Pre-execution safety layer for autonomous agent wallets via MCP and x402.
Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.
https://api.actiongate.xyz/mcp6 tools · 632msrequest_api_keyProvision a prepaid ActionGate API key with $1.00 of starter credits for this operator email.Provision a prepaid ActionGate API key with $1.00 of starter credits for this operator email.
| Parameter | Type | Description |
|---|---|---|
| email* | string | Operator email address that should own the API key. |
balanceReturn the current prepaid credit balance and usage count for an ActionGate API key.Return the current prepaid credit balance and usage count for an ActionGate API key.
| Parameter | Type | Description |
|---|---|---|
| api_key* | string | ActionGate API key. |
top_upGenerate a Stripe Checkout link so the human operator can add prepaid credits to an existing ActionGate API key.Generate a Stripe Checkout link so the human operator can add prepaid credits to an existing ActionGate API key.
| Parameter | Type | Description |
|---|---|---|
| api_key* | string | Existing ActionGate API key to top up. |
| tier | string | Credit pack tier. Defaults to starter. |
risk_scoreScore the risk of a proposed agent action before execution. Paid via x402 or API key credits. Free tier: 20 risk score calls/day per client.Score the risk of a proposed agent action before execution. Paid via x402 or API key credits. Free tier: 20 risk score calls/day per client.
| Parameter | Type | Description |
|---|---|---|
| request_id | string | Optional caller-supplied request identifier for tracing and receipts. |
| actor* | object | Actor metadata for the agent proposing the action. |
| action* | object | Action payload to evaluate. Additional action-specific fields are accepted as passthrough. |
| context | object | Optional execution context such as chain state, balances, or treasury metadata. |
simulateEstimate cost, failure risk, and notable side effects for a proposed action. Paid via x402 or API key credits. Free tier: 20 simulate calls/day per client.Estimate cost, failure risk, and notable side effects for a proposed action. Paid via x402 or API key credits. Free tier: 20 simulate calls/day per client.
| Parameter | Type | Description |
|---|---|---|
| request_id | string | Optional caller-supplied request identifier for tracing and receipts. |
| actor* | object | Actor metadata for the agent proposing the action. |
| action* | object | Action payload to evaluate. Additional action-specific fields are accepted as passthrough. |
| context | object | Optional execution context such as chain state, balances, or treasury metadata. |
policy_gateApply treasury policy to a proposed action and return allow, deny, or allow-with-limits. Paid via x402 or API key credits. Free tier: 10 policy gate calls/day per client.Apply treasury policy to a proposed action and return allow, deny, or allow-with-limits. Paid via x402 or API key credits. Free tier: 10 policy gate calls/day per client.
| Parameter | Type | Description |
|---|---|---|
| request_id | string | Optional caller-supplied request identifier for tracing and receipts. |
| actor* | object | Actor metadata for the agent proposing the action. |
| action* | object | Action payload to evaluate. Additional action-specific fields are accepted as passthrough. |
| policy* | object | Policy pack input, including policy_id and any policy-specific override values. |
| context | object | Optional execution context such as chain state, balances, or treasury metadata. |
6 of 6 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
Pre-execution safety layer for autonomous agent wallets via MCP and x402.
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.