PluginBench
MCP Server
Active
Apache-2.0

Covenant Guard MCP Server

org.opencovenant/guard

Hard spend caps, OS sandboxing, and signed receipts for autonomous coding agents.

What is the Covenant Guard MCP server?

Covenant Guard is an MCP server that provides infrastructure for agent-native computing, sitting between agent applications and the host OS. It enforces hard spend caps, OS-level sandboxing, and generates signed receipts for unattended agents like Claude Code, enabling durable context, explicit authority, and append-only audit trails.

Covenant Guard is a daemon-based control plane for autonomous software agents. It owns scoped capabilities, durable memory, runtime isolation, append-only audit logs, and commit-scoped provenance—so agent frameworks don't have to reinvent them. Use it to safely run long-running coding agents with budget enforcement, sandboxed execution, and verifiable accountability.

How to install Covenant Guard

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "guard": {
      "command": "https://github.com/open-covenant/covenant/releases/download/covguard-v0.1.1/covenant-guard.mcpb",
      "args": []
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • Intent dispatch — Normalized request routing for CLI, IPC, HTTP, and MCP surfaces with daemon-mediated execution.
  • Runtime with budget enforcement — Agent execution with hard spend caps, CPU time limits (projection-tick preempt and wall-clock backstop), manifest contracts, and optional Linux gVisor sandboxing.
  • Memory tiers — SQLite-backed working, episodic, and long-term records with embedding hooks, drift reports, and bounded compaction.
  • Signed capabilities — Scoped permissions with known-scope validation, dispatch-time enforcement, expiry, and revocation.
  • Append-only audit log — JSONL event chain with hash-chain integrity verification, retention controls, and audit-root attestations.
  • Identity and peer authentication — Local ed25519 identity, peer registry, operator tokens, token rotation, and peer revocation.
  • MCP adapter — Native MCP integration alongside IPC, HTTP gateway, and A2A mailbox primitives.
  • Settlement and receipts — Local resource receipts, HTTP 402 (x402) payment rail for metered resources, and multi-chain trust projection (Solana, Base, Robinhood Chain).
  • Operator console — Next.js web UI for dispatching intents, browsing audit chains, granting capabilities, and inspecting memory.

Use cases

  • Run unattended coding agents with hard spend limits and automatic budget enforcement to prevent runaway costs.
  • Audit every action an agent takes with append-only logs and signed receipts for compliance and accountability.
  • Sandbox hostile or untrusted agent code with OS-level isolation (gVisor support) while maintaining capability-scoped access.
  • Persist agent context across interruptions and restarts using durable memory tiers and resumable task state.
  • Delegate scoped permissions to remote agents or services with signed capabilities and revocation support.

Covenant Guard MCP server FAQ

What is Covenant Guard?

Covenant Guard is an MCP server that provides a daemon-based control plane for autonomous agents. It enforces hard spend caps, OS-level sandboxing, signed receipts, append-only audit logs, and durable memory—enabling safe, accountable long-running agent work.

Is it free?

Covenant is open-source under Apache-2.0. The daemon and CLI are free to run locally. On-chain settlement (Solana, Base, Robinhood Chain) and x402 payment rails incur transaction fees; a live x402 seller settles USDC on mainnet.

How do I install it in Cursor or Claude?

Install the MCP server via the provided mcpb binary (covenant-guard.mcpb v0.1.1). Configure it in your client's MCP settings to connect to the local covenantd daemon over IPC or HTTP. See docs.opencovenant.org for setup details.

Do I need authentication?

Covenant uses local ed25519 identity and operator bearer tokens for daemon access. Peer-to-peer communication uses peer authentication and revocation. On-chain operations require Solana or EVM wallet signing; local-only operation does not.

What are the system requirements?

Covenant runs on Linux and macOS as an unprivileged daemon. Optional gVisor sandboxing requires Linux. The daemon is written in Rust; the operator console is Next.js. A Solana or EVM wallet is needed only for on-chain settlement.

Can I use it without blockchain?

Yes. Covenant works entirely locally with IPC, HTTP, and MCP surfaces. Blockchain integration (Solana settlement, Base/Robinhood Chain trust projection, x402 payments) is optional for on-chain receipt anchoring and multi-peer economics.

README (reference)

Source of truth, from the repository.

Covenant

CI kani License: Apache-2.0 DOI Rust

Open infrastructure for agent-native computing.

<p align="center"> <img src="./assets/architecture.png" alt="Covenant architecture: clients reach covenantd over CLI / IPC / HTTP / MCP / A2A; the daemon dispatches through eight primitives over a cross-cutting audit layer running on an unprivileged Linux/macOS host." width="900"/> </p>

Covenant sits below agent applications and above the host operating system. It owns the state, authority, and accountability concerns that recur across agent frameworks — scoped capabilities, durable memory, runtime isolation, append-only audit, and commit-scoped provenance — so individual frameworks can stop reinventing them.

<!-- METRICS:START -->

Status. Local control plane is real and live-tested (50 Rust crates, ~284k lines, 3870 source-discovered Rust tests including 486 live boundary tests). Production-grade sandboxing for hostile agent code and networked multi-peer operation are roadmap; the Solana settlement program is deployed on mainnet (credits, staking, slashing, on-chain receipt anchoring), but its daemon-driven economic lifecycle is not yet production. See BUILT.md for the explicit honesty boundary.

<!-- METRICS:END -->

Multi-chain reach. The trust layer also projects onto Base mainnet as signed statements any EVM contract verifies with one ecrecover — ERC-8004 agent registration, a deployed bond-receipt verifier, a registered EAS reputation schema, and an ENS CCIP-Read gateway (*.agents.opencovenant.eth) — while $CVNT stays a single Solana mint that is never bridged or wrapped and every per-call fee and bond is chain-local USDC. On-chain reputation writes and funded USDC bonds are registered but not yet exercised, while live x402 sellers settle chain-local USDC on both Solana and Base mainnet, and on Robinhood Chain mainnet (chain 4663) a USDG x402 payment and an on-chain bounded-spend escrow are proven with real USDG. See docs/multichain-value-capture.md.

Quick start

Try it without installing — sandbox.opencovenant.org. Public operator console wired to a live daemon, state resets every 12 hours.

To run it locally, build the daemon and CLI, register the sample agent, and start the daemon:

git clone https://github.com/open-covenant/covenant && cd covenant
cd agent-os && cargo build --workspace --exclude covenant-settlement-program --locked

# Register the example agent (daemon loads $COVENANT_HOME/agents/ at startup)
mkdir -p ~/.covenant/agents
cp -R ../examples/hello-agent ~/.covenant/agents/hello

# Start the daemon
./target/debug/covenantd

Then drive it from either surface — they share the same daemon, audit chain, and capability store.

CLI

./target/debug/covenant capabilities grant memory.write
./target/debug/covenant capabilities grant intent.subscribe
./target/debug/covenant intent "say hello"

Operator console — a Next.js UI for dispatching intents, browsing the audit chain, granting capabilities, and inspecting memory tiers.

cd agent-os/covenant-web
pnpm install --ignore-workspace
pnpm dev   # http://localhost:3000

The console proxies the daemon's HTTP gateway, injects the operator bearer token server-side, and renders every dispatch as a verifiable trace through the hash-chained audit log. See examples/hello-agent for the agent walkthrough, docs/demo.md for a CLI transcript, and deploy/README.md for shipping the console as a public sandbox on Render.

TypeScript SDK

Agent authors building on the deployed Solana settlement program can install @covenant-org/sdk from npm:

npm install @covenant-org/sdk @solana/web3.js

It turns every Covenant instruction (agent registration, $CVNT staking, task escrow, credit purchase, receipt anchoring) into a signed @solana/web3.js transaction, with the wire bytes encoded from the on-chain program IDLs so they cannot drift from what the program accepts. Apache-2.0, one runtime dependency. Source lives in packages/sdk.

Why Covenant

Software agents are moving from interactive assistance toward long-running engineering work. That shift changes the infrastructure problem. Agents need durable context, explicit authority, reliable tool access, recovery after interruption, and a record of what happened.

Conventional developer environments assume a human operator is present at every step. Blockchain systems assume verifiable state transitions, explicit authority, and durable coordination across independent actors. Covenant brings those assumptions into agent infrastructure:

  • Governance: intents, manifests, scoped permissions, review gates, and policy-aware dispatch.
  • Continuity: persistent memory, resumable task state, repair workflows, and structured handoff.
  • Accountability: append-only audit logs, integrity reports, signed actions, and commit-scoped provenance.
  • Interoperability: native tools, MCP integration, A2A messaging, local gateway APIs, and protocol adapters.
  • Execution: daemon-mediated runtime dispatch with budget enforcement and sandbox-aware agent manifests.
  • Settlement: local receipts and protocol scaffolding for accountable resource use and agent coordination economics.

Architecture

The system center is covenantd, a Rust daemon that owns local state and mediates privileged operations through IPC, an HTTP gateway, signed capabilities, audit logs, memory stores, and runtime dispatch.

#PrimitiveRole
1IntentNormalized request shapes for CLI, IPC, HTTP, routing, and daemon dispatch.
2RuntimeAgent execution with budget enforcement (projection-tick preempt and wall-clock backstop at cpu_ms_per_task), manifest contracts, trusted-local subprocesses, and opt-in Linux gVisor runner support.
3MemorySQLite-backed working, episodic, and long-term records with embedding hooks, ignore rules, drift reports, repair, and bounded compaction.
4IdentityLocal ed25519 identity, peer registry, operator tokens, token rotation, and peer revocation.
5PermissionsSigned capabilities with known-scope validation, dispatch-time enforcement, expiry, and revocation tombstones.
6CommsIPC frames, local HTTP gateway, MCP adapter, and A2A mailbox primitives.
7CompositorNext.js web console (agent-os/covenant-web), public landing/docs surface, and covenant-tui terminal UI with intent, memory, audit, capabilities, A2A, chain-receipts, and peer-registry views over the daemon IPC.
8SettlementLocal resource receipts and protocol scaffolding for agent coordination economics.

Audit underlies Identity, Permissions, and Settlement — append-only JSONL events, local hash-chain integrity reports, retention controls, signed actions, and audit-root attestations. The primary implementation lives in agent-os/, the Rust workspace containing the daemon, CLI, TUI, protocol crates, runtime, memory, identity, permissions, peer authentication, audit, MCP and A2A adapters, budget ledger, and settlement components. The surrounding monorepo contains public documentation, web surfaces, circuits, SDK packages, and supporting services.

See docs/audit-integrity.md, docs/capabilities.md, and agent-os/README.md for implementation details and validation evidence.

Capabilities

Covenant includes:

  • Rust daemon and CLI for local agent orchestration.
  • IPC and local HTTP gateway surfaces.
  • Signed capability lifecycle for implemented namespaces, including grant-time validation, expiry, revocation, and dispatch-time scope enforcement.
  • Peer authentication, operator token rotation, peer revocation, and peer-scoped A2A checks.
  • Append-only audit log with structured event types, bounded reads, retention purge, and local hash-chain verification.
  • SQLite-backed project memory across working, episodic, and long-term tiers.
  • MCP adapter, native tool integration, and A2A mailbox primitives.
  • Budget ledger primitives with daemon-backed pause checkpoint storage for budget exhaustion, shutdown drains, and single-use resume handoff.
  • Local settlement receipts for resource accounting.
  • Agent-to-service payments over HTTP 402 (x402): the daemon can pay for metered resources outbound, and Covenant operates a live x402 seller that settles in USDC on Solana mainnet (paid Covenant-Verified attestations, on-chain identity passports, and reputation reads), alongside an escrow service and an Ephemeral-Rollup credit facilitator.
  • Multi-chain trust projection onto Base mainnet: ERC-8004 agent registration, a deployed bond-receipt verifier and EAS reputation schema, EAS off-chain attestations for audit roots and reputation, and an ENS CCIP-Read gateway (*.agents.opencovenant.eth) that resolves to the canonical Solana identity — each verifiable with one ecrecover, no bridge and no cross-chain token. On-chain reputation scores and funded USDC bonds are not yet exercised. The same stateless verifier design and x402 rail also reach Robinhood Chain mainnet (chain 4663): a USDG x402 payment has settled on mainnet in real USDG, and a SpendGrantEscrow contract enforces bounded agent spend with its charge, release, and refund loop proven on Robinhood Chain testnet, while the bond and reputation verifiers are deployed but not yet exercised and no ERC-8004 identity is projected there. See docs/multichain-value-capture.md.
  • Commit-scoped provenance envelopes that bind task records, changed Git blobs, transition events, and validation evidence.
  • Unsigned or locally signed audit-root attestations for local integrity reports, with release-target binding to release-subject and release-scope manifests so a single attestation covers the audit log, the release artifact set, and the in-scope task set.
  • Opt-in live tests for daemon, CLI, runtime, and selected backend boundaries.
  • Source-built local installer for the daemon and CLI with a relative-path install manifest.
  • CI coverage for Rust, documentation, workflow linting, provenance verification, dependency audits, and CodeQL. Public live-test inventory comes from source; private workflow checkouts may add stricter matrix validation.

Validation

Run the scripts-only gate when the change does not need Rust tooling:

bash agent-os/scripts/validate.sh --scripts

Run the fast local gate from the repository root:

bash agent-os/scripts/validate.sh --quick

Run the full Rust validation gate:

bash agent-os/scripts/validate.sh

Verify committed provenance envelopes:

node agent-os/scripts/provenance.mjs verify-all

Build the public documentation surface:

pnpm --dir landing install --frozen-lockfile --ignore-workspace
pnpm --dir landing build

Run live boundary tests when host prerequisites are available:

cd agent-os
cargo test --workspace --exclude covenant-settlement-program -- --ignored live_

Inspect the public live coverage inventory:

bash agent-os/scripts/test-stats.sh

Research Direction

Covenant advances open infrastructure for:

  • governed autonomous software maintenance;
  • verifiable agent actions and commit-scoped provenance;
  • capability-scoped delegation across local and remote agents;
  • durable project memory for long-running work;
  • resumable task ownership across interruptions;
  • reproducible temporal state, correction, and proof-carrying replay;
  • policy-aware tool use and sandboxed execution;
  • audit-root attestations, public provenance, and agent coordination economics.

The Covenant Timeline integration applies the standalone Timeline kernel to release chronology. Its checked v0.1.0-alpha.1 run persists across a process restart, records an authoritative timestamp correction without rewriting the earlier state, and verifies proof-carrying conclusions at three historical record cuts with the exact published package @covenant-org/timeline@0.0.0-alpha.2. The original v0alpha1 checkpoint adapter remains available as a compatibility surface.

This is a shadow audit, not a release gate or a grant of authority. Timeline's preregistered frontier-model benchmark did not pass its standalone model-memory accuracy gate: it beat bounded narrative memory but did not beat stateless full-context structured extraction, producing a recorded decision of kill. Covenant uses the integration for deterministic temporal state, correction, replay, and proof verification—not as evidence that Timeline improves model accuracy. The complete benchmark result is public.

Citing

If you use Covenant in academic work or reference the design in a paper, please cite the whitepaper:

Covenant contributors. (2026). Covenant: A Capability-Based Operating Layer for Autonomous Software Engineering Agents. Zenodo. https://doi.org/10.5281/zenodo.20134416

@misc{covenant2026,
  author    = {Covenant contributors},
  title     = {Covenant: A Capability-Based Operating Layer for Autonomous Software Engineering Agents},
  year      = {2026},
  publisher = {Zenodo},
  doi       = {10.5281/zenodo.20134416},
  url       = {https://doi.org/10.5281/zenodo.20134416}
}

A copy of the PDF lives at opencovenant.org/paper.pdf; the LaTeX source is under paper/arxiv/.

Contributing

Covenant is systems infrastructure with security-sensitive boundaries. Contributions should include a validation plan, tests for changed behavior, and a clear statement of operational impact.

Start with CONTRIBUTING.md and ROADMAP.md. Changes touching identity, permissions, audit, runtime isolation, settlement, provenance, release automation, or CI should receive especially close review.

Security

Follow SECURITY.md for responsible disclosure. The runtime isolation boundary is tracked in docs/runtime-sandbox-security.md. Do not open public issues for vulnerabilities.

License

Apache-2.0. See LICENSE.

Related MCP servers

MIMizuki logo

Mizuki

Active

Fixed-price maintenance for public GitHub issues, paid in USDC on Solana.

8
Rust
Apache-2.0
View repository →
LILinear Project logo

Linear Project

Maintained

Scope-gated Linear project administration with optional GitHub and Obsidian evidence adapters

0
TypeScript
MIT
View repository →
OPOperations Pulse logo

Local-first operational pulses, durable ticket memory, and governed connection discovery.

0
JavaScript
MIT
View repository →

Read-only project readiness, dependency, evidence, and bounded local activity views.

0
JavaScript
Apache-2.0
View repository →
RURunGlance logo

RunGlance

Active

Read-only local progress, usage, lock state, work lists, and verified run receipts.

0
JavaScript
Apache-2.0
View repository →

Secure AI access to OpenOak tasks, notes, and Kanban boards.

View repository →