAA, GDPR, etc.) and returning ALLOW, BLOCK, or CONSTRAIN decisions with an audit trail.
    MIT
  • A
    license
    Not graded
    quality
    F
    maintenance
    Enables verification of AI agent identity, authority, and integrity at transaction time, returning signed verdicts for allow, step-up, review, or block.
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Enables agents to request payment authorization against signed human mandates, enforcing policy-as-code limits and returning a decision (authorize, challenge, or deny) without moving funds.
    1
    Apache 2.0