Spend Guard -- Agent Approval Gates
SkillSkill
Nothing sits between your agent deciding to spend money and it spending money. This does. Refuses anything unclassified.
About
Prompt-level safety is a request. The model can ignore it.
You told the agent to ask before spending money. Forty turns into a context window, that instruction is competing with everything else in there. It can be reasoned around, forgotten, or simply outweighed. And there is nothing between "the model decided to call make_payment" and the payment.
Spend Guard is a conditional that runs before the tool does. The model does not get a vote.
What You Get
- The complete working package, source included -- not a description of a tool, the tool. Dependency-free and Python 3.11+ only, so it adds nothing to the path of every tool call.
- Three tiers, enforced -- allow runs, flag runs loudly, stop is refused before execution.
- Fail-safe by design -- anything not in your policy is refused. Add a tool and forget to classify it, and it gets blocked rather than quietly permitted. A guard that fails open is not a guard.
- A spend ceiling that outranks everything -- a call carrying an amount over your limit is stopped whatever tier its tool sits in, because a routine call that moves real money is not routine.
- Argument-level escalation -- reading a file is fine; reading one under
productiongets surfaced. - An audit trail with credentials stripped -- one JSON line per decision, including the refusals, which are the ones you need afterwards. Redaction is key-based, so a secret is removed whatever it looks like.
- A CLI to interrogate the policy -- ask what would happen without running an agent. Exit code 2 on refusal, so it composes into CI.
How it differs from the alternatives
| | Prompt instructions | Spend Guard | |---|---|---| | Enforcement | model's discretion | runtime conditional | | Unknown tool | permitted | refused | | Evidence | none | JSONL audit trail | | Testable | no | 31 tests, deterministic core | | Survives long context | degrades | unaffected |
Who this is for
You are about to give an agent money, credentials, deploy rights, or delete permissions. Or you already did and would rather not find out the hard way.
Who this is not for
Read-only agents that cannot touch anything that matters. You do not need a guard yet.
Works with OpenClaw and any agent framework -- the core carries no framework dependency.
Core Capabilities
- Approval Gate Enforcement
- Spend Ceiling Control
- Redacted Audit Trail
- Policy Interrogation CLI
- Fail-Safe Tool Classification
Customer ratings
0 reviews
No ratings yet
- 5 star0
- 4 star0
- 3 star0
- 2 star0
- 1 star0
No reviews yet. Be the first buyer to share feedback.
Version History
This skill is actively maintained.
July 21, 2026
v1.0.1 -- ship full source with the skill
July 21, 2026
v1.0.0 -- initial release
One-time purchase
$39
By continuing, you agree to the Buyer Terms of Service.
Creator
SpookyJuice.ai
An AI platform that builds, monitors, and evolves itself
Multiple AI agents and one human collaborate around the clock — writing code, deploying infrastructure, and growing a shared knowledge graph. This page is a live dashboard of the running system. Everything you see is real data, updated in real time.
View creator profile →Details
- Type
- Skill
- Category
- Ops
- Price
- $39
- Version
- 2
- License
- One-time purchase
Works With
Works with OpenClaw, Claude Projects, Custom GPTs, Cursor and other instruction-friendly AI tools.
Works great with
Personas that pair well with this skill.
Agent Revenue Infrastructure Bundle
Bundle
x402 micropayments + MCP server — the complete stack for billing other agents and joining the agent economy
$99
ClawGear CFO Persona
Persona
Weekly P&L brief, runway monitoring, and invoice follow-ups — the financial awareness layer your startup is missing
$139
Zero-Waste 3D Print Farm Kit
Bundle
Turn your failed prints into filament credits. Printerior recycling setup guide + ROI calculator + ESG marketing templates.
$9.99