@scopebond/framework
v0.3.2
Published
Scopebond framework plugins — one import so an agent checks your policy before every tool call and records a signed receipt. Cooperative (M0) in-process guard with Vercel AI SDK and LangGraph/LangChain adapters.
Maintainers
Readme
@scopebond/framework
One import so an agent checks your policy before every tool call and records a signed receipt — the same policy your other agents use. Cooperative (M0): the framework asks Scopebond first and honors the answer.
- Label: cooperative · prevents if honored. Enforcement depends on the framework honoring the guard; code that calls a tool outside the framework's tool loop is not covered.
- Receipt class: signed-intent — the agent's key signs the intent, so it is the strongest evidence class.
Adapters for the Vercel AI SDK and LangGraph/LangChain ship here; each framework is an optional peer, never a dependency.
Vercel AI SDK
import { createToolGuard, wrapVercelTools } from "@scopebond/framework";
import { generateText } from "ai";
const guard = createToolGuard({ policy, agentKeyPem, manifest: { transfer: "payout.create" } });
const result = await generateText({
model,
tools: wrapVercelTools(myTools, guard), // each tool checks policy before it runs
prompt,
});A denied call returns a synthetic denial result to the model instead of executing.
LangGraph / LangChain
import { createToolGuard, wrapLangGraphTool } from "@scopebond/framework";
const guard = createToolGuard({ policy, agentKeyPem });
const guardedSearch = wrapLangGraphTool(searchTool, guard);
// use guardedSearch anywhere the original tool went (ToolNode, bindTools, …)Other frameworks
Any framework whose tools have a name and an async execute is covered:
import { guardedTool, wrapOpenAITools, guardExecute } from "@scopebond/framework";
const guarded = guardedTool(myTool, guard); // { name, execute }
const guardedList = wrapOpenAITools(agentTools, guard); // OpenAI Agents SDK array
const safeExecute = guardExecute("send_email", sendEmail, guard); // any functionPolicy
Tools are governed by name via the Action Taxonomy's tool.<name> type (or a
manifest mapping to a richer type). "Allow search and read; cap transfers":
{
"vocabulary_version": "1.0", "policy_id": "agent", "version": 1,
"clauses": [
{ "id": "tools", "type": "action_allowlist", "mode": "enforce", "action_types": ["tool.search", "tool.read", "payout.create"] },
{ "id": "cap", "type": "spend_limit", "mode": "enforce", "asset": "USDC", "max_per_action": 100000 }
]
}An unlisted tool is denied by the closed allowlist (fail closed). createToolGuard
returns { check(name, args) } if you drive the tool loop yourself.
Experimental alpha; controlled test use only.
