I just shipped ragleap-agents v0.1.0. It's not a framework, it's a guardrail.
llm is any callable(prompt) -> str. No SDK lock-in.
The loop
llm -> JSON action -> validate against JSON Schema -> check ToolPolicy -> execute or pause for approval
Security model
python
ToolPolicy(
taints=True, # this tool reads untrusted data
outbound=True, # this tool sends data out
requires_approval=True
)
Rule: After a tainting tool has run, every later outbound tool needs approval.
No policy? Counted as both taints + outbound. Fail closed.
Tool outputs are capped, fenced, tags neutralized case-insensitively.
**
## Pause / Resume
**
StateStore is pluggable. InMemoryStateStore included.
Approve -> sends. Reject -> never sends. Replay -> ResumeError.
**
## Provenance you can check
**
PR #628 merged as d3e0c14, release PR #646 -> tag 0482515
CI 37889921507 success, publish run 37890106262 with trusted publishing.
Wheel: d305238f... Tar: 44cf1267... - identical in logs and PyPI.
41 tests, mutation-checked.
**
## Install
**
pip install ragleap-agents==0.1.0
pip install ragleap-tools==0.4.0 # dependency
This does NOT stop prompt injection. It limits blast radius IF your policies are accurate.
Code: PR #628 in antonyrag/ragleap-core
Top comments (0)