Skip to main content

AgentShield — Firewall for AI Agent Spending

Stop runaway AI agents before they burn your budget. 9 composable rules evaluated per-transaction in <1ms. Pure Python stdlib — zero dependencies.

Install

pip install agentshield-spend

(The import name is agentshield — the PyPI name agentshield belongs to an unrelated project.)

Quick Start

from agentshield import SpendControlEngine

engine = SpendControlEngine()

# A transaction your agent wants to make
transaction = {
    "amount": 500.00,
    "merchant": "openai-api",
    "category": "llm_inference",
    "agent_id": "my-agent",
    "timestamp": "2026-08-10T10:00:00Z",
}

# Your spend-control rules
rules = [
    {"id": "r1", "type": "transaction_limit", "priority": 1,
     "params": {"max_amount": 250}, "action": "BLOCK"},
    {"id": "r2", "type": "daily_total", "priority": 2,
     "params": {"max_daily": 2000}, "action": "BLOCK"},
    {"id": "r3", "type": "velocity", "priority": 3,
     "params": {"window_minutes": 60, "max_count": 10}, "action": "FLAGGED"},
]

# Prior transactions today (for daily_total and velocity checks)
prior_transactions = []

# Evaluate — returns in <1ms
result = engine.evaluate(transaction, rules, prior_transactions)
print(result["decision"])  # BLOCKED
print(result["reason"])    # Transaction amount $500.00 exceeds limit of $250.00

Rule Types (9)

Rule Description Example Params
transaction_limit Block single calls over $X {"max_amount": 500}
daily_total Cap cumulative daily spend {"max_daily": 2000}
velocity Detect burst patterns {"window_minutes": 60, "max_count": 10}
merchant_allowlist Only approved API providers {"allowed": ["openai-api", "anthropic-api"]}
category_block Block spend categories {"blocked": ["crypto_exchange"]}
session_budget Per-session spend cap with decay {"max_session": 100, "decay_factor": 0.3}
cascade_cost Expected value with retry cost {"max_cascade_cost": 100, "fail_probability": 0.3, "reversal_cost": 200}

Eval Gym (56 scenarios)

from agentshield import run_eval

results = run_eval()
print(f"{results['passed']}/{results['total']} passed")  # 56/56

All 56 test scenarios are MIT licensed. Use them as test fixtures for your own spend-control implementation.

Key Design Decisions

  • Pure Python 3.11 stdlib — no pip install required (except for the package wrapper itself)
  • Decimal for money — never float, always decimal.Decimal
  • Stateless — no file I/O, no network, no global state
  • Deterministic — same inputs always produce the same output
  • <1ms per evaluation

Links

License

MIT

Release files for agentshield-spend 1.0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for agentshield-spend 1.0.1
File Size Uploaded
agentshield_spend-1.0.1.tar.gz 13.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for agentshield-spend 1.0.1
File Interpreter ABI Platform
agentshield_spend-1.0.1-py3-none-any.whl Python 3 none any Details

Total release size: 25.9 kB

Release files / agentshield_spend-1.0.1.tar.gz

Download URL agentshield_spend-1.0.1.tar.gz
Size 13.0 kB
Tags Source
SHA-256 checksum
How to use checksums
8406c86d132ce9ac689822312b6132f3736c27b668491fd40e0ef01e86b63f3a
BLAKE2b-256 checksum
How to use checksums
6277e8edf7da58fcc688a02c798af61d780f6e6ede6fb87a8bfe050d2f6d32d6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.15

Release files / agentshield_spend-1.0.1-py3-none-any.whl

Download URL agentshield_spend-1.0.1-py3-none-any.whl
Size 12.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
832157a7064e00b1625442d05e17bef897fcb66802b52f6ab590e24a190e1240
BLAKE2b-256 checksum
How to use checksums
83aa7ec464cfaf78e67fc22be8746721224ae72acd9d9910fd902dfa07efdbd5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.15

Release history Release notifications | RSS feed

This release

1.0.1 This release

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page