Covenant Guard runs on your own machine — the client starts it, so there is no endpoint to ping. Last commit 14 Sep 2026.
Hard spend cap, OS sandbox, and signed receipts for unattended coding agents like Claude Code.
We read the source, 19 h ago · rules 3dff92dd89df
What this server is able to do. For an MCP server this is often the job itself — a terminal server runs commands because that is what it is for. Listed so you know what you are plugging in, not as an accusation.
r#"{"type":"covenant_endpoint_attestation_v1","url":"https://example.com/x402/foo","network":"solana","asset":"EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v","payTo":"ZAU64eKWAgiGNux8bzvgRn8RvWqFhdMVrpJytF7V1qm","checks":{"live":true,"validX402Challenge":true},"source"…
const child = spawn(process.execPath, ['dist/server.js'], {
const raw = (await deps.connection.eval(
let url = format!("https://api.telegram.org/bot{}/sendMessage", self.token);
**/id_rsa*\n\
Is this your server and something here is wrong? Tell us — corrections are free and do not require a plan.
We found places where it runs commands, builds paths or queries from values it is given. None of that is a flaw by itself — it becomes one when the code changes, and code changes quietly between releases. We re-read it on every one.
Signed receipts and Cedar policies for AI agent tool calls. Claude Code hooks, MCP gateway.
Signed, cited, replayable workflows for Claude, Codex, Gemini, DeepSeek, and other agents.
Shared memory for AI coding agents. Save once, reuse from Cursor, Claude Code, Codex.
Tamper-evident, Sigstore-signed audit trail for Claude Code agents.
Durable local-first MCP relay for independent coding agents.
Rent a real UK phone number and receive SMS/OTP codes — built for AI coding agents.
Verified memory for coding agents: claims cited against code, stale withheld, savings receipts.
Deterministic release gate for AI-written code and coding agents.
Answers built from our own checks of this server.