DEV Community

RagLeap
RagLeap

Posted on

ragleap-agents v0.1.0: A Fail-Closed Act-Observe Loop in 200 Lines

I just shipped ragleap-agents v0.1.0. It's not a framework, it's a guardrail.

llm is any callable(prompt) -> str. No SDK lock-in.

The loop

llm -> JSON action -> validate against JSON Schema -> check ToolPolicy -> execute or pause for approval

Security model


python
ToolPolicy(
  taints=True,      # this tool reads untrusted data
  outbound=True,    # this tool sends data out
  requires_approval=True
)

Rule: After a tainting tool has run, every later outbound tool needs approval.

No policy? Counted as both taints + outbound. Fail closed.

Tool outputs are capped, fenced, tags neutralized case-insensitively.


**

## Pause / Resume
**

StateStore is pluggable. InMemoryStateStore included.

Approve -> sends. Reject -> never sends. Replay -> ResumeError.

**

## Provenance you can check
**

PR #628 merged as d3e0c14, release PR #646 -> tag 0482515
CI 37889921507 success, publish run 37890106262 with trusted publishing.

Wheel: d305238f... Tar: 44cf1267... - identical in logs and PyPI.

41 tests, mutation-checked.

**

## Install
**

pip install ragleap-agents==0.1.0
pip install ragleap-tools==0.4.0  # dependency

This does NOT stop prompt injection. It limits blast radius IF your policies are accurate.

Code: PR #628 in antonyrag/ragleap-core

Enter fullscreen mode Exit fullscreen mode

Top comments (0)