Autonomous agents get drained every day ÔÇö $45M lost in a single January attack. MandateGuard is the pre-action enforcement layer: budgets, allowlists, rate limits, and signed mandates evaluated with no LLM in the decision path. Mount it via MCP in minutes.
Buy Pro ÔÇö $149/mo GitHubOWASP names it LLM08. Every agent with a wallet is one prompt injection away from being drained. Standards (Google AP2, Coinbase x402, ERC-8004) define the paperwork ÔÇö nobody ships the enforcement.
Prompt injection makes the agent "refund the customer" ÔÇö to an attacker wallet. MandateGuard blocks by allowlist, budget, and per-call limits before the tool runs.
Compromised context steers the agent to bulk spend. Signed, time-boxed mandates cap the blast radius; nothing exceeds the issuer's explicit scope.
When a drain happens, you need proof. Every decision lands in a tamper-evident SHA-256 ledger you can verify in O(n).
One deterministic engine. No model sampling. Same inputs  same verdict, always.
Agent intent ÔöÇÔöÇÔû authorize(intent) ÔöÇÔöÇÔû PolicyEngine Ôöé scope ┬À allowlist ┬À denylist Ôöé budget ┬À rate limit ┬À mandate Ôû╠APPROVED / DENIED / REQUIRES_APPROVAL Ôû╠append-only SHA-256 ledger (audit)
Allowed tools, destinations, per-call max, currency, per-window call limits.
Ed25519, nonce-bound, time-boxed authorizations in the AP2 / x402 / ERC-8004 pattern. The agent cannot widen its own scope.
Mount as a guardrail in Claude, Cursor, or any harness. Pro features (RBAC, revocation, persistence, webhooks) gate via signed licenses.
MIT core, forever. Pay only for what operations need: revocation, persistence, RBAC, webhooks, and audit notary. Pay in USDT ÔÇö Solana or Ethereum.
Send USDT to one of the wallets below and email your order id + tx hash to ezequiellich44@gmail.com. Your signed Pro license is issued within 24h.
Faster and cheaper fees. Amount: 149 USDT/mo.
3fZSMAyCEMhZwWiynbJDjoYNUT97aiV9BLzoUNroEMAz Amount: 149 USDT/mo.
0x4Ed4D0750453C027FA8398067d5af980Bcc9B6eD Include your email or order id in the transfer memo. After sending, email your tx hash so we can verify on-chain and deliver your license.
# from source (repo, works today)git clone https://github.com/ezequiellich44-cmd/MandateGuard.gitcd MandateGuardpip install -e ".[mcp]"mandateguard-mcp# or mount the MCP bundle from the official registry:io.github.ezequiellich44-cmd/mandateguard
Python 3.10. Core decision path is stdlib + cryptography for mandates. Full docs on GitHub.
Questions or volume pricing? ezequiellich44@gmail.com
Star on GitHub