npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

affixio-agent-guard

v0.1.0

Published

Free, local-first guard that checks an LLM agent's tool calls against policy before execution. Simulated local receipts only — not cryptographic attestation.

Downloads

161

Readme

affixio-agent-guardnpmMITTypeScriptZero DepsLocal First

Stop LLM agents spending money or leaking secrets. 5 lines. No API keys. Runs offline.

Free, local-first guard that checks an LLM agent's tool calls against policy before the tool runs. TypeScript, ESM, Node 20+. No API keys, no cloud services, no network calls.

Why?

Agent demos ship with allowedTools: ['*']. One prompt injection and it calls payments.refund. This blocks it before it runs.

⚠️ This is a developer demo. It does not replace AffixIO's paid production verification, hosted controls, ML-DSA attestations, enterprise audit or payment features. Receipts here are local simulations, not cryptographic attestations.

Install

npm install affixio-agent-guard

Usage

import { createGuard, checkToolCall, writeReceipt } from 'affixio-agent-guard';

const policy = {
  allowedTools: ['payments.create', 'crm.lookupCustomer'],
  allowedHosts: ['api.example.com'],
  maxAmount: 500,
  blockedSecrets: ['sk_live_', 'AKIA'],
  requireApprovalFor: ['payments.refund'],
};

const decision = checkToolCall(
  { tool: 'payments.create', host: 'api.example.com', amount: 120, args: { customer: 'cust_42' } },
  policy,
);
// { allowed, reason, receipt }

if (decision.allowed) {
  // execute the tool call in your agent runtime
  console.log(decision.reason, decision.receipt.requestHash);
} else {
  console.warn('Blocked:', decision.reason);
}

// Optionally persist the local simulation receipt
const path = await writeReceipt(decision.receipt); // writes .affixio/receipt-<ts>.json

// Or bind a policy once:
const guard = createGuard(policy);
guard.check({ tool: 'payments.create', args: {} });

CLI demo

npx affixio-agent-guard demo

Shows one allowed mock MCP-style call and one denied call containing a fake secret, writing local simulation receipts to .affixio/.

Policy

| Key | Meaning | | -------------------- | -------------------------------------------------------------- | | allowedTools | Tool names the agent may call (exact match) | | allowedHosts | Hosts tools may contact (exact match; calls without a host pass this check) | | maxAmount | Maximum permitted monetary amount | | blockedSecrets | Substrings that must never appear in tool arguments | | requireApprovalFor | Tools that always require explicit human approval (fail closed) |

Threat model & clear limits

What it does: deterministic, fail-closed policy check of a single tool call; SHA-256 hash (Node crypto only) of the canonical request; local JSON receipts; zero network.

What it does not do:

  • Not a cryptographic attestation. Receipts are local, unsigned JSON. Anyone can edit them.
  • Not tamper-evident in production. The request hash binds the receipt to the request, but the receipt itself is not signed, timestamped by a trusted authority, or anchored.
  • Not enforcement. The guard only returns a decision; your agent runtime must honor it. A compromised runtime can bypass it entirely.
  • Not an approval workflow. requireApprovalFor denies unless you build your own approval step.
  • Not secret-scanning proof. Only exact substring matches of the patterns you configure.
  • No network, keys or cloud. By design, so it cannot verify counterparty identity, authorization chains or real-world state.

Paid upgrade path: when you need production enforcement, replace the local simulated receipt with AffixIO's real proof and authorisation flow — hosted policy controls, ML-DSA attestations and enterprise audit.

Exports

createGuard(policy), checkToolCall(request, policy), writeReceipt(receipt, dir?), runDemo(), plus canonicalRequestHash and all TypeScript types.

Development

npm install
npm test
npm run build
node dist/cli.js demo

Clean install

If npm test or npm run build fail with sh: 1: vitest: Permission denied / sh: 1: tsc: Permission denied (e.g. after copying the project, when the execute bit on node_modules/.bin binaries is lost), do a clean reinstall:

cd ~/Desktop/affixio-agent-guard
rm -rf node_modules package-lock.json
npm install
npm test
npm run build
node dist/cli.js demo

MIT.