costwright
Provides static worst-case token-budget analysis for CrewAI workflows in Python repos, identifying certifiable, default-dependent, non-certifiable, and runaway units.
Provides static worst-case token-budget analysis for LangGraph workflows in Python repos, identifying certifiable, default-dependent, non-certifiable, and runaway units.
Provides static worst-case token-budget analysis for OpenAI Agents SDK workflows in Python repos, identifying certifiable, default-dependent, non-certifiable, and runaway units.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@costwrightcheck my LangGraph project for token budget issues"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
costwright — MCP server
Static worst-case token-budget analysis for LLM-agent workflows. Point it at a Python repo using LangGraph / CrewAI / OpenAI-Agents-SDK and it reports — by pure AST analysis, without running the code — the worst-case budget ceiling of every workflow graph: which units are certifiable / default-dependent / non-certifiable / runaway, and which LLM calls have no token cap. Optionally issues an Ed25519-signed budget certificate logged to a public transparency log. Wraps the hosted costwright API; backed by a Lean 4 cost-soundness theorem.
Use it before deploying an agent workflow to catch missing token caps and
while True:runaway drivers — the budget version of a type check.
Tools
Tool | What it does | Key? |
| Static budget analysis of a local repo. Returns pass/fail + counts of certifiable/default-dependent/non-certifiable/runaway units. | yes |
| Issues a signed, logged budget certificate. Returns cert_id + signature + verify_url. | yes |
| Verify a certificate by id (valid/expired/revoked, signature check). | public |
| Active Ed25519 public keys for offline verification. | public |
Related MCP server: cycles-mcp-server
Setup
{
"mcpServers": {
"costwright": {
"command": "npx",
"args": ["-y", "costwright-mcp"],
"env": { "COSTWRIGHT_API_KEY": "your_rapidapi_key" }
}
}
}The key is sent as X-RapidAPI-Key (RapidAPI channel) by default; set COSTWRIGHT_DIRECT=1 to send
it as Authorization: Bearer for the direct channel. verify and pubkey work with no key.
check/certify build a .py-only gzip archive of repo_path client-side (excluding venv,
node_modules, tests, etc.) and send it for analysis — your source is uploaded to the hosted API.
See https://eleata.io/privacy/. MIT licensed.
Maintenance
Related MCP Servers
- Alicense-qualityAmaintenanceTACIT (Tracked Agent Capabilities In Types) is a safety harness for AI agents. Instead of calling tools directly, agents write code in Scala 3 with capture checking: a type system that statically tracks capabilities and enforces that agent code cannot forge access rights, cannot perform effects beyond its budget, and cannot leak information from pure sub-computations. It provides an MCP interface,Last updated64Apache 2.0
- AlicenseAqualityAmaintenanceRuntime budget authority for autonomous agents - a set of tools to check, reserve, spend, and release budget before and after every costly, risky operation. The agent asks "can I afford this?" before acting, and reports what it actually used afterward.Last updated9813Apache 2.0
- AlicenseAqualityAmaintenanceAn MCP code-intelligence server for AI agents with pre-indexed AST cache, 62 MCP tools, and TOON-compressed output, enabling token-efficient code analysis and project health grading entirely locally.Last updated944MIT
- AlicenseAqualityCmaintenanceStructural memory for coding agents — 60% fewer tokens, refactor-safe, runs entirely on your machine.Last updated44715Apache 2.0
Related MCP Connectors
Agent Token Budget MCP — hard per-session token + spend cap with signed budget-exhausted
Agentic workflow budget approvals with usage receipts.
Budget & cost control for AI agents — per-agent spend caps + rate limits before each call.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/hernaninverso/costwright-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server