wallet_add_account
Create a new Algorand account, store it in the agent-wallet database with a nickname, and auto-switch to it if it is the first account. Returns address, public key, nickname, and index. The mnemonic is held internally by the MCP server and never returned to the agent.
This record as markdown: /tools/goplausible-algorand-mcp/wallet-add-account.md
What wallet_add_account does on Algorand MCP
AI agents use wallet_add_account to create or update resources in Algorand MCP, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Algorand MCP environment.
Why wallet_add_account is rated Medium
This tool creates and persists new blockchain accounts, which is a reversible write operation. While account creation itself is Write-category, the high severity reflects that compromised account creation in a financial blockchain context (Algorand) could facilitate unauthorized fund transfers or asset control.
From the tool's definition Tool creates a new Algorand account and stores it in the agent-wallet database, evidenced by phrases: 'Create a new Algorand account', 'store it in the agent-wallet database', and 'auto-switch to it'. This is data creation and modification.
Attacks that exploit this kind of access
The rule that runs wallet_add_account safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Algorand MCP, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For wallet_add_account, this is the rule to start with:
wallet_add_account stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Algorand MCP, apply this rule, and every wallet_add_account call is checked against it from then on.
Questions about wallet_add_account
Create a new Algorand account, store it in the agent-wallet database with a nickname, and auto-switch to it if it is the first account. Returns address, public key, nickname, and index. The mnemonic is held internally by the MCP server and never returned to the agent. It is categorised as a Write tool in the Algorand MCP MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
Register the Algorand MCP server in PolicyLayer and add a rule for wallet_add_account: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Algorand MCP. Nothing to install.
wallet_add_account is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the wallet_add_account rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for wallet_add_account. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
wallet_add_account is provided by the Algorand MCP server (goplausible/algorand-mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Algorand, and thousands of servers like it.
This server
Across the catalogue