Grimdall for Python
One decorator. Any framework. Zero infra.
Grimdall is a local-only runtime security layer for AI agents. One import
guards tool calls in any agent framework, with no proxy, no Docker, no
signup, and no network calls. Policies, rate limits, budgets, approvals,
and a tamper-evident audit trail live in your project's .grimdall/
directory and interoperate with the Grimdall CLI hooks and Node SDK on the
same hash-chained audit.json.
Install
pip install grimdall
No dependencies beyond the Python standard library. Works offline, forever, for $0/month.
One decorator
from grimdall import Guard
guard = Guard() # zero-config: reads .grimdall/ policies, appends the local audit chain
@guard.wrap
def run_shell(command: str) -> str:
return f"[mock] executed: {command}"
run_shell("ls -la") # allowed, logged as "allowed"
run_shell("rm -rf /") # raises GrimdallBlockedError, logged as "blocked"
Every decision is appended to the same SHA-256 hash-chained audit file as
CLI-hook events, so a single audit.json can be verified end to end:
from grimdall import AuditTrail
AuditTrail(".grimdall").verify() # raises AuditError on any tampering
Inline guardrails
from grimdall import Guard, Policy
guard = Guard()
guard.add_policy(
Policy(
deny=["github_delete_repo"],
rate_limit={"max": 10, "per": "minute"},
budget={"max_spend": 50.0, "period": "day"},
require_approval=["deploy_production"],
)
)
Evaluation order: identity/credential -> policy rules -> rate limits ->
budget -> approval -> execute. Approval tools prompt in your terminal
([Allow/Deny/Allow 1h]) and a timeout or a missing TTY denies the call:
approvals never fail open.
Any framework
from grimdall import Guard
from grimdall.integrations.langchain import GrimdallCallbackHandler
handler = GrimdallCallbackHandler(Guard())
Adapters ship for LangChain, openai-agents, CrewAI, and AutoGen under
grimdall.integrations.*. Each is a thin shim over the same core Guard and
never forces the framework to be installed.
Audit mode
When .grimdall/config.json sets "mode": "audit" (the CLI default),
blocked decisions are recorded as would_block and the call proceeds. Run
npx grimdall mode enforce to switch to hard enforcement.
Project layout
.grimdall/ (created for you)
├── policies.json # default policies (CLI-compatible)
├── config.json # mode + optional Slack webhook
├── audit.json # tamper-evident hash chain
└── spend.json # budget ledger
Metadata
Release files for grimdall 0.4.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| grimdall-0.4.0.tar.gz | 29.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| grimdall-0.4.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 57.5 kB
Release files / grimdall-0.4.0.tar.gz
| Download URL | grimdall-0.4.0.tar.gz |
|---|---|
| Size | 29.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
5be33c8d0ea51268ff667c4ee54251b24dcfdc919597248904683d9fa36650e7
|
|
BLAKE2b-256 checksum How to use checksums |
df98a22a91ca0eb97b38efd8deb2d8db8e974b60b56fadea6fe8b5d03869535c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 26, 2026.
Transparency logRelease files / grimdall-0.4.0-py3-none-any.whl
| Download URL | grimdall-0.4.0-py3-none-any.whl |
|---|---|
| Size | 28.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
7b63f41b3f2b61dd8a31c20c94507b0596320e91f90b38c4c149d60b89eea3e4
|
|
BLAKE2b-256 checksum How to use checksums |
db2ca01fd5e49822424b54179ff1aa27872f9f351b81f0456273696f5952eb58
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 26, 2026.
Transparency log