Skip to content

MCP for Claude, ChatGPT and Cursor

A prompt is not a limit. A model can misread a number, repeat itself, or be talked out of an instruction. Guard’s MCP server gives an agent tools that cannot break your limits, because every order still passes the same nine rules as any bot’s.

Tool (planned)What it does
accountequity, positions, stops, open orders
limitsyour rules and the risk state (active, halted for the day, stopped)
preview_order“what would you allow for this trade?”: the size and the rule that bound it, without sending
place_orderentry with its stop, through the nine rules
amend_stopmove a stop; only tighter is accepted
close_positionreduce or close; never blocked
killpull the kill switch

There is no tool to raise a limit, loosen a stop, resume after a halt or release the kill switch. Those need you, at the machine.

Example. You ask the agent to “go long ETH with 10x, stop 1% below”. It calls preview_order and gets back: “resized: open positions may be worth at most 5x equity”. It can report that to you; it cannot change it.

Edit claude_desktop_config.json (macOS: ~/Library/Application Support/Claude/claude_desktop_config.json; Windows: %APPDATA%\Claude\claude_desktop_config.json), then restart Claude Desktop.

{
"mcpServers": {
"zunder-guard": {
"command": "zunder-guard",
"args": ["mcp"]
}
}
}
Terminal window
claude mcp add zunder-guard -- zunder-guard mcp

The -- separates Claude Code’s options from the server’s command.

.cursor/mcp.json in a project, or ~/.cursor/mcp.json for all projects:

{
"mcpServers": {
"zunder-guard": {
"command": "zunder-guard",
"args": ["mcp"]
}
}
}
from agents.mcp import MCPServerStdio
async with MCPServerStdio(
name="zunder-guard",
params={"command": "zunder-guard", "args": ["mcp"]},
) as guard:
... # pass `guard` in the agent's mcp_servers

ChatGPT’s connectors reach MCP servers over the internet (SSE or streamable HTTP); a local server started from a command does not work there. Guard runs on your machine and listens on localhost only. So ChatGPT is not supported directly.

We do not recommend exposing Guard to the internet with a tunnel to make it work. A connection through the relay is being considered; it is not planned yet.

zunder-guard mcp talks to your running Guard on your machine. It holds no key of its own: the API wallet key stays in Guard.