AgentGuard
Local package path declaredNo credentials listedRepository declared by sourceUpdated 2026-09-21
io.github.MerchantGuard/agentguard · Registry status: active
At a glance
Local spend caps, kill-switch blocking and Ed25519-signed receipts for AI agent tool calls.
Vendor's own description, untranslated and unverified
- Execution location
- Local package path declared
- Required secrets declared
- No credentials listed
- Declared version and change
0.3.1· Source-reported change date 2026-09-21- Repository as declared
- github.com/MerchantGuard/agentguard-mcp
- Configuration
- can be built from the disclosed start template
Inspect connection paths and prerequisites
Related categories
- MCP servers without declared required secrets35,800
- Locally executed MCP servers17,056
- MCP servers with a repository URL30,107
- MCP servers with a path argument498
- Local MCP servers without declared required secrets13,238
- Local MCP servers with a repository URL16,152
6 of 13 categories. All categories in the segment catalogue
Page last changed:
Sources and collection
- Runs
- Local package path declared
- Credentials
- No credentials listed
- Registry record changed
- 2026-09-21
- Setup
- Template available
- Registry name
io.github.MerchantGuard/agentguard- Package coordinate
npm:@agentguard-run/mcp- Declared version
0.3.1- Source-reported listing date
- 2026-09-21
- Source-reported change date
- 2026-09-21
- First seen by tracevero
- 2026-09-22
- Vendor's website
- https://agentguard.run
Evidence for this page · Source: MCP-Register · collected on 2026-09-22
Every value below comes from it. Where one differs, its origin is stated on its row. What the confidence levels mean
Measured values
| Required secrets declared | No credentials listed no Original data – Required secret variables (raw): confirmed absent Original data – Required secret headers (raw): confirmed absent Source: MCP-Register · collected on 2026-09-22 · derived |
|---|---|
| Execution location | Local package path declared local Original data – Transports (raw): stdio Source: MCP-Register · collected on 2026-09-22 · derived |
| Path argument present | yes Original data – Path arguments (raw): confirmed absent Original data – Path environment variables (raw): AGENTGUARD_HOME Source: MCP-Register · collected on 2026-09-22 · derived |
| Repository URL listed | Repository declared by source yes Original data – Repository (raw): https://github.com/MerchantGuard/agentguard-mcp Source: MCP-Register · collected on 2026-09-22 · derived |
| Declared version | 0.3.1 Source: MCP-Register · collected on 2026-09-22 · self-declared |
What is measured is what a manifest declares, not what a piece of software does. This registry fetches no repository URL, no endpoint and no package index; nothing here is verified. Which value comes from which source, and by which rule it was formed, is set out in the Methodology.
Source data25
All 25 values in this block: self-declared.
| Description (raw) | Local spend caps, kill-switch blocking and Ed25519-signed receipts for AI agent tool calls. |
|---|---|
| Environment variables (raw) | AGENTGUARD_MCP_DAILY_CAP_CENTS, AGENTGUARD_MCP_PER_CALL_CAP_CENTS, AGENTGUARD_MCP_TENANT, AGENTGUARD_HOME, AGENTGUARD_MCP_LEDGER, AGENTGUARD_MCP_DISABLE_COST_OVERRIDE, AGENTGUARD_LOCK_COST_OVERRIDES, AGENTGUARD_ACTOR_DIGEST, AGENTGUARD_LICENSE_KEY, AGENTGUARD_LICENSE_ENDPOINT, AGENTGUARD_NO_BEACON, AGENTGUARD_TELEMETRY, AGENTGUARD_INSTALL_ID, AGENTGUARD_ANONYMOUS_INSTALL_ID, CI, GITHUB_ACTIONS, GITLAB_CI, CIRCLECI, BUILDKITE, VERCEL, NETLIFY |
| Required secret variables (raw) | confirmed absent |
| Transports (raw) | stdio |
| Path arguments (raw) | confirmed absent |
| Repository (raw) | https://github.com/MerchantGuard/agentguard-mcp |
| Package registries (raw) | npm |
| Required secret headers (raw) | confirmed absent |
| Path environment variables (raw) | AGENTGUARD_HOME |
| Remote URLs (raw) | confirmed absent |
| Remote hosts (raw) | confirmed absent |
| Registry status message (raw) | confirmed absent |
| First listed in the registry (raw) | 2026-09-21 |
| Last changed in the registry (raw) | 2026-09-21 |
| Schema version of the raw record (raw) | https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json |
| Delivery form (raw) | package |
| Repository platform (raw) | github |
| Repository subfolder (raw) | confirmed absent |
| Package identifiers (raw) | @agentguard-run/mcp |
| Package versions (raw) | 0.3.1 |
| Runtime hints (raw) | npx |
| Environment variable formats (raw) | filepath, number, string |
| Environment variable descriptions (raw) | AGENTGUARD_ACTOR_DIGEST=Set to 1 to hash actor identifiers before they enter local receipts. · AGENTGUARD_ANONYMOUS_INSTALL_ID=Legacy fallback for AGENTGUARD_INSTALL_ID in opted-in activation telemetry. · AGENTGUARD_HOME=Local signing-key, configuration and ledger directory. Defaults to .agentguard in the operating system home directory. · AGENTGUARD_INSTALL_ID=Optional identifier used only by opted-in activation telemetry when no saved install identifier exists. · AGENTGUARD_LICENSE_ENDPOINT=License and seat service base URL. No prompts, tool content or receipts are sent. · AGENTGUARD_LICENSE_KEY=Optional AgentGuard license key for license validation and seat registration. Otherwise read from local configuration. · AGENTGUARD_LOCK_COST_OVERRIDES=Spend SDK startup lock. Set to 1 to prevent model pricing overrides. · AGENTGUARD_MCP_DAILY_CAP_CENTS=Local daily spend cap in cents. A nonnegative integer. · AGENTGUARD_MCP_DISABLE_COST_OVERRIDE=Set to 1 to discard and prevent model pricing overrides for this server. · AGENTGUARD_MCP_LEDGER=Local decision storage. ndjson persists receipts across restarts; memory retains this process only. · AGENTGUARD_MCP_PER_CALL_CAP_CENTS=Local per-call spend cap in cents. A nonnegative integer. · AGENTGUARD_MCP_TENANT=Tenant identifier stamped into local receipts. · AGENTGUARD_NO_BEACON=Set to 1 to disable optional activation telemetry regardless of saved consent. · AGENTGUARD_TELEMETRY=Set to 1 to opt in to content-free activation telemetry. Otherwise saved consent applies, default off. · BUILDKITE=Existing runtime marker. A nonempty value marks opted-in activation telemetry as CI; it does not enable telemetry. · CI=Existing runtime marker. A nonempty value marks opted-in activation telemetry as CI; it does not enable telemetry. · CIRCLECI=Existing runtime marker. A nonempty value marks opted-in activation telemetry as CI; it does not enable telemetry. · GITHUB_ACTIONS=Existing runtime marker. A nonempty value marks opted-in activation telemetry as CI; it does not enable telemetry. · GITLAB_CI=Existing runtime marker. A nonempty value marks opted-in activation telemetry as CI; it does not enable telemetry. · NETLIFY=Existing runtime marker. A nonempty value marks opted-in activation telemetry as CI; it does not enable telemetry. · VERCEL=Existing runtime marker. A nonempty value marks opted-in activation telemetry as CI; it does not enable telemetry. |
| Icon formats (raw) | confirmed absent |
| Connection paths (source structure) | {"packages":[{"registryType":"npm","identifier":"@agentguard-run/mcp","version":"0.3.1","runtimeHint":"npx","transport":"stdio","environment":[{"name":"AGENTGUARD_MCP_DAILY_CAP_CENTS","description":"Local daily spend cap in cents. A nonnegative integer.","format":"number","required":false,"secret":false},{"name":"AGENTGUARD_MCP_PER_CALL_CAP_CENTS","description":"Local per-call spend cap in cents. A nonnegative integer.","format":"number","required":false,"secret":false},{"name":"AGENTGUARD_MCP_TENANT","description":"Tenant identifier stamped into local receipts.","format":"string","required":false,"secret":false},{"name":"AGENTGUARD_HOME","description":"Local signing-key, configuration and ledger directory. Defaults to .agentguard in the operating system home directory.","format":"filepath","required":false,"secret":false},{"name":"AGENTGUARD_MCP_LEDGER","description":"Local decision storage. ndjson persists receipts across restarts; memory retains this process only.","format":"string","required":false,"secret":false},{"name":"AGENTGUARD_MCP_DISABLE_COST_OVERRIDE","description":"Set to 1 to discard and prevent model pricing overrides for this server.","format":"string","required":false,"secret":false},{"name":"AGENTGUARD_LOCK_COST_OVERRIDES","description":"Spend SDK startup lock. Set to 1 to prevent model pricing overrides.","format":"string","required":false,"secret":false},{"name":"AGENTGUARD_ACTOR_DIGEST","description":"Set to 1 to hash actor identifiers before they enter local receipts.","format":"string","required":false,"secret":false},{"name":"AGENTGUARD_LICENSE_KEY","description":"Optional AgentGuard license key for license validation and seat registration. Otherwise read from local configuration.","format":"string","required":false,"secret":true},{"name":"AGENTGUARD_LICENSE_ENDPOINT","description":"License and seat service base URL. No prompts, tool content or receipts are sent.","format":"string","required":false,"secret":false},{"name":"AGENTGUARD_NO_BEACON","description":"Set to 1 to disable optional activation telemetry regardless of saved consent.","format":"string","required":false,"secret":false},{"name":"AGENTGUARD_TELEMETRY","description":"Set to 1 to opt in to content-free activation telemetry. Otherwise saved consent applies, default off.","format":"string","required":false,"secret":false},{"name":"AGENTGUARD_INSTALL_ID","description":"Optional identifier used only by opted-in activation telemetry when no saved install identifier exists.","format":"string","required":false,"secret":false},{"name":"AGENTGUARD_ANONYMOUS_INSTALL_ID","description":"Legacy fallback for AGENTGUARD_INSTALL_ID in opted-in activation telemetry.","format":"string","required":false,"secret":false},{"name":"CI","description":"Existing runtime marker. A nonempty value marks opted-in activation telemetry as CI; it does not enable telemetry.","format":"string","required":false,"secret":false},{"name":"GITHUB_ACTIONS","description":"Existing runtime marker. A nonempty value marks opted-in activation telemetry as CI; it does not enable telemetry.","format":"string","required":false,"secret":false},{"name":"GITLAB_CI","description":"Existing runtime marker. A nonempty value marks opted-in activation telemetry as CI; it does not enable telemetry.","format":"string","required":false,"secret":false},{"name":"CIRCLECI","description":"Existing runtime marker. A nonempty value marks opted-in activation telemetry as CI; it does not enable telemetry.","format":"string","required":false,"secret":false},{"name":"BUILDKITE","description":"Existing runtime marker. A nonempty value marks opted-in activation telemetry as CI; it does not enable telemetry.","format":"string","required":false,"secret":false},{"name":"VERCEL","description":"Existing runtime marker. A nonempty value marks opted-in activation telemetry as CI; it does not enable telemetry.","format":"string","required":false,"secret":false},{"name":"NETLIFY","description":"Existing runtime marker. A nonempty value marks opted-in activation telemetry as CI; it does not enable telemetry.","format":"string","required":false,"secret":false}],"additional_arguments_declared":false}],"remotes":[]} |
Embed this badge
Paste this line into a README of your own. The badge states how many values the registry holds for the entry and when it last looked, and it links back to this page.
[](https://tracevero.com/mcp/io-github-merchantguard-agentguard)
The image is drawn again on every request, so it always reports the current state while the pasted line stays as it is. It carries no rating and no traffic light – only the two measured figures.
Changes
| 2026-09-22 | Declared version: – → 0.3.1 |
|---|---|
| 2026-09-22 | Repository URL listed: – → yes |
| 2026-09-22 | Path argument present: – → yes |
These are the 3 most recent changes to this entry. Full history
tracevero · https://tracevero.com/mcp/io-github-merchantguard-agentguard