{"_id":"@covenant-org/robinhood-guard-proxy","name":"@covenant-org/robinhood-guard-proxy","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@covenant-org/robinhood-guard-proxy","version":"0.1.0","mcpName":"org.opencovenant/robinhood-guard","description":"A Covenant Guard MCP proxy in front of Robinhood's agentic trading MCP: policy enforced before an order is placed, every decision signed.","type":"module","main":"dist/server.js","bin":{"covenant-robinhood-guard":"dist/server.js"},"keywords":["mcp","robinhood","trading","guard","covenant"],"license":"MIT","repository":{"type":"git","url":"git+https://github.com/open-covenant/covenant.git"},"homepage":"https://opencovenant.org","engines":{"node":">=22"},"publishConfig":{"access":"public"},"scripts":{"build":"rm -rf dist && tsc -p tsconfig.build.json","start":"node dist/server.js","typecheck":"tsc -p tsconfig.json --noEmit","test":"vitest run --passWithNoTests","lint":"echo skip","clean":"rm -rf dist"},"dependencies":{"@modelcontextprotocol/sdk":"1.26.0","bs58":"^6.0.0","zod":"4.3.6"},"devDependencies":{"@types/node":"25.6.0","typescript":"6.0.3","vitest":"^4.1.5"},"_id":"@covenant-org/robinhood-guard-proxy@0.1.0","bugs":{"url":"https://github.com/open-covenant/covenant/issues"},"_nodeVersion":"24.14.0","_npmVersion":"11.9.0","dist":{"integrity":"sha512-hr1B/gAjZkWFlbYQcLvMN1qUu6sqHinqj2DAYwEUr7qnx4pmCuZ/+KSdlQ5HEZCiurtH3cfDsskpZOtflkSTng==","shasum":"5a42d5a8bcc62ac1278d58572ca71c619bdc2ea5","tarball":"https://registry.npmjs.org/@covenant-org/robinhood-guard-proxy/-/robinhood-guard-proxy-0.1.0.tgz","fileCount":6,"unpackedSize":18166,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDQeiM0c5rD24hNqplbT+niY7Pvna6H5rBJg8Qt44qEMQIgJoXw09t7cC5Ue3OEgrqDzwauccRvY7I25Fe7Syf6ijo="}]},"_npmUser":{"name":"covenant-user","email":"contact@opencovenant.org"},"directories":{},"maintainers":[{"name":"covenant-user","email":"contact@opencovenant.org"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/robinhood-guard-proxy_0.1.0_1784637751713_0.6437723629427701"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-21T12:42:31.256Z","0.1.0":"2026-07-21T12:42:31.888Z","modified":"2026-07-21T12:42:32.290Z"},"maintainers":[{"name":"covenant-user","email":"contact@opencovenant.org"}],"description":"A Covenant Guard MCP proxy in front of Robinhood's agentic trading MCP: policy enforced before an order is placed, every decision signed.","homepage":"https://opencovenant.org","keywords":["mcp","robinhood","trading","guard","covenant"],"repository":{"type":"git","url":"git+https://github.com/open-covenant/covenant.git"},"bugs":{"url":"https://github.com/open-covenant/covenant/issues"},"license":"MIT","readme":"# @covenant-org/robinhood-guard-proxy\n\nA Covenant Guard MCP proxy that sits in front of Robinhood's agentic trading MCP.\nYour agent connects to this instead of Robinhood directly. Reads and non-order\ntools pass straight through; an order tool is checked against your policy first,\nso a refused order never reaches the venue, and every decision (placed or\nrefused) is signed.\n\nYou bring your own Robinhood agentic account. The proxy holds no funds and runs\nlocally.\n\n## Use it\n\n```bash\nclaude mcp add robinhood-guard --transport stdio -- npx -y @covenant-org/robinhood-guard-proxy\n```\n\nEnvironment:\n\n- `ROBINHOOD_MCP_URL` — upstream agentic MCP (default `https://agent.robinhood.com/mcp/trading`)\n- `ROBINHOOD_MCP_AUTH` — bearer token forwarded to the upstream\n- `COVENANT_TRADING_POLICY` — path to a policy JSON (unset ⇒ deny all orders)\n- `COVENANT_GUARD_ATTESTOR_KEYPAIR` — base64 ed25519 seed for signing receipts (unset ⇒ ephemeral, pubkey logged)\n- `COVENANT_GUARD_ORDER_TOOLS` — comma-separated exact order-tool names, overriding the heuristic\n\nPolicy JSON (same schema as the covenant-robinhood crate):\n\n```json\n{\n  \"venue\": \"robinhood\",\n  \"caps\": { \"per_order_usd\": 500, \"daily_notional_usd\": 2000 },\n  \"risk\": { \"daily_loss_stop_usd\": 300 },\n  \"universe\": { \"allow\": [\"BTC-USD\", \"ETH-USD\"], \"sides\": [\"buy\"] },\n  \"order_types\": [\"market\"],\n  \"rate\": { \"max_orders_per_min\": 10 },\n  \"approvals\": { \"require_human_over_usd\": 400 }\n}\n```\n\n## To confirm against a live account\n\nRobinhood's agentic MCP schema isn't public, so two things need a real (US-only)\nagentic account to pin down, both overridable without a code change:\n\n- the exact order-tool names — set `COVENANT_GUARD_ORDER_TOOLS` if the heuristic\n  misses one (it errs toward intercepting anything that looks like an order);\n- how the order value arrives in the tool arguments — the extractor reads common\n  dollar-amount fields and fails closed when it can't determine a value and a USD\n  cap is set.\n","readmeFilename":"README.md","_rev":"1-f50851ad988351c2cecdd94396a6de72"}