kushbitx-mcp-agent
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@kushbitx-mcp-agentevaluate a 0.25 USDC spend against SpendGuard policy"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
kushbitx-mcp-agent
A real agent-directed integration for @kushbitx/sdk — built for the KushBitx bounty issue #1.
The model decides which SDK tool to call and in what order. It is not a fixed-sequence demo script: the agent receives three tool schemas, emits tool_calls, reads the results, and chooses when to stop. The same three capabilities are also exposed as an MCP stdio server so any MCP host can drive them.
What changed in this revision
This revision answers the three points in the maintainer's technical review:
Review point | How it is addressed |
"Use an actual AI agent runtime — the current |
|
"Add automated tests — |
|
"Provide fresh verification evidence … reproducible from a clean clone." | README rewritten; |
Related MCP server: x402farm-mcp
Security posture
Guarantee | How it is enforced |
No private key is ever requested, read, stored, or logged | No key argument exists in any tool schema; |
No payment is ever signed or executed | The x402 tool stops at the HTTP 402 challenge and returns it verbatim |
No signing, payment, recovery, or policy-mutation tool is exposed | Only three read-only tools are registered. A test asserts the handlers never call |
SpendGuard is never claimed to enforce anything | Descriptions, the agent's system prompt, and the run summary all state the verdict is advisory and that enforcement belongs to the signing/execution layer |
Unexpected responses surface as failures | A non-402 status, a missing challenge, or an unknown service throws; a test asserts each case |
Layout
agent/
tools.mjs # three tool schemas + SDK-backed handlers (the single source of truth)
agent.mjs # [OI]-compatible tool-calling AGENT LOOP (the model chooses the calls)
src/
server.mjs # MCP stdio server exposing the same three tools
retry.mjs # bounded retry for transient upstream signals only
test/
tools.test.mjs # tool layer: happy paths, validation, failures, retry, no-signing guard
server.test.mjs # MCP adapter contract + error-result behaviour
evidence/
agent-run.md # sanitized transcript of a real agent-directed run
agent-transcript.jsonTools exposed
Tool | Free? | Purpose |
| ✅ | Inspect basic Base token market data for an address |
| ✅ | Evaluate a proposed USDC spend against a policy before money moves (advisory) |
| ✅ | Discover the x402 payment requirements for a paid service (stops at 402) |
Requirements
Node.js 22 or later (tested on v22.23.1)
No wallet, no funds, and no API key to KushBitx are required for the free path
Setup
git clone https://github.com/krpx0341/kushbitx-mcp-agent
cd kushbitx-mcp-agent
npm installRun the tests
npm testExpected: # tests 18 / # pass 18 / # fail 0. All tests are offline — the SDK's fetchFn injection seam is used, so no network or credentials are needed.
Run the agent
The agent needs an [OI]-compatible chat-completions endpoint. Point it at any provider that supports tool calling:
export OPENAI_BASE_URL="https://your-endpoint/v1"
export OPENAI_API_KEY="your-key"
export AGENT_MODEL="your-model"
npm run agentTo capture the full tool-call transcript:
export AGENT_TRANSCRIPT_OUT="./evidence/agent-transcript.json"
npm run agentThe agent prints every tool call with its arguments and result, then a summary. It exits non-zero if the three-tool checklist was not completed, so CI can catch a regression.
Using the MCP server from another host
{
"mcpServers": {
"kushbitx": {
"command": "node",
"args": ["/absolute/path/to/kushbitx-mcp-agent/src/server.mjs"]
}
}
}Verified output
From the committed run — full detail in evidence/agent-run.md:
======================================================================
Summary
======================================================================
turns used : 2
tool calls : 3
distinct tools : preview_token, evaluate_spend, get_payment_challenge
tool errors : 0
No private key was requested, read, or stored. No payment was signed.
SpendGuard output is advisory; enforcement belongs to the signing layer.SpendGuard returned decision: HUMAN_APPROVAL with advisory: true and
executionAuthorized: false. The x402 challenge decoded to
x402Version: 2, scheme: exact, network: eip155:8453,
amount: "250000" (0.25 USDC). Nothing was signed and nothing was paid.
Notes and observations
Upstream flakiness on the free preview. During testing on 2026-09-19
POST /api/token-previewreturned HTTP503({"error":"Market data is temporarily unavailable..."}) intermittently — roughly one call in three — while/api/spendguard/evaluateand/api/token-riskstayed healthy.src/retry.mjsretries only that transient signal, bounded; a genuine failure is still surfaced as an error. Flagging in case the market-data dependency needs a look.evaluateSpendvalidates progressively, revealing required fields one at a time. The accepted shape is{ agentId, requestId, amount, chain: 'base', asset: 'USDC', recipient, service?, policy }, wherepolicyrequiresmaxPerTransaction,remainingDailyBudget,requireHumanAbove,maxRepeats,allowedRecipients, andblockUnknownRecipients.Reproducibility. A clean clone plus
npm installis enough:npm testproves the tool layer offline,npm run agentproves the model-directed path against a live endpoint.
Sanitization
The repository contains only public data: the well-known USDC contract address on Base, the SDK's own published payTo address from the x402 challenge, and BaseScan-visible values. The API key for the model endpoint is supplied at runtime via OPENAI_API_KEY and is not committed, logged, or printed. No private key, seed phrase, personal wallet address, or personal data appears anywhere in this repository.
License
Apache-2.0, matching the upstream SDK.
This server cannot be deployed
Maintenance
Related MCP Connectors
Paid MCP tools behind one endpoint. Agents pay per call in USDC on Base via x402.
Metered MCP tools: free discovery over MCP; per-call execution settled in USDC via x402 v2.
Pay-per-call MCP tools via x402 (USDC on Base): QR codes, images, text analysis, web fetch.
Production-grade MCP gateway delivering 8 real-time AI tools with instant x402 micropayments settled in USDC on Base Mainnet or SPL-USDC on Solana. Features Basescan contract auditing, wallet analytics, headless browser scraping, and pre-scraped oracle data feeds.
Related MCP Servers
- AlicenseAqualityDmaintenanceThe x402 ecosystem's read MCP for Base. Verify on-chain USDC settlements, parse publisher manifests, and audit x402 payment receipts from any MCP-compatible AI agent.1165 npm2MIT
- AlicenseNot gradedqualityDmaintenanceMCP server that provides AI agents with pay-per-call access to a suite of tools (honeypot check, token market, DeFi yields, etc.) via USDC on Base using the x402 protocol.9 npmMIT

tereno-mcpofficial
AlicenseNot gradedqualityBmaintenanceMCP server for verifying blockchain safety on Base via x402, with free pricing/receipt tools and paid per-call guard, contract, and metadata checks settled in USDC.47 npmMIT- FlicenseNot gradedqualityBmaintenanceExposes Base mainnet chain query tools over MCP, letting clients fetch an address's native balance and current gas fee estimates (slow/standard/fast urgency) from an upstream HTTP API. Paid tools are gated by x402 micropayments settled through the CDP facilitator, with a free health check and a documented free-trial allotment.-