Skip to main content

GuardClaw: The Open Cryptographic Execution Format for AI Agents

PyPI Python License Protocol

GuardClaw implements GEF-SPEC-1.0 — a vendor-neutral, language-agnostic protocol for turning AI agent tool calls into tamper-evident, offline-verifiable execution records.

No server required. No SaaS dependency. No central verifier. Just a signed file and a public key.


Why this exists

AI agents now run shell commands, call APIs, and modify production systems. Standard application logs live in mutable databases — anyone with admin or root access can alter them after the fact. GEF-SPEC gives you a different guarantee: a hash-chained, Ed25519-signed ledger where any tampering breaks the chain and is mathematically detectable.

This is honest about its scope. GuardClaw proves what was recorded — not whether the action was wise, authorized, or safe. It's an evidence layer, not a policy engine.


What it actually does today

  • RFC 8785 canonicalization (JCS) — deterministic serialization across platforms.
  • Causal hash chains — SHA-256 forward-linked envelopes; any gap or reorder is detectable.
  • Ed25519 signing, with an optional out-of-process signing daemon so keys never live in agent memory.
  • AWS KMS / HashiCorp Vault support for delegated signing (KMS HSMs are FIPS 140-2 Level 3 validated in most regions — verify current validation status for your specific region/key type before relying on this for a compliance claim).
  • RFC 6962 Merkle inclusion proofs — prove a single record existed in a large ledger without sharing the whole file.
  • MCP proxy mode — intercept and sign tool calls between an MCP client and server with no code changes.
  • 274-case internal adversarial test suite covering signature mutation, chain tampering, and crash recovery. This is our own test suite, not a third-party audit — treat it as evidence of engineering rigor, not as independent certification.

What it doesn't do (yet)

  • No independent security audit or penetration test has been performed.
  • No production deployments at scale are known to us.
  • Compliance mapping (EU AI Act, SOC 2, etc.) describes how the primitives could support those requirements — it is not a certification, legal opinion, or guarantee of audit acceptance. Talk to your own counsel and auditors.

Quick start

pip install --upgrade guardclaw
from guardclaw import GEFLedger, Ed25519KeyManager, RecordType

key_manager = Ed25519KeyManager.generate()
ledger = GEFLedger(
    key_manager=key_manager,
    agent_id="my-agent",
    ledger_path="./evidence_vault",
)

ledger.emit(
    record_type=RecordType.TOOL_CALL,
    payload={"action": "example_action", "detail": "..."},
)

assert ledger.verify_chain() is True

Out-of-Process Signing Daemon (Zero Key Exposure)

For production deployments where agent processes should not hold private signing keys in memory:

# Start background daemon
guardclaw daemon start --port 9443
from guardclaw import DaemonClient, RecordType

with DaemonClient(host="127.0.0.1", port=9443) as client:
    env = client.emit(
        record_type=RecordType.TOOL_CALL,
        payload={"action": "rebalance_portfolio", "amount": 1000},
    )

Model Context Protocol (MCP) Transparent Proxy

Intercept and sign tool calls between Claude Desktop / Cursor and upstream MCP servers with zero code modifications:

guardclaw mcp-proxy --cmd "npx -y @modelcontextprotocol/server-filesystem ./data"

The bet we're making

Signed logs are a checkbox any platform can add for free. A shared, vendor-neutral format that works the same way whether your agent runs on AWS, Azure, GCP, or your laptop is not something any single platform has an incentive to build — because it makes you portable, not locked in.

If you maintain an MCP server, an agent framework, or a compliance tool and want GEF-SPEC support, open an issue or a PR. Real third-party adoption is the only thing that makes this format worth anything — we'd rather have one external integration than a hundred stars.


License

Apache 2.0. Fork it, extend it, integrate it — the code was never the moat.

Metadata

Release files for guardclaw 0.8.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for guardclaw 0.8.1
File Size Uploaded
guardclaw-0.8.1.tar.gz 1.6 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for guardclaw 0.8.1
File Interpreter ABI Platform
guardclaw-0.8.1-py3-none-any.whl Python 3 none any Details

Total release size: 1.7 MB

Release files / guardclaw-0.8.1.tar.gz

Download URL guardclaw-0.8.1.tar.gz
Size 1.6 MB
Tags Source
SHA-256 checksum
How to use checksums
06dee61a98e0dd1313227150e7a93cec4ee12a501daee6acea15a7fdeabcffe1
BLAKE2b-256 checksum
How to use checksums
938631928b9fd4d6b4568134f925d563ef01039b331c9c9959a788ea7c7bfb77
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.5

Release files / guardclaw-0.8.1-py3-none-any.whl

Download URL guardclaw-0.8.1-py3-none-any.whl
Size 133.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c4762c7aacfb7ab1aae60e046205074a58fcf2357a0edad52f780e4741686e84
BLAKE2b-256 checksum
How to use checksums
a8159606622f5e14a88cc524da5edc0f9401dfc586c896d3cd29069af57942fb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.5

Release history Release notifications | RSS feed

0.8.2

2 release files

This release

0.8.1 This release

2 release files

0.8.0

2 release files

0.7.1

2 release files

0.7.0

2 release files

0.6.1

2 release files

0.6.0

2 release files

0.5.2

2 release files

0.5.1

2 release files

0.1.4

2 release files

0.1.3

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page