Package
@flashylabs/wdk-policy-guard
A spending-policy layer for wallets built on Tether’s WDK, or any wallet SDK. Grades a proposed spend against a per-agent envelope — chain, kind, asset and destination allowlists, a per-transaction cap, a daily cap — before anything signs, and returns ALLOW, ESCALATE, or DENY, always with a reason.
version source-available on GitHub (npm publish pending) · audit of 2026-10-04 · source: github.com/FlashyLabs/wdk-policy-guard
github.com/FlashyLabs/wdk-policy-guardWDK ships a policy engine with denial codes but nothing that grades a transfer against per-agent, per-day limits. Extracted from the policy layer built for Flashy Wallet’s own agent-facing envelope grading and open-sourced because the gap — spending limits for an automated caller holding a wallet — belongs to every team building on WDK, not just to us.
grade() is pure: it reads a DailyLedger’s reservations but never writes them, so a caller can preview a verdict without side effects. Reserving happens only after ALLOW, and is the caller’s own responsibility — which keeps the core function safe to call speculatively from a UI.
Commands
| Command | Does |
|---|---|
| npm test | run the 43-test suite — node’s built-in runner, no external services |
Edge cases — each one paid for once
Amounts are strings, never a Number, at every comparison
A spending cap compared as a JS Number silently stops being a cap once the amount crosses Number.MAX_SAFE_INTEGER. The package converts to BigInt exactly once, at the comparison, and the daily-cap and per-transaction-cap tests both exercise amounts at that boundary rather than trusting the arithmetic by inspection.
A self-contradictory envelope is caught before it can allow more than it claims
validateEnvelope() refuses an envelope whose autoApproveMax exceeds its perTxMax, or whose perTxMax exceeds its dailyMax — three numbers that read as independent limits on a form but are only a real limit when ordered correctly relative to one another.