Local advisory pre-trade risk gate for agents. Never places orders.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
The pre-trade latch for your trading agent. Advisory-only.
Three things you need to know before anything else:
init / append / repair / prune / shadow report) are supported on Linux and macOS only. On Windows the package still imports, and the rule engine / Guard / CLI / MCP still compute decisions; those write paths fail closed with audit_platform_unsupported. Offline verify / read of a stopped snapshot remain available. Windows MCP is a limited integration path, not a full trusted audit chain.Honest boundary (please read): Deadlatch is advisory. It cannot force an agent that never calls it to call it, and it cannot stop an agent that ignores a BLOCK from submitting the order somewhere else. Whether the agent calls the guard and honors the result is the integrator's decision. Do not rely on this tool as a guarantee against loss β it is a gate, not an insurance policy.
The current install path is the verified
PyPI deadlatch==0.1.2,
published on 2026-09-22. The stable GitHub v0.1.2 Release
targets b072e8a4d4b053e1d5a428dbb9c47e06652fbf4c; its wheel/sdist assets match the PyPI originals.
The published MCP Registry name is io.github.Diabloluo/deadlatch at version 0.1.2,
verified active/latest on 2026-09-22. The local server.json matches that published version.
The command below starts the verified PyPI package directly.
MCP-first start:
--policy and --portfolio are required local files. --audit-path and --kill-switch-path are optional. Use fictional or your own simulated inputs only. Deadlatch is advisory-only: it never places orders and cannot stop an agent that never calls it. Option orders must use the broker's unique full contract code as symbol. A historical GitHub pre-release remains at v0.1.0.dev1; it is not the current install path.
Then:
PASS β BLOCK β local audit. Windows can import the package and run rule computation; it is not the audit-write Quick Start.That GitHub issue is public. Do not paste accounts, positions, orders, API keys, tokens, customer names, or private paths. Security defects must go through GitHub Security Advisories, not a public issue.
All three quick starts use fictional data and a temporary audit path. They are executed from the same source scripts by the test suite, so they cannot drift from the documentation. Full audit-write / MCP Quick Start requires Linux or macOS. Windows may import the library and evaluate rules; it will not initialize or append a durable audit collection.
Shows Guard.from_policy(...) β Order / Portfolio β guard.check(...):
a valid order returns PASS / 0; an oversized order returns BLOCK / 3 with the
hit rules; on BLOCK the example caller stops β no broker call is ever made.
Creates fresh inputs in a temp directory (dynamic timestamps β never goes stale),
then runs deadlatch check for PASS (exit 0), BLOCK (exit 3), an input
error (exit 4), and a --json check, plus shadow report --json over the audit.
Starts deadlatch-mcp as a real subprocess over stdio, lists the five tools,
and calls check_order once for PASS and once for BLOCK. policy / portfolio /
audit paths are server startup configuration β an agent cannot swap them as
tool arguments. BLOCK is a constraint the caller must honor; technically the guard
cannot force a fully bypassing agent to call it.
| Deadlatch is | Deadlatch is not |
|---|---|
| A local, deterministic risk gate evaluated before you submit | A signal generator, recommender, or portfolio optimizer |
| A library, a CLI, and a stdio MCP server β no broker connectivity, no policy mutation | A broker adapter, an execution engine, or a market feed |
| An auditable check: every evaluation is written to a local JSONL log | A cloud service, a database, or a telemetry sink |
| USD-only, single-leg orders, one snapshot per check (v0.1) | Multi-leg, multi-currency, Greeks/IV-aware (see limitations) |
Who should not use it: anyone expecting a profit guarantee, a backtest engine, a portfolio manager, or a tool that enforces itself. If the agent never calls the guard, or ignores a BLOCK, nothing in this repository can stop it.
exit 3); input/config errors β
exit 4; internal errors β exit 5. An uncertain state is never reported as PASS.symbol must be the broker's unique full contract code; never reuse
an underlying ticker across different expiries, strikes, or rights.exit 4); the MCP account-status tool fail-closes on mismatch.Write surface: the tool never modifies policy, portfolio, or
kill-switch state, never connects to a broker, and never places an order.
Two kinds of intentional local file writes exist:
Guard.check() / check_order append one sanitized
v2 record to a UTC day shard next to the logical audit path (30-day
retention). Append is a bounded tail write under a shared lock; it does not
rewrite history. A new collection needs one explicit
deadlatch audit init (or initialize_audit_state) before append;
Guard/MCP never auto-migrate. deadlatch shadow report and
deadlatch audit prune delete whole shard files that fall outside the
30-calendar-day window. deadlatch audit repair --quarantine still uses
lock/tmp files and os.replace when it isolates a truncated tail. Ordinary
append is not crash-atomic across files. POSIX locks are cross-process.
v0.1.2 durable audit writes are Linux/macOS only; Windows writers receive
audit_platform_unsupported and do not skip directory fsync to report success.deadlatch migrate --output <file>
writes the migrated document only when you explicitly pass --output.The public contract for these rules, Decimal thresholds, exit codes, and option-symbol requirements is docs/rules-spec.md.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/deadlatch)<a href="https://allmcps.com/mcp/deadlatch"><img src="https://allmcps.com/api/badge/deadlatch?style=directory" alt="Deadlatch on AllMCPs" /></a>