Skip to main content

GuardClaw: The Open Cryptographic Execution Format for AI Agents

PyPI Python License Protocol

GuardClaw implements GEF-SPEC-1.0 — a vendor-neutral, language-agnostic protocol for turning AI agent tool calls into tamper-evident, offline-verifiable execution records.

No server required. No SaaS dependency. No central verifier. Just a signed file and a public key.


Why this exists

AI agents now run shell commands, call APIs, and modify production systems. Standard application logs live in mutable databases — anyone with admin or root access can alter them after the fact. GEF-SPEC gives you a different guarantee: a hash-chained, Ed25519-signed ledger where any tampering breaks the chain and is mathematically detectable.

This is honest about its scope. GuardClaw proves what was recorded — not whether the action was wise, authorized, or safe. It's an evidence layer, not a policy engine.


What it actually does today

  • RFC 8785 canonicalization (JCS) — deterministic serialization across platforms.
  • Causal hash chains — SHA-256 forward-linked envelopes; any gap or reorder is detectable.
  • Ed25519 signing, with an optional out-of-process signing daemon so keys never live in agent memory.
  • AWS KMS / HashiCorp Vault support for delegated signing (KMS HSMs are FIPS 140-2 Level 3 validated in most regions — verify current validation status for your specific region/key type before relying on this for a compliance claim).
  • RFC 6962 Merkle inclusion proofs — prove a single record existed in a large ledger without sharing the whole file.
  • MCP proxy mode — intercept and sign tool calls between an MCP client and server with no code changes.
  • 274-case internal adversarial test suite covering signature mutation, chain tampering, and crash recovery. This is our own test suite, not a third-party audit — treat it as evidence of engineering rigor, not as independent certification.

What it doesn't do (yet)

  • No independent security audit or penetration test has been performed.
  • No production deployments at scale are known to us.
  • Compliance mapping (EU AI Act, SOC 2, etc.) describes how the primitives could support those requirements — it is not a certification, legal opinion, or guarantee of audit acceptance. Talk to your own counsel and auditors.

Quick start

pip install --upgrade guardclaw
from guardclaw import GEFLedger, Ed25519KeyManager, RecordType

key_manager = Ed25519KeyManager.generate()
ledger = GEFLedger(
    key_manager=key_manager,
    agent_id="my-agent",
    ledger_path="./evidence_vault",
)

ledger.emit(
    record_type=RecordType.TOOL_CALL,
    payload={"action": "example_action", "detail": "..."},
)

assert ledger.verify_chain() is True

Out-of-Process Signing Daemon (Zero Key Exposure)

For production deployments where agent processes should not hold private signing keys in memory:

# Start background daemon
guardclaw daemon start --port 9443
from guardclaw import DaemonClient, RecordType

with DaemonClient(host="127.0.0.1", port=9443) as client:
    env = client.emit(
        record_type=RecordType.TOOL_CALL,
        payload={"action": "rebalance_portfolio", "amount": 1000},
    )

Model Context Protocol (MCP) Transparent Proxy

Intercept and sign tool calls between Claude Desktop / Cursor and upstream MCP servers with zero code modifications:

guardclaw mcp-proxy --cmd "npx -y @modelcontextprotocol/server-filesystem ./data"

Where this fits

Provenance standards like SLSA and in-toto attest to how software was built and deployed — a point-in-time, pre-execution guarantee.

GuardClaw addresses a different moment in the lifecycle: what an autonomous agent does at runtime, as it executes tool calls and interacts with external systems.

We are one of several independent groups exploring runtime execution attestation for AI agents in 2026. What we offer today is:

  1. A Python reference implementation for Python agent runtimes and frameworks.
  2. A zero-code MCP stdio proxy that wraps and signs tool invocations for any server speaking the Model Context Protocol (regardless of whether the server was written in TypeScript, Python, or Go).
  3. An open, vendor-neutral envelope format (GEF-SPEC-1.0) based on RFC 8785 canonicalization and Ed25519 signatures.

If you maintain an MCP tool or Python agent framework and want to experiment with runtime cryptographic evidence, we welcome issues and pull requests.


License

Apache 2.0. Fork it, extend it, integrate it — the code was never the moat.

Metadata

Release files for guardclaw 0.8.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for guardclaw 0.8.2
File Size Uploaded
guardclaw-0.8.2.tar.gz 1.6 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for guardclaw 0.8.2
File Interpreter ABI Platform
guardclaw-0.8.2-py3-none-any.whl Python 3 none any Details

Total release size: 1.7 MB

Release files / guardclaw-0.8.2.tar.gz

Download URL guardclaw-0.8.2.tar.gz
Size 1.6 MB
Tags Source
SHA-256 checksum
How to use checksums
582ea7e237e35563793e9625ac701b9da0fae1b02fc912d716c114c7ee7cdb44
BLAKE2b-256 checksum
How to use checksums
cc04441ec064290a06de9e4473f2d12de9a63e93136411dff5358248162c230c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.5

Release files / guardclaw-0.8.2-py3-none-any.whl

Download URL guardclaw-0.8.2-py3-none-any.whl
Size 133.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
65a51259279df38e83dca9577d3097cf9fa3311ff4f761b29ff8482d43697e34
BLAKE2b-256 checksum
How to use checksums
e6f79cf1225addd6ae4d1cbef8bd9232b22a49185a8dd1507208c795da1ed2b4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.13.5

Release history Release notifications | RSS feed

This release

0.8.2 This release

2 release files

0.8.1

2 release files

0.8.0

2 release files

0.7.1

2 release files

0.7.0

2 release files

0.6.1

2 release files

0.6.0

2 release files

0.5.2

2 release files

0.5.1

2 release files

0.1.4

2 release files

0.1.3

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page