Hard spend cap, OS sandbox, and signed receipts for unattended coding agents like Claude Code.
Runs locally over stdio
This server isn't hosted — your MCP client launches it from a package registry. Use one of the commands below, or drop the config into your client (e.g. Claude Desktop).
Distributed as an MCP bundle (`https://github.com/open-covenant/covenant/releases/download/covguard-v0.1.1/covenant-guard.mcpb`) — download it and import the bundle in your MCP client.