Monarch
Agent FilesRaw agent sources are listed in /docs/manifest.json
# Monarch Shield North Star

Fail automatic x402 v2 buyer calls that have no recognized policy seam.

## Product contract

Doctor parses JavaScript and TypeScript, tracks selected official x402 imports and client aliases, and fails when a supported paid call has no recognized, earlier policy seam on the same client path.

```bash
npx @monarch-shield/x402@0.2.0 doctor --ci --strict
```

## Evidence contract

Never describe a passing scan as proof that the policy is correct or the payment is safe.

Doctor is single-file static analysis. Custom and cross-file wrappers, unsupported languages, computed code, and unrecognized x402 APIs remain outside the contract. It can report false positives.

Doctor does not verify policy quality, provider identity, destination correctness, amounts, networks, authorization, simulation, settlement, delivery, legal requirements, or compliance.

## Credibility contract

- first-party fixtures are labeled first-party
- no external adoption is claimed without independently reviewed evidence
- local tests do not prove npm publication
- a GitHub tag does not prove the Action works in another repository
- deployment does not prove the live site serves the intended commit
- no partnership, endorsement, grant, or marketplace listing is implied by a reference fixture

## Adoption contract

Earn usage with a narrow open-source tool:

1. publish reproducible scanner behavior
2. make installation and CI adoption easy
3. collect minimal false-positive and false-negative fixtures
4. improve the heuristic against a locked benchmark
5. list the tool only where its static-analysis job matches the marketplace

Hosted reporting and runtime policy are not part of Monarch Shield 0.2.0.