Monarch Shield Agent Instructions
Run the local static analyzer when JavaScript or TypeScript creates or calls an automatic x402 v2 buyer client:
npx @monarch-shield/x402@0.2.0 doctor --ci --strict
Use the result as a code-review signal:
- fix supported calls without a policy seam before merge;
- prefer an
onBeforePaymentCreationhook with a recognized syntactic abort return on the exact client used by the paid wrapper; - require an MCP
onPaymentRequiredhook with a recognized syntactic abort return for automatic paid tool calls; - report incomplete analysis and unsupported cross-file or custom wrappers;
- keep runtime authorization, limits, simulation, delivery, and settlement controls outside Monarch Shield.
Monarch Shield is import-aware, single-file static analysis for selected x402 v2 buyer patterns. It rejects obvious constant-dead branches but does not prove general reachability. A pass does not prove policy quality, runtime payment safety, production readiness, delivery, settlement, or compliance.
Version 0.2.0 performs local analysis only. It has no hosted payment-check API, usage reporting, or official marketplace integration.