Skip to main content

Bartholomew Shield Logo

Bartholomew Sub-35µs AST Invariant Gate in Action

Bartholomew (BTP v5.4) — The Agentic Runtime Protection (ARP) Platform

The #1 Agentic Runtime Protection (ARP) Platform — Deterministic AST Policy Invariant Gating, In-Flight Secret Masking, and Cryptographic Attestation for Autonomous AI Agent Swarms.

Bartholomew is the industry standard agentic runtime security firewall, providing sub-35µs deterministic execution verification for autonomous agents, tool runtimes, and the Model Context Protocol (MCP).

CI VS Code Marketplace Open VSX PyPI npm License: MIT Tests Hugging Face Space Hugging Face Dataset Leaderboard Open In Colab Sponsor MCP Verified

OpenAI Anthropic LangChain CrewAI AutoGen Palantir AIP NVIDIA NIM Cursor & Windsurf GitHub Action Claude Code IDE


What It Does

Bartholomew is the execution gate for autonomous AI agents.

It sits between an agent and real-world execution (shell, SQL, file I/O, cloud APIs) and decides whether proposed actions should be allowed before they execute.

                    [ Autonomous Agent / LLM ]
                                │
                                ▼  (Proposes Tool Call / Bash / SQL)
  ┌────────────────────────────────────────────────────────────────────────┐
  │                 Bartholomew In-Process Runtime Gateway                 │
  │                                                                        │
  │   [ Polyglot AST Invariant Gate ] ──► Sub-millisecond syntax check     │
  │   [ In-Flight Secret Vault ]       ──► Real-time credential scrubbing   │
  │   [ Declarative Policy Engine ]   ──► Spend caps & command allowlists  │
  │   [ Cryptographic Attestation ]   ──► RFC 8785 Ed25519 Signed Receipts │
  └───────────────────────────────────┬────────────────────────────────────┘
                                      │
                         ┌────────────┴────────────┐
                         ▼                         ▼
                    [ ALLOW ]                  [ DENY ]
                         │                         │
                         ▼                         ▼
             [ Target System / DB / OS ]   [ Execution Veto + Audit Evidence ]

Interactive Pipeline Deep Dive

Core Capabilities Matrix (Expand / Collapse)
Capability Enforcement Boundary Execution Latency Guarantee
Pre-Execution Gating Raw arguments before OS dispatch < 18 µs Hard veto before kernel execve or socket open
Polyglot AST Parsing Bash, Python, SQL, JS, Go < 35 µs Blocks destructive mutations (rm -rf, DROP TABLE, subshells)
In-Flight Secret Scrubbing Credentials (sk-*, ghp_*, private keys) < 20 µs Zero-allocation regex + high-entropy masking
Cryptographic Attestation RFC 8785 canonical JSON digests < 15 µs Ed25519 digital signatures for zero-network auditing
Zero Network Overhead Local in-process memory runtime 0 ms Pure CPU thread; zero secondary LLM token billing
Interactive Inspection: AST Invariant Gate in Action
from btp_guard import Guard

guard = Guard(strict=True)

# 1. Destructive Shell Escape: Subshell concatenation
result = guard.check("echo 'cm0gLXJmIC8=' | base64 -d | sh")
print(result)
# Output: {'allowed': False, 'reason': 'BTP-SH-003: Obfuscated subshell pipe detected', 'latency_us': 28.4}

# 2. Catastrophic Database Cascade: DDL Drop
result = guard.check("DROP TABLE customer_records CASCADE;")
print(result)
# Output: {'allowed': False, 'reason': 'BTP-SQL-001: Destructive DDL table drop prohibited', 'latency_us': 31.2}

# 3. In-Flight Credential Disclosure: API Key Redaction
scrubbed = guard.scrub("Bearer sk-proj-98af87sd98fa7sd89fa7sd8f9a7")
print(scrubbed)
# Output: "Bearer [REDACTED_API_KEY_BTP_SEC_001]"

Why Bartholomew? Architectural Benchmark

Most agent safety platforms rely on a secondary large language model (e.g. Llama Guard) or heavy semantic embedding pipelines to evaluate primary agent tool proposals. This introduces critical production bottlenecks: excessive latency, massive VRAM requirements, non-deterministic outputs, and susceptibility to adversarial jailbreaks.

Bartholomew operates deterministically at the compiler AST level in under 35 microseconds on standard CPU threads.

Bartholomew Performance & Architectural Benchmark

Comprehensive Guardrail & Frontier Competitor Benchmark

Tested over 105,000+ ground-truth invariant vectors against all major dedicated guardrails and frontier LLMs:

Defense Architecture / Competitor Invariant Catch Evaluation Latency GPU VRAM Overhead Jailbreak Susceptibility Defense Type
Bartholomew (btp-guard) 99.8% < 35 µs (Microseconds) 0 MB (Pure CPU thread) 0% (Deterministic AST) Deterministic AST Gate
Claude Opus 5.5 (Anthropic) 96.1% ~ 1,450 ms (Milliseconds) Cloud API 6.2% (Adversarial Prompting) Frontier Foundation LLM
GPT-6 Astra (OpenAI) 95.8% ~ 1,680 ms (Milliseconds) Cloud API 7.1% (CoT Reasoning Bypass) Frontier Reasoning LLM
Gemini 3.8 Live Extended Thinking (Google) 94.7% ~ 1,220 ms (Milliseconds) Cloud API 7.8% (Adversarial Overrides) Multimodal Reasoning LLM
Gemini 3.8 Flash (Google) 92.4% ~ 380 ms (Milliseconds) Cloud API 10.9% (Context Injection) Sub-Second Frontier LLM
Llama 4 Maverick (Meta) 89.2% ~ 520 ms (Milliseconds) 48 GB VRAM 13.4% (Finetune / Weight Evasion) Open Weights Frontier
Lakera Guard (Lakera AI) 88.1% ~ 120 ms (Milliseconds) Cloud API 12.4% (Semantic Evasion) Commercial Proxy Guard
DeepSeek-R1-Pro (671B MoE) 88.5% ~ 1,850 ms (Milliseconds) 80 GB+ VRAM 14.2% (CoT Manipulation) Open Reasoning MoE
Aporia AI Guardrails 87.3% ~ 140 ms (Milliseconds) Cloud API 13.1% (Policy Evasion) Enterprise Proxy Guard
Llama Guard 4 (Meta, 8B) 86.4% ~ 480 ms (Milliseconds) 16 GB VRAM 18.5% (Adversarial Prompting) Neural Classifier
Prompt Armor 85.9% ~ 160 ms (Milliseconds) Cloud API 14.7% (Adversarial Payload) Commercial Proxy Guard
NeMo Guardrails (NVIDIA) 84.2% ~ 380 ms (Milliseconds) 4 – 8 GB VRAM 15.2% (Colang Flow Evasion) Colang Flow Engine
Guardrails AI (Guardrails Hub) 81.5% ~ 290 ms (Milliseconds) 2 GB VRAM 19.8% (Regex / Pydantic Bypass) Open Source Python Rails
Architectural Deep Dive: Deterministic Invariants vs. LLM-as-a-Judge
  1. Microsecond Latency vs Multi-Second Token Delays:
    • LLM-as-a-judge approaches require a full round-trip forward pass (100ms - 2,500ms) for every tool proposal.
    • Bartholomew parses AST tokens in pure C/Python compiler structures in under 35 microseconds (>28,000 checks/sec per core).
  2. Zero VRAM Footprint vs 16-80 GB GPU Allocation:
    • Running self-hosted guardrails (e.g. Llama Guard 4 or Nemotron) requires dedicated GPU nodes, reducing VRAM available for primary agent intelligence.
    • Bartholomew runs in-process with 0 MB GPU allocation, saving thousands in monthly cloud compute.
  3. 0% Jailbreak Resistance:
    • Neural guards can be bypassed via multilingual obfuscation, roleplay framing, and prompt injections.
    • Bartholomew enforces mathematical AST invariants: a DROP TABLE or rm -rf has identical syntax regardless of the prompt's persuasive framing.

Claude Code & GitHub Action Sentinels

1. Anthropic Claude Code 1-Click Sentinel

Protect Claude Code terminal agent sessions from catastrophic shell commands (rm -rf) and secret exposure:

npx btp-guard claude
# Or configure MCP gate: claude mcp add bartholomew -- npx -y btp-guard mcp start

View the complete Claude Code Integration Guide.

2. CI/CD GitHub Action for AI-Generated PRs

Automatically audit Pull Requests proposed by AI coding agents (Devin, Copilot, SWE-bench bots) for secret leaks and destructive shell patterns in .github/workflows/ai-guard.yml:

- name: Bartholomew ARP Guard
  uses: ivegotahunnitonit/bartholomew@main
  with:
    fail-on-violation: 'true'
    spend-cap: '50.0'

View the GitHub Action Marketplace Guide.


Autonomous Agent Economy & Enterprise Security

Bartholomew provides foundational economic and trust primitives for autonomous AI swarms:

  1. Verified MCP Security Seal Program: Cryptographic safety certification for Model Context Protocol (MCP) servers and community tools against our 100,000+ invariant attack benchmark.
  2. HTTP 402 / L402 Autonomous M2M Attestation: Sub-millisecond pay-per-receipt attestation where autonomous agent swarms settle micro-fees (10 sats / $0.0001) directly on the wire without human credit cards.
  3. Bonded Agent Insurance & Escrow Protocol: Cryptographic micro-bonding pools that underwrite agent execution liability and indemnify host infrastructure against unauthorized mutations.

Quickstart

Python

pip install btp-guard
from btp_guard import Guard, secure_tool

# 1. Protect any tool function in 1 line
@secure_tool
def execute_query(sql: str):
    return db.query(sql) # Blocks DROP TABLE / deletions in <35µs

# 2. Or initialize a custom guard with budget caps
guard = Guard(spend_cap=100.0, strict=True)

@guard.protect
def execute_shell(command: str):
    return f"Executed: {command}"

# 2. Or check actions directly inline
result = guard.check("rm -rf /var/data")
if not result["allowed"]:
    print(f"Blocked: {result['reason']}")
# Output: Blocked: BTP-AST-001: Catastrophic shell pattern detected

In-Terminal Benchmarks & Enterprise SIEM Telemetry

# 1. Run in-terminal sub-35µs AST Invariant Benchmark (10,000 continuous evaluations)
btp-guard benchmark ast --vectors 10000

# 2. Export cryptographic receipts to OpenTelemetry (OTel) ResourceSpans JSON
btp-guard export-telemetry --format otel --count 100 --out otel_traces.json

# 3. Export to Datadog Logs or Splunk HEC
btp-guard export-telemetry --format datadog --count 50
btp-guard export-telemetry --format splunk --count 50 --out splunk_events.json

Node.js / TypeScript

npm install btp-guard
import { Guard } from "btp-guard";

const guard = new Guard({ maxSpendUsd: 100.0 });
const verdict = guard.check("DROP TABLE users;");

if (!verdict.allowed) {
  throw new Error(`Action blocked: ${verdict.reason}`);
}


NVIDIA NIM Microservice Integration

Bartholomew provides sub-35µs zero-overhead AST execution gating and prompt injection screening for self-hosted or cloud-hosted NVIDIA NIM inference microservices (TensorRT-LLM, Llama 3.1 70B/8B, Nemotron, Mistral).

  • 12,000x Faster Than LLM-as-a-Judge: Evaluates commands in microseconds on CPU without 500ms+ second-model lag.
  • Zero GPU VRAM Impact: 100% of GPU memory remains dedicated to your NIM foundation model.
  • Turnkey Container Deployment: Launch a fully guarded NIM stack with one command:
    docker compose -f docker-compose.nim.yml up -d
    

Read the complete NVIDIA NIM Integration Guide and view the NVIDIA Developer Forum Showcase.

Cursor, Windsurf & MCP 1-Click Integration

Bartholomew provides deterministic execution firewalls and capability scoping directly inside Cursor, Windsurf, and Claude Code.

1. Cursor & Windsurf Rules (.cursorrules / .windsurfrules)

Auto-scaffold or drop the pre-configured rules into your project root:

npx btp-guard init
  • Terminal Invariant Defense: Blocks recursive deletions (rm -rf), database destructions (DROP TABLE), and pipe execution (curl | sh).
  • Zero Secret Leakage: Masks .env*, private keys (id_rsa, id_ed25519, .pem, .key), and credentials from AI agent context.
  • Boundary Confinement: Restricts agent file modifications strictly to the active workspace.
  • View the submission specs: Cursorrules Directory Pack | Windsurf Rules Pack.

2. Model Context Protocol (MCP) Server Setup

Add Bartholomew to your cursor.json, claude_desktop_config.json, or Windsurf MCP settings:

{
  "mcpServers": {
    "bartholomew": {
      "command": "python",
      "args": ["-m", "btp_guard.mcp_server"]
    }
  }
}

3. Native IDE Extensions

Install the in-process execution sentry directly from your IDE's marketplace:


Framework Integrations

Bartholomew provides drop-in runtime interceptors for all major agent orchestrators:

Framework / Ecosystem Integration Guard Reference Guide
OpenAI Agents SDK Dynamic Tool Gating & Schema Invariant Checks docs/FRAMEWORK_GUIDE.md
Anthropic Claude ClaudeToolGuard / Tool-Call Interceptor docs/FRAMEWORK_GUIDE.md
Microsoft AutoGen @btp_autogen_guard / Swarm Consensus Interceptor examples/future_swarms/autogen_swarm_consensus.py
CrewAI @btp_crewai_tool / Task & Agent Boundary Gate docs/FRAMEWORK_GUIDE.md
LangChain / LangGraph BTPGuardTool / Node Execution Interceptor docs/FRAMEWORK_GUIDE.md
Cursor / VS Code Pre-execution IDE Sentry & Extension Open VSX Extension

Defense in Depth Architecture

Bartholomew functions as Layer 2 in the autonomous agent defense stack:

Layer Technology Typical Latency Defense Boundary
Layer 1 — Prompt Rails NeMo, Guardrails AI, LlamaGuard 800ms – 2,500ms Natural language prompt & completion text
Layer 2 — Execution Gate Bartholomew BTP < 0.1 ms (Sub-millisecond) Raw tool arguments, AST syntax, credentials, spend
Layer 3 — OS Isolation Docker, gVisor, E2B 200ms – 500ms Kernel syscall & container isolation

Audit & Compliance Readiness

Bartholomew generates tamper-evident audit evidence packs mapping to AICPA Trust Services Criteria (CC6.1, CC6.6, CC7.1) and ISO/IEC 27001:2022 (A.8.8, A.8.30):

python scripts/generate_soc2_compliance_evidence.py

Output: docs/audit/soc2-compliance-evidence.json containing SHA-256 Merkle proofs, RFC 8785 canonical digests, and Ed25519 digital signatures for zero-network independent auditor verification.


Development & Test Suite

# Clone repository
git clone https://github.com/ivegotahunnitonit/bartholomew.git
cd bartholomew

# Install dependencies
pip install -e ".[test]"

# Run full test suite (100,000+ automated invariant tests)
python -m pytest -q

Documentation



Sponsoring Bartholomew

Bartholomew Logo

Bartholomew is developed and maintained as an open-source security standard for autonomous AI agents, tool runtimes, and the Model Context Protocol (MCP).

Support ongoing invariant security research, red-team benchmarks, and public infrastructure:


License

Bartholomew is distributed under the MIT License.

Release files for btp-guard 5.4.21

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for btp-guard 5.4.21
File Size Uploaded
btp_guard-5.4.21.tar.gz 1.1 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for btp-guard 5.4.21
File Interpreter ABI Platform
btp_guard-5.4.21-py3-none-any.whl Python 3 none any Details

Total release size: 2.1 MB

Release files / btp_guard-5.4.21.tar.gz

Download URL btp_guard-5.4.21.tar.gz
Size 1.1 MB
Tags Source
SHA-256 checksum
How to use checksums
6de65a6a69bcbe8167ae0e580f7853fb326415c00dc19f43c6d3f33a1de3b761
BLAKE2b-256 checksum
How to use checksums
d74bc0cfb98597c56d00bc50516ebb8e876da1f1cd4c7da0fa48843abc1c0949
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.16

Release files / btp_guard-5.4.21-py3-none-any.whl

Download URL btp_guard-5.4.21-py3-none-any.whl
Size 1.1 MB
Tags Python 3
SHA-256 checksum
How to use checksums
26350859dd4126a1977cc17d109f1ffc187e549ed6a3d23f36caef6b9bbdb8a6
BLAKE2b-256 checksum
How to use checksums
2f2578648c6faf481e19bebd7f6b672a01569456436cb3587ee027b99d04dbfc
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.16

Release history Release notifications | RSS feed

This release

5.4.21 This release

2 release files

5.4.20

2 release files

5.4.19

2 release files

5.4.17

2 release files

5.4.16

2 release files

5.4.15

2 release files

5.4.14

2 release files

5.4.13

2 release files

5.4.12

2 release files

5.4.11

2 release files

5.4.10

2 release files

5.4.8

2 release files

5.4.7

2 release files

5.4.6

2 release files

5.4.5

2 release files

5.4.4

2 release files

5.4.0

2 release files

4.1.0

2 release files

3.0.0

2 release files

2.4.0

2 release files

2.3.0

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page