MCP Spend Security Guide
MCP gives agents tools — and tools can spend. This guide covers the security model for agent spend over MCP.
The risk model
Every MCP server is third-party code with tool access.
A paid tool in a loop, or a malicious server, spends without review.
Vetting servers
Review source, check authors, pin versions, and scope permissions — treat MCP servers like dependencies.
The deterministic guard
The sipi.bot MCP tool evaluates every proposed purchase before it happens — rules, not prompts.
None
| Layer | Control |
|---|---|
| Server vetting | Source review + least privilege |
| Paid tools | Merchant allowlist + caps |
| Decision | Pre-spend guard tool |
| Audit | Queryable log |
FAQ
Can an MCP server spend money?
If it exposes a paid tool or holds a credential, yes. Gate it.
Is the guard model-free?
Yes — deterministic rules, nothing to inject.
Related
Stop the next $12,400 night.
One API call (or MCP tool) in front of every agent transaction — APPROVED, BLOCKED, or FLAGGED, deterministic, ~5 ms, fully logged.
See plans — from $99/mo Try a live check