@mounaji_npm/agentlaw-core
v0.1.0
Published
Deterministic policy engine for AI agent tool calls: parse, sign, verify and evaluate AgentLaw policy manifests. No MCP dependency — embeddable anywhere.
Downloads
18
Maintainers
Readme
Private distribution copy of
@agentlaw/core(same source, published under the@mounaji_npmscope). Consumers point at it withAGENTLAW_CORE_MODULE.
@mounaji_npm/agentlaw-core
The deterministic policy engine behind AgentLaw: parse, sign, verify and evaluate policy manifests for AI agent tool calls. No MCP dependency, no LLM in the loop — embeddable in any agent host.
import { loadPolicy, evaluate } from "@mounaji_npm/agentlaw-core";
const policy = loadPolicy({ path: "policy.yaml", trustedPublicKeysPem: [pub] });
const verdict = evaluate(policy.compiled, { tool: "create_payment", args: { amount: 250 } });
// → { decision: "approve", ruleId: "pay-decision", ... } — same input, same verdict, every timeWhat it provides:
- Manifest schema + loader — YAML/JSON policy manifests (
agentlaw/v1alpha1), zod-validated, deny-by-default, first-match-wins. - Ed25519 signing — canonical JSON hashing, sign/verify with keys that never travel with the manifest.
- Evaluator — typed conditions over tool args, glob matching, rate limits, validity windows and session TTLs. Fail-closed everywhere.
Spec: RFC-0001 — policy manifest. For the CLI and MCP gateway built on this engine, see @agentlaw/gateway.
Apache-2.0.
