
Rein Agent Risk Scale
io.github.reinlayerv0.1.0Updated Oct 7, 2026
Indicative Agent Risk Rating (A-E) self-check for AI agents that spend money. Not a credit rating.
Overview
Lets an assistant run a self-declared A-E risk self-check on an AI agent that can spend money, and explain the grade.
- What it does
- The remote MCP endpoint exposes three tools: self_check scores a deployment from structured answers about its controls, get_scale returns the A-E scale and what each grade means, and explain_grade says what a given grade requires. Scoring uses fixed published rules rather than a language model, so identical answers always produce the same grade. Responses list the findings that most explain the grade and the steps that would raise it.
- When to use it
- Use it when you want an assistant to assess or document the controls around an agent that can spend money, such as accountability, spend caps, payee limits, a stop switch, escalation, monitoring and incident history. It is a self-declared, indicative check, not a credit rating or investment advice.
- Requirements
- A remote streamable HTTP MCP endpoint; no sign-in, no API key and no environment variables are declared. Any MCP client can connect to the endpoint URL. The README's example scripts use Python and, for the agent examples, an OpenAI API key.
Installation
In SourceWeft
- Open Rein Agent Risk Scale in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"rein-agent-risk-scale": {
"type": "http",
"url": "https://rein-scale.mangowave-ad191d9c.eastus.azurecontainerapps.io/mcp"
}
}
}README
Rein Agent Risk Scale: MCP examples
Copy-paste examples that connect an AI agent to the Rein Agent Risk Scale self-check over MCP. The self-check gives an agent that can spend money an indicative Agent Risk Rating on an A-E scale, from the controls around it: who is accountable, spend caps and where they are enforced, payee limits, a stop switch and who holds it, human escalation, monitoring, history and incidents.
MCP endpoint (streamable HTTP, no sign-in):
The endpoint has three tools:
self_checkscores a deployment from structured answers;get_scalereturns the A-E scale and what each grade means;explain_gradesays what a grade requires.
Scoring is fixed, published rules with no language model, so the same answers always give the same grade.
Examples
Each example is one file of under 40 lines.
The three agent examples use OpenAI by default (export OPENAI_API_KEY=...). Pass any model your framework accepts to main() to use another.
- Tested: every example was run against the live endpoint on 7 October 2026 at the versions above.
- Watched weekly: a check runs them against the latest framework releases, because releases rename things.
mcp2.x renamed its HTTP client, and it now yields two streams instead of three.
Use it from any MCP client
There are docs written for agents at /skill.md and /llms.txt.
What a self-check is, and is not
- Indicative. The grade comes from your own answers. It is self-declared and unverified, so the rated grade stays
E (unverified)until the controls are verified. - Explained. The response lists the findings that most explain the grade and the steps that would raise it.
- Private by default. Answers and grades are stored under a pseudonymised record. A handle is published only if you set
publish_opt_in: true. Never send secrets or personal data. - Not a credit rating, not investment advice, and not an offer of credit.
License
MIT. See LICENSE.
Source: README.md at commit 536abb4
Tools
0Version history
1- v0.1.0LatestOct 7, 2026

