Skip to main content

Grimdall for Python

One decorator. Any framework. Zero infra.

Grimdall is a local-only runtime security layer for AI agents. One import guards tool calls in any agent framework, with no proxy, no Docker, no signup, and no network calls. Policies, rate limits, budgets, approvals, and a tamper-evident audit trail live in your project's .grimdall/ directory and interoperate with the Grimdall CLI hooks and Node SDK on the same hash-chained audit.json.

Install

pip install grimdall

No dependencies beyond the Python standard library. Works offline, forever, for $0/month.

One decorator

from grimdall import Guard

guard = Guard()  # zero-config: reads .grimdall/ policies, appends the local audit chain

@guard.wrap
def run_shell(command: str) -> str:
    return f"[mock] executed: {command}"

run_shell("ls -la")   # allowed, logged as "allowed"
run_shell("rm -rf /") # raises GrimdallBlockedError, logged as "blocked"

Every decision is appended to the same SHA-256 hash-chained audit file as CLI-hook events, so a single audit.json can be verified end to end:

from grimdall import AuditTrail

AuditTrail(".grimdall").verify()  # raises AuditError on any tampering

Inline guardrails

from grimdall import Guard, Policy

guard = Guard()
guard.add_policy(
    Policy(
        deny=["github_delete_repo"],
        rate_limit={"max": 10, "per": "minute"},
        budget={"max_spend": 50.0, "period": "day"},
        require_approval=["deploy_production"],
    )
)

Evaluation order: identity/credential -> policy rules -> rate limits -> budget -> approval -> execute. Approval tools prompt in your terminal ([Allow/Deny/Allow 1h]) and a timeout or a missing TTY denies the call: approvals never fail open.

Any framework

from grimdall import Guard
from grimdall.integrations.langchain import GrimdallCallbackHandler

handler = GrimdallCallbackHandler(Guard())

Adapters ship for LangChain, openai-agents, CrewAI, and AutoGen under grimdall.integrations.*. Each is a thin shim over the same core Guard and never forces the framework to be installed.

Audit mode

When .grimdall/config.json sets "mode": "audit" (the CLI default), blocked decisions are recorded as would_block and the call proceeds. Run npx grimdall mode enforce to switch to hard enforcement.

Project layout

.grimdall/  (created for you)
├── policies.json   # default policies (CLI-compatible)
├── config.json     # mode + optional Slack webhook
├── audit.json      # tamper-evident hash chain
└── spend.json      # budget ledger

Metadata

Release files for grimdall 0.4.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for grimdall 0.4.0
File Size Uploaded
grimdall-0.4.0.tar.gz 29.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for grimdall 0.4.0
File Interpreter ABI Platform
grimdall-0.4.0-py3-none-any.whl Python 3 none any Details

Total release size: 57.5 kB

Release files / grimdall-0.4.0.tar.gz

Download URL grimdall-0.4.0.tar.gz
Size 29.1 kB
Tags Source
SHA-256 checksum
How to use checksums
5be33c8d0ea51268ff667c4ee54251b24dcfdc919597248904683d9fa36650e7
BLAKE2b-256 checksum
How to use checksums
df98a22a91ca0eb97b38efd8deb2d8db8e974b60b56fadea6fe8b5d03869535c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 26, 2026.

Transparency log

Release files / grimdall-0.4.0-py3-none-any.whl

Download URL grimdall-0.4.0-py3-none-any.whl
Size 28.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
7b63f41b3f2b61dd8a31c20c94507b0596320e91f90b38c4c149d60b89eea3e4
BLAKE2b-256 checksum
How to use checksums
db2ca01fd5e49822424b54179ff1aa27872f9f351b81f0456273696f5952eb58
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 26, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.4.0 This release

2 release files

0.3.3

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page