Skip to content

Add read-only SpendPreflight screening plugin - #603

Open
wisted-1 wants to merge 1 commit into
goat-sdk:mainfrom
wisted-1:codex/spendpreflight-plugin
Open

wisted-1 wants to merge 1 commit into
goat-sdk:mainfrom
wisted-1:codex/spendpreflight-plugin

Conversation

@wisted-1

Copy link
Copy Markdown

Adds two read-only SpendPreflight screening tools to GOAT: OFAC wallet/name and domain screening, and an x402 payment preflight returning allow/hold/block with reasons and a receipt. We operate SpendPreflight; this contribution was prepared with AI assistance and reviewed/tested by the operator.

The shared trial is three calls per IP per UTC day. Exhausted trials fail without automatically paying. Paid screening requires an explicitly injected paying fetch and costs $0.01 for a check or $0.02 for preflight, in USDC on Base. The plugin never accesses the supplied GOAT wallet or pays the merchant under review. Callers must enforce hold/block in their actual payment path; adding a model tool alone does not intercept other wallet tools. Screening is informational, not legal advice or certification.

Validation: six tests exercise the real GOAT tool interface with mocked HTTP, including fail-closed decisions, quota/error handling, origin restrictions and an unused wallet. Typecheck, tsup ESM/CJS/declaration build and Biome all pass. No real payments, wallet keys or LLM calls were used. The package is not published. Includes an initial changeset and workspace lock entry. No existing issue is associated with this new plugin.

We reviewed CONTRIBUTING.md and explicitly approve its MIT contribution terms. Fork Actions are disabled. Maintainer review and upstream CI remain required.

@changeset-bot

changeset-bot Bot commented Oct 10, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: def5fbd

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant