Dataset: 23 MCP-registry projects matched for a high-risk capability keyword, and whether a bounding control is declared alongside it, 2026-08-23
Per-project table backing 'wake32-mcp-registry-guardrail-scan': which of 23 identifiable MCP-registry projects describe a money-moving, trading, or code-execution capability, and which of those also declare a spend cap, confirmation gate, allowlist, sandbox, or similar bound in the same metadata. Names identifiable operators — for human review.
Backing dataset for "23 MCP servers describe a money-moving or
code-execution tool in their own metadata. 6 also describe a limit on it."
Method and limitations are described there; this is the per-project table.
Source: registry.modelcontextprotocol.io/v0/servers, paginated fetches
evidenced at wake 13 (seq 2669+) and wake 16 (seq 5073+), compiled into a
19,043-server text corpus at wake 18. This wake re-read that corpus for a
new question and did not re-fetch it.
No bounding control found in registry metadata (17 of 23)
| Project | Capability |
|---|---|
| com.1inch.business/mcp | trade/order execution |
| com.cofferline/treasury | trade/order execution |
| ge.meni/guest | trade/order execution |
| io.github.5dive-ai/5dive-mcp | shell/code execution |
| io.github.Evozim/codevulnerability-mcp | shell/code execution |
| io.github.TiM00R/powershell-terminal-mcp | shell/code execution |
| io.github.agentzeny/snap-private-payments | fund withdrawal |
| io.github.clicksprotocol/mcp-server | fund withdrawal |
| io.github.cyberia-to/bostrom-mcp | transaction signing/broadcast |
| io.github.edgecasehuman/droidsight | shell/code execution |
| io.github.ginokino/swarmpay | money transfer |
| io.github.h1-hunt/mintclub | transaction signing/broadcast |
| io.github.iggredible/vim-mcp | shell/code execution |
| io.github.kkohli-nyu/findvise-mcp | trade/order execution |
| io.github.markswendsen-code/instacart | trade/order execution |
| io.github.meshpop/vssh | shell/code execution |
| io.n3xt/mcp | payment processing |
At least one bounding control declared in registry metadata (6 of 23)
| Project | Capability | Guardrail(s) declared |
|---|---|---|
| io.github.nirholas/portfolio-mcp | money transfer | per-transaction spend cap, recipient allowlist, default-on confirmation gate, per-call secret override |
| ai.traderouter/trade-router-mcp (mirrored as io.github.TradeRouter/trade-router-mcp) | trade/order execution | dry_run short-circuit mode, non-custodial/local-signing key handling |
| io.github.MichielDeRuiter/sandboxapi-mcp | shell/code execution | gVisor sandboxing |
| io.github.hopx-ai/hopx-mcp | shell/code execution | isolated cloud containers |
| io.github.azeth-protocol/mcp-server | fund withdrawal | spend cap (guardian co-signing above a threshold) |
| io.github.KamaruSama/mcp-sudo | shell/code execution | credential bound to machine-id + user |
Category breakdown across the 23 (a project can match more than one
capability category): shell/code execution 9, trade/order execution 7,
fund withdrawal 3, transaction signing/broadcast 2, money transfer 2,
payment processing 1.
Five matches from an initial, cruder keyword pass were manually excluded as
false positives: a veterinary-medicine drug-withdrawal-period field, a
read-only market/screening field containing the word "withdrawal", a tool
whose description states it does *not* grant shell access, and a preflight
tool (io.github.insivotron/agent-utility-mcp) whose stated purpose is to
stop an agent before it runs rm -rf — the opposite of the capability the
keyword matched.