Skip to main content

agent-second-fuse

Independent fail-closed second fuse for AI agents. It sits outside the agent it protects, judges every tool call before it runs, signs each decision with an Ed25519 receipt, and chains those receipts into a tamper-evident ledger. From that ledger you can export an incident report aligned with the 2026-10-09 White House Superintelligence Force (SIF) mandate on mandatory reporting of significant AI incidents.

tool call
   │
   ▼
GuardedKernel.guard()
   │  rule engine (fail-closed, short-circuit):
   │    tool ACL → parameter rules → dangerous patterns / exfiltration
   │    → constitution immutability → identity continuity
   ▼
Ed25519 decision receipt  ──►  append-only hash-chained ledger
   │
   ▼
incident report (Markdown / JSON)

Why it exists

Logs being viewable is not the same as behavior being controllable. An agent that can reach a shell, an outbound network call, or a funds transfer needs a check that is independent of the model's cooperation: a policy it cannot talk its way past, plus evidence a third party can verify offline. On 2026-10-09 the White House Superintelligence Force made prompt incident reporting a national-security obligation the same day a major lab disclosed that a test model had submitted unauthorized information to a government website and that tool isolation had failed. This package targets both halves: stop the action, preserve the proof.

Install

pip install agent-second-fuse

Quick start (zero config)

from agent_runtime_guard import GuardedKernel, PolicyConfig

kernel = GuardedKernel.bootstrap(
    PolicyConfig.builtin("general"),
    evidence_dir=".guard-evidence",
    agent_id="checkout-agent",
)

outcome = kernel.guard("execute_shell", {"command": "sudo rm -rf /"})
outcome.blocked            # True
outcome.receipt.receipt_id # 'r...'

Every call is signed and appended to the ledger:

# verify the whole ledger offline (no network): chain + every signature
arg-fuse inspect --evidence .guard-evidence

# export an incident report
arg-fuse report --evidence .guard-evidence \
    --title "Checkout agent incident" --reporter "Your team" \
    --out incident.md

What the guard checks

  • Tool ACL — allow/deny lists; unknown tools are blocked by default (fail-closed).
  • Parameter rules — typed numeric/enum/regex checks on named arguments (gt/lt/gte/lte/eq/neq/in/not_in/regex, nested field paths).
  • Dangerous patterns & data exfiltration — destructive commands, curl -d @, nc, /dev/tcp, delimiter-chained exfiltration, plus Base64/Hex/NFKC/whitespace normalization so encoded variants still match. Outbound targets can be restricted against an allow list with CIDR support.
  • Constitution immutability — protected dimensions cannot be modified.
  • Identity continuity — persona/directive drift is detected against a baseline.

Signed receipts

Each decision is a JSON envelope; the signature covers JCS(payload) only, so the signature field itself is never part of the signed input. Verification needs just the local public key and never touches the network:

from agent_runtime_guard import Receipt, verify_receipt
from agent_runtime_guard.keys import load_public_key

pub = load_public_key(open(".guard-evidence/keys/verifying.pub","rb").read())
receipt = Receipt.from_json(open("receipt.json").read())
verify_receipt(receipt, pub)  # True/False

Honest scope: the signing key is self-generated. Receipts provide offline verifiability and tamper evidence, not third-party CA identity. For external trust, register the public key in your own root of trust.

CLI

arg-fuse guard     # judge one call, sign + append to the ledger
arg-fuse inspect   # verify a receipt or the entire ledger offline
arg-fuse report    # build an incident report (md/json)
arg-fuse keys      # show the local public key and kid
arg-fuse validate  # validate a policy file
arg-fuse demo      # run the built-in second-fuse demo

Incident report scope

The report states only facts recorded in the ledger with their timestamps and includes a hash-chain integrity check. Actions outside instrumented coverage are not included. Whether an event is legally "reportable" under any specific regulation is a determination for your legal team; the report supplies evidence, not that conclusion.

License

MIT. See LICENSE.

Metadata

Release files for agent-second-fuse 0.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for agent-second-fuse 0.2.1
File Size Uploaded
agent_second_fuse-0.2.1.tar.gz 36.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for agent-second-fuse 0.2.1
File Interpreter ABI Platform
agent_second_fuse-0.2.1-py3-none-any.whl Python 3 none any Details

Total release size: 79.6 kB

Release files / agent_second_fuse-0.2.1.tar.gz

Download URL agent_second_fuse-0.2.1.tar.gz
Size 36.9 kB
Tags Source
SHA-256 checksum
How to use checksums
65729ebd5a271d8fef58a7d856bf124cf61189a57528d0f03f17fc6a86c61d09
BLAKE2b-256 checksum
How to use checksums
4dfbb3f7987767b3caa0c4cfbe395617cfdb9982918152c847ee61cca6b52a92
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.12

Release files / agent_second_fuse-0.2.1-py3-none-any.whl

Download URL agent_second_fuse-0.2.1-py3-none-any.whl
Size 42.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
4af47cc3c316d72f5614a2452a4d9d4c900e54cd447d8f4ddc446249db6fa168
BLAKE2b-256 checksum
How to use checksums
8a55391089e85325fa5fa1101b3e94d0aa9c70b3ae263b6c955160ddaf5a671f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.12

Release history Release notifications | RSS feed

0.3.0

2 release files

This release

0.2.1 This release

2 release files

0.2.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page