Skip to main content

conduct-agent-guard

Conduct Guard on every tool call, in the agent framework you already use. One line per framework; the same Conduct policy decides for all of them.

Framework One line
Claude Agent SDK ClaudeAgentOptions(hooks=conduct_hooks())
OpenAI Agents SDK Agent(tools=guard_tools([...]))
LangChain / LangGraph create_agent(..., middleware=[ConductMiddleware()])
Google ADK LlmAgent(before_tool_callback=conduct_before_tool_callback())
CrewAI register_conduct_hook() before crew.kickoff()

Each adapter sends the tool name + arguments to Conduct's guard_check action gate before the tool runs. Adapters translate; Conduct decides.

  • block / approval: the tool does not run, and the model gets the reason (so it can explain or adapt).
  • warning / advisory: the tool runs.

The audit row records which framework made the call.

pip install "conduct-agent-guard[claude]"     # or [openai] [langchain] [adk] [crewai]
export CONDUCT_AGENT_TOKEN=cond_agt_...       # from the Conduct console or `conduct login`
Env var Default
CONDUCT_AGENT_TOKEN required
CONDUCT_API_URL https://gateway.conductai.ai
CONDUCT_WORKSPACE_ID from the token

Unreachable Conduct fails closed (the tool is blocked); pass ToolGuard(..., unreachable_fallback="fail_open") to change that.

Run the examples

Every example runs the same scenario. The agent searches the web (allowed), then tries to save the untrusted result to long-term memory. That save is blocked by the memory-poisoning rule (asi06_untrusted_promotion_to_durable) in a default Conduct workspace.

cd packages/conduct-agent-guard/examples
./run_all.sh            # live_smoke + all five agents
./run_all.sh smoke      # no LLM needed: every adapter against your live policy
./run_all.sh claude crewai

run_all.sh needs uv and gives each framework its own environment. Current CrewAI and OpenAI Agents can't share one: they pin different openai majors.

LLM access

The agent examples default to Anthropic (claude-haiku-4-5).

  • Direct: export ANTHROPIC_API_KEY=.... The Claude Agent SDK example can also use your Claude Code login.

  • Through the Conduct Gateway (model traffic governed too):

    # Anthropic profile
    export ANTHROPIC_BASE_URL=https://gateway.conductai.ai/gateway/v1/anthropic
    export ANTHROPIC_API_KEY=<conduct token>
    export DEMO_PROVIDER=anthropic DEMO_MODEL=cond-<code>-<alias>
    
    # or an OpenAI profile
    export OPENAI_BASE_URL=https://gateway.conductai.ai/gateway/v1/openai/v1
    export OPENAI_API_KEY=<conduct token>
    export DEMO_PROVIDER=openai DEMO_MODEL=cond-<code>-<alias>
    

    The profile identifier is on the Gateway profile page. source ~/.conduct/env sets the base URLs and keys if you used conduct login.

Tests

uv run --no-project --with-editable '.[claude,openai,langchain,adk,dev]' pytest
uv run --no-project --with-editable '.[crewai,dev]' pytest     # CrewAI needs its own env

The core tests run without any framework installed; adapter tests skip when their SDK is missing.

Metadata

Release files for conduct-agent-guard 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for conduct-agent-guard 0.1.0
File Size Uploaded
conduct_agent_guard-0.1.0.tar.gz 10.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for conduct-agent-guard 0.1.0
File Interpreter ABI Platform
conduct_agent_guard-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 19.8 kB

Release files / conduct_agent_guard-0.1.0.tar.gz

Download URL conduct_agent_guard-0.1.0.tar.gz
Size 10.7 kB
Tags Source
SHA-256 checksum
How to use checksums
f3061381d80102dba7eb971be7ffcd3e81563e3d98882a799324efc779abcda2
BLAKE2b-256 checksum
How to use checksums
28525118fe5b4ccb009e4c0f977cda5b04c42b9cd558e018d934bd3e21a57a15
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release files / conduct_agent_guard-0.1.0-py3-none-any.whl

Download URL conduct_agent_guard-0.1.0-py3-none-any.whl
Size 9.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
e017bc23cac006c08ffc74042d0714a6137f7f80240c7ac27ade469d191eda05
BLAKE2b-256 checksum
How to use checksums
46bc9d81f1be2d239d6507c3aa623871a2da18be73bf1f94b76a7f9704f04977
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page