The Aave MCP Prepares, the Agent Wallet Signs — But Who Judges?
Canonical: https://scriptmasterlabs.com/aave-mcp-metamask-agent-wallet
On October 9, 2026, Aave announced its MCP server connects to MetaMask's Agent Wallet, with a hard split of duties: the Aave MCP prepares Aave actions, and the Agent Wallet signs and submits them.
The wiring, briefly:
-
Sept 9, 2026 — Aave launches its official MCP server at
https://mcp.aave.com(no API key). It exposes Aave V3/V4 data plus transaction-building tools: supply, borrow, withdraw, repay, manage collateral, token swaps, and reads on positions, rates, health factors. - The design — the server returns unsigned transactions or typed data. It holds no private keys. Authorization and signing are entirely the wallet's job.
- Oct 9, 2026 — the MetaMask connection: the self-custodial Agent Wallet authorizes and submits what the MCP prepares, under user-defined rules: spending limits, protocol restrictions, Guard Mode vs Beast Mode — plus transaction simulation, Blockaid threat scanning, MEV protection.
The gap nobody closes
Static rules catch bad bytes: malformed transactions, malicious contracts, over-cap spend. They do not catch bad judgment. A 95%-LTV borrow passes every static check — under the limit, simulates clean, not malicious — and sits one price wick from liquidation. Simulation answers "will it execute." Blockaid answers "is it an attack." The cap answers "is it small enough." None answers "was this instruction sound."
Tested live this morning
Two Aave-MCP-shaped instructions, scored against a live decision gate (bands: ≥0.80 auto / 0.50–0.79 hold / <0.50 escalate), Oct 10, 2026:
- Q1 — 2,000 USDC borrow at 95% LTV on Aave V3, wallet auto-signs → confidence 0.5, advisory — hold for human review
- Q2 — read-only USDC supply-APY lookup, no transaction prepared → confidence 0.5, advisory — hold for human review
The honest finding: the uncalibrated heuristic (local-heuristic-v1, calibrated=false) held both for review. It could not discriminate the liquidation-edge borrow from the harmless rate lookup. Fail-closed is safe, but undiscriminating — calibrated judgment, not static caps, is the upgrade, and it belongs between preparation and signing: exactly the seam this integration leaves open.
The 5-step DIY
- Connect read-only first: point an MCP client at
https://mcp.aave.com, ask for rates and a health factor, verify the shape. - Lock the wallet rules: spending limit, protocol restricted to Aave, Guard Mode on.
- Score every prepared transaction before signing:
POST /api/harness/decidewith the instruction as a choice question. - Band it: ≥0.80 auto-sign, 0.50–0.79 hold, <0.50 escalate and log. Never auto-sign an unsigned MCP transaction on static rules alone.
- Keep the ledger: instruction, confidence, band, action, timestamp per decision.
Full receipts, curl shapes, Claim JSON-LD, and honest caveats on the canonical page.
Top comments (0)