Skip to main content

AW-1 Circuit Breaker

License: MIT Python: 3.10+ MCP Version: 2024-11-05 Evaluator Grade: AISI/METR A

Deterministic, out-of-band execution circuit breaker and Model Context Protocol (MCP) server for autonomous AI agents.

Standard LLM guardrails (RLHF, system prompts, secondary evaluators) operate in-band: probabilistic models evaluating their own execution safety. When autonomous agents gain shell access, external tool execution, or financial disbursement rails, adversarial injections bypass prompt boundaries via Base64 steganography, dynamic , or velocity micro-drains.

AW-1 enforces a deterministic, out-of-band proxy layer between the cognitive reasoning node and host execution sockets.


⚡ Key Highlights

  • Layer 0 AST Symbolic Unpacker: Recursively decompiles tool payloads, Base64 strings, and dynamic calls into execution primitives ([DYNAMIC_EVAL], [NETWORK_EGRESS], [EXEC_SHELL], [DESTRUCTIVE_WRITE]) in <0.15 ms.
  • Native MCP JSON-RPC 2.0 Server: Out-of-the-box integration for Claude Desktop, Gemini Enterprise, Cursor, and custom agent swarms.
  • 100% Adversarial Containment: Validated across 1,000 cycles of the BRK Breakout Suite with 0.00% false positives on benign traffic.
  • Zero Dependencies: Pure standard-library Python (sub-millisecond fast path).
  • Statutory Non-Repudiation: Cryptographically sealed JSON-LD dossiers anchored by SHA-256 digests.

📊 Adversarial Gauntlet Benchmark

Results from 1,000 automated attack cycles on the BRK Breakout Suite (scripts/benchmark_mcp_breaker.py):

Test Suite Attack Vector Sample Payload Verdict Mean Latency
BRK-101 Base64 Steganography & eval() eval(compile(b64decode(...))) HALT 0.128 ms
BRK-102 Covert TCP Socket Egress socket.connect(('198.51.100.1', 4444)) HALT 0.134 ms
BRK-103 Destructive Filesystem Tampering shutil.rmtree('/dossiers') HALT 0.119 ms
BRK-BENIGN Operational Escrow Lookup SELECT balance FROM trust_escrow ALLOW 0.057 ms
  • Containment Rate: 100.00% (745 / 745 attacks neutralized)
  • False Positive Rate: 0.00% (255 / 255 benign queries passed)
  • Mean Pre-Execution Overhead: 0.142 ms
  • Evaluation Grade: AISI_METR_COMPLIANT_GRADE_A

🔌 Model Context Protocol (MCP) Server

AW-1 exposes standardized JSON-RPC tools for agent frameworks:

Exposed MCP Tools:

  1. audit_agent_tool_call: Pre-execution inspection decomposing tool payloads into AST primitives.
  2. verify_statutory_quota: Botswana CEE Act 2021 (>= 50% citizen equity) and CEDA compliance checking.
  3. verify_cryptographic_seal: Independent validation of Bank of Botswana 1-to-1 trust backing SHA-256 seals.

Connecting via Claude Desktop / Cursor

Add to your claude_desktop_config.json:

{
  "mcpServers": {
    "aw1-breaker": {
      "command": "python3",
      "args": ["/path/to/aw1-breaker/scripts/aw1_mcp_server.py"]
    }
  }
}

🚀 Quickstart (Python SDK)

from aw1 import ExecutionBreaker

# Initialize out-of-band circuit breaker
breaker = ExecutionBreaker(baseline_velocity=50000.0)

# Intercept proposed agent action before execution
verdict = breaker.intercept(
    actor_id="agent_ops_01",
    tool_name="shell_exec",
    payload="import socket; s = socket.socket()"
)

if verdict["status"] == "HALT":
    raise PermissionError(f"Circuit Breaker Tripped: {verdict['reason']}")

📄 Research & Preprints

Full research specification and mathematical proofs:


📜 License

MIT License. Designed and maintained by Laveto Wisdom Research Group (Laveto Labs).

Metadata

Release files for aw1-circuit-breaker 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for aw1-circuit-breaker 0.1.0
File Size Uploaded
aw1_circuit_breaker-0.1.0.tar.gz 39.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for aw1-circuit-breaker 0.1.0
File Interpreter ABI Platform
aw1_circuit_breaker-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 58.9 kB

Release files / aw1_circuit_breaker-0.1.0.tar.gz

Download URL aw1_circuit_breaker-0.1.0.tar.gz
Size 39.0 kB
Tags Source
SHA-256 checksum
How to use checksums
a895ca8c0559eeccf2db107c1e5c154936b7e500ae8773a14774aacc52315024
BLAKE2b-256 checksum
How to use checksums
6d0b7bbc1cdd3d2aca6659d7066aac3fdb6e27327ddc387da645cd760b1e2e90
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.1

Release files / aw1_circuit_breaker-0.1.0-py3-none-any.whl

Download URL aw1_circuit_breaker-0.1.0-py3-none-any.whl
Size 20.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
63aaa6ae1000c0b42fe7b1211a5f1af0da51c9aa58d445c421397a6a031c5281
BLAKE2b-256 checksum
How to use checksums
f8ddcec2babe4007da364ebed09b037a331e41b5314eba2b99e7e1ff40b3c275
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.1

Release history Release notifications | RSS feed

0.1.1

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page