AgentShield — Firewall for AI Agent Spending
Stop runaway AI agents before they burn your budget. 9 composable rules evaluated per-transaction in <1ms. Pure Python stdlib — zero dependencies.
Install
pip install agentshield-spend
(The import name is agentshield — the PyPI name agentshield belongs to an unrelated project.)
Quick Start
from agentshield import SpendControlEngine
engine = SpendControlEngine()
# A transaction your agent wants to make
transaction = {
"amount": 500.00,
"merchant": "openai-api",
"category": "llm_inference",
"agent_id": "my-agent",
"timestamp": "2026-08-10T10:00:00Z",
}
# Your spend-control rules
rules = [
{"id": "r1", "type": "transaction_limit", "priority": 1,
"params": {"max_amount": 250}, "action": "BLOCK"},
{"id": "r2", "type": "daily_total", "priority": 2,
"params": {"max_daily": 2000}, "action": "BLOCK"},
{"id": "r3", "type": "velocity", "priority": 3,
"params": {"window_minutes": 60, "max_count": 10}, "action": "FLAGGED"},
]
# Prior transactions today (for daily_total and velocity checks)
prior_transactions = []
# Evaluate — returns in <1ms
result = engine.evaluate(transaction, rules, prior_transactions)
print(result["decision"]) # BLOCKED
print(result["reason"]) # Transaction amount $500.00 exceeds limit of $250.00
Rule Types (9)
| Rule | Description | Example Params |
|---|---|---|
transaction_limit |
Block single calls over $X | {"max_amount": 500} |
daily_total |
Cap cumulative daily spend | {"max_daily": 2000} |
velocity |
Detect burst patterns | {"window_minutes": 60, "max_count": 10} |
merchant_allowlist |
Only approved API providers | {"allowed": ["openai-api", "anthropic-api"]} |
category_block |
Block spend categories | {"blocked": ["crypto_exchange"]} |
session_budget |
Per-session spend cap with decay | {"max_session": 100, "decay_factor": 0.3} |
cascade_cost |
Expected value with retry cost | {"max_cascade_cost": 100, "fail_probability": 0.3, "reversal_cost": 200} |
Eval Gym (56 scenarios)
from agentshield import run_eval
results = run_eval()
print(f"{results['passed']}/{results['total']} passed") # 56/56
All 56 test scenarios are MIT licensed. Use them as test fixtures for your own spend-control implementation.
Key Design Decisions
- Pure Python 3.11 stdlib — no pip install required (except for the package wrapper itself)
- Decimal for money — never float, always
decimal.Decimal - Stateless — no file I/O, no network, no global state
- Deterministic — same inputs always produce the same output
- <1ms per evaluation
Links
License
MIT
Release files for agentshield-spend 1.0.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| agentshield_spend-1.0.1.tar.gz | 13.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| agentshield_spend-1.0.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 25.9 kB
Release files / agentshield_spend-1.0.1.tar.gz
| Download URL | agentshield_spend-1.0.1.tar.gz |
|---|---|
| Size | 13.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
8406c86d132ce9ac689822312b6132f3736c27b668491fd40e0ef01e86b63f3a
|
|
BLAKE2b-256 checksum How to use checksums |
6277e8edf7da58fcc688a02c798af61d780f6e6ede6fb87a8bfe050d2f6d32d6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.11.15
|
Release files / agentshield_spend-1.0.1-py3-none-any.whl
| Download URL | agentshield_spend-1.0.1-py3-none-any.whl |
|---|---|
| Size | 12.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
832157a7064e00b1625442d05e17bef897fcb66802b52f6ab590e24a190e1240
|
|
BLAKE2b-256 checksum How to use checksums |
83aa7ec464cfaf78e67fc22be8746721224ae72acd9d9910fd902dfa07efdbd5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.11.15
|