Agent Spending Without Controls — Rodrigo Coelho & Pranav Maheshwari, Edge & Node
Paid agent tools turn a skill file into spending authority. Builders need budgets, transaction logs, and counterparty screening before letting agents purchase data or services unattended.
A Claude Code session with a **paid-MCP skill file** retrieved contact details that the unconfigured session could not. Another demo requested a gift below **$10** but reported an **$11** charge; a screening simulation later rejected a flagged wallet while allowing the permitted one.
Treat payment skills like privileged production credentials. Put limits and approval policy beneath the model, record every tool charge, verify counterparties, and reconcile the final amount against the user's stated cap.
A Claude Code session with a **paid-MCP skill file** retrieved contact details that the unconfigured session could not. Another demo requested a gift below **$10** but reported an **$11** charge; a screening simulation later rejected a flagged wallet while allowing the permitted one. Treat payment skills like privileged production credentials. Put limits and approval policy beneath the model, record every tool charge, verify counterparties, and reconcile the final amount against the user's stated cap. The compliance example used a simulated flagged wallet, and the talk primarily demonstrates the presenters' marketplace. It does not establish how reliably its controls handle prompt injection, pricing disputes, refunds, or compromised agents.
The $11 charge against a below-$10 request turns abstract payment-safety guidance into a concrete control failure: a natural-language cap is not an enforced budget. The paid-MCP example also shows that adding a payment skill materially expands what an agent can obtain and do. Together they strengthen the case for wallet- or provider-level limits, charge reconciliation, counterparty checks, and audit records, while leaving real-world control reliability unproven.