Skip to main content

axio-tui-guards

PyPI Python License: MIT

Permission guard plugins for axio-tui.

Guards intercept tool calls before execution and can allow, modify, or deny them. Ships two guards: a path-access guard that asks the user before touching filesystem locations, and an LLM-based guard that reviews tool calls for safety.

Features

  • PathGuard - intercepts tools that touch the filesystem; prompts the user once per directory and remembers the decision for the session
  • LLMGuard - runs a secondary LLM call to review each tool invocation before allowing it
  • PermissionGuard protocol - both guards implement axio.PermissionGuard and compose cleanly
  • TUI-aware - prompts appear as native axio-tui dialogs, not blocking stdin reads

Installation

pip install axio-tui-guards

Or install as part of the TUI bundle:

pip install "axio-tui[guards]"

Guards

PathGuard

Intercepts tool calls that contain filesystem paths (file_path, filename, directory, path, cwd). On the first access to a new directory it asks the user to allow, allow all (subtree), or deny.

from axio_tui_guards.guards import PathGuard
from axio.tool import Tool

guard = PathGuard()   # uses TUI prompt_fn by default

tool = Tool(
    name="write_file",
    description="Write a file",
    handler=write_file,
    guards=(guard,),
)

Decision caching:

  • Allow - grants access to the parent directory for the current session
  • Allow all - grants access to the directory and all subdirectories
  • Deny - blocks this path; raises GuardError immediately on retry

LLMGuard

Uses a secondary LLM call to review the tool handler arguments before execution. If the reviewer deems the call unsafe it raises GuardError with the reason.

from axio_tui_guards.guards import LLMGuard
from axio.agent import Agent
from axio.context import MemoryContextStore
from axio.testing import StubTransport, make_text_response

reviewer = Agent(system="", tools=[], transport=StubTransport([make_text_response("allow")]))
guard = LLMGuard(agent=reviewer, context=MemoryContextStore())

Composing guards

Guards are applied in order - attach both for layered protection:

from axio_tui_guards.guards import PathGuard, LLMGuard
from axio.agent import Agent
from axio.context import MemoryContextStore
from axio.testing import StubTransport, make_text_response
from axio.tool import Tool

reviewer = Agent(system="", tools=[], transport=StubTransport([make_text_response("allow")]))
tool = Tool(
    name="shell",
    description="Run shell commands",
    handler=shell,
    guards=(PathGuard(), LLMGuard(agent=reviewer, context=MemoryContextStore())),
)

Custom guards

Implement the PermissionGuard protocol to write your own:

from typing import Any
from axio.permission import PermissionGuard
from axio.exceptions import GuardError

class MyGuard(PermissionGuard):
    async def check(self, tool: Any, **kwargs: Any) -> dict[str, Any]:
        if "rm -rf" in str(kwargs.get("command", "")):
            raise GuardError("Refusing to run rm -rf")
        return kwargs

Plugin registration

[project.entry-points."axio.guards"]
path = "axio_tui_guards.guards:PathGuard"
llm  = "axio_tui_guards.guards:LLMGuard"

Part of the axio ecosystem

axio · axio-tui

License

MIT

Metadata

Release files for axio-tui-guards 0.11.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for axio-tui-guards 0.11.2
File Size Uploaded
axio_tui_guards-0.11.2.tar.gz 86.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for axio-tui-guards 0.11.2
File Interpreter ABI Platform
axio_tui_guards-0.11.2-py3-none-any.whl Python 3 none any Details

Total release size: 93.8 kB

Release files / axio_tui_guards-0.11.2.tar.gz

Download URL axio_tui_guards-0.11.2.tar.gz
Size 86.4 kB
Tags Source
SHA-256 checksum
How to use checksums
610634e7e60b4bcfe8c40ec966c5ab911b0746d9f66bcb0cd7f714d2730f586e
BLAKE2b-256 checksum
How to use checksums
5f4ca7348b98368f97f79636c0ed8e671a8d45168e1f47e2b455c1d53dfb9685
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 11, 2026.

Transparency log

Release files / axio_tui_guards-0.11.2-py3-none-any.whl

Download URL axio_tui_guards-0.11.2-py3-none-any.whl
Size 7.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b996357786ac1610e87c15cd5bcd0ecccd888824fcd1131191b80bb941cf84b8
BLAKE2b-256 checksum
How to use checksums
b8c4b55bbb04b6139bf0b97a46d510dca39f775a7f00a89f72807dd5579d83a5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 11, 2026.

Transparency log

Release history Release notifications | RSS feed

0.11.3

2 release files

This release

0.11.2 This release

2 release files

0.11.1

2 release files

0.11.0

2 release files

0.10.1

2 release files

0.10.0

2 release files

0.9.9

2 release files

0.9.8

2 release files

0.9.7

2 release files

0.9.6

2 release files

0.9.5

2 release files

0.9.4

2 release files

0.9.2

2 release files

0.9.1

2 release files

0.9.0

2 release files

0.8.0

2 release files

0.7.0

2 release files

0.6.2

2 release files

0.6.1

2 release files

0.6.0

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.5

2 release files

0.3.4

2 release files

0.3.3

2 release files

0.3.2

2 release files

0.2.3

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page