@agent-monitor/agent
v4.1.1
Published
Safe tools, security guardrails, ActionInterceptor, ApprovalManager, and DeepSeek coding agent for Agent Monitor
Readme
@agent-monitor/agent
Action interception, security guardrails, safe tool definitions, approval management, and reference DeepSeek autonomous agent runtime.
Overview
@agent-monitor/agent sits between the AI model and the operating system. It provides the runtime interception harness, containment guardrails, safe tools, and the DeepSeek client implementation.
Key Modules
ActionInterceptor:- Intercepts tool calls before execution.
- Enforces authoritative pre- and post-approval Kill Switch circuit breaker.
- Enforces workspace containment and symlink checks.
- Evaluates deterministic policies and coordinates human approval.
- Emits strictly sequenced audit events.
ApprovalManager:- Manages pending approval requests.
- Handles asynchronous resolution and expiration timeouts.
tools/:- Safe tools:
readFileTool,writeFileTool,listFilesTool,runCommandTool. - Guardrails:
resolveSafeWorkspacePath(iterative URL decoding, POSIX and Windows backslash normalization, canonical symlink validation). - Child Process Isolation:
runCommandToolsanitizesprocess.envto prevent accidental credential leakage to child processes.
- Safe tools:
deepseek/:DeepSeekClient: Lightweight HTTP client for DeepSeek Chat API.DeepSeekCodingAgent: Reference autonomous coding agent loop.
Installation
npm install @agent-monitor/agent @agent-monitor/coreExample Usage
import {
ActionInterceptor,
readFileTool,
writeFileTool,
runCommandTool,
} from "@agent-monitor/agent";
import { PolicyEngine } from "@agent-monitor/core";
const interceptor = new ActionInterceptor({
sink: {
emit: async (event) => console.log("Event:", event.type),
},
policyEngine: new PolicyEngine(),
});
interceptor.registerTool(readFileTool);
interceptor.registerTool(writeFileTool);
interceptor.registerTool(runCommandTool);
const output = await interceptor.invoke(
"read_file",
{ path: "package.json" },
{
sessionId: "ses_123",
agentId: "my-agent",
workspaceRoot: process.cwd(),
},
);