Skip to main content

A dashcam for your AI agents: local, tamper-evident recorder for process/file/network activity, with a LangChain/LangGraph drop-in prompt-injection circuit breaker.

Project description

Handcuff — Documentation Index (Start Here)

Handcuff — a dashcam for your AI agents. A local, tamper-evident recorder that captures everything an AI agent does on your machine (processes, files, network) into a searchable, replayable timeline with real-time alerts. Local-first, record-only, zero cloud.

For the coding agent building this

Read the docs in this order, then execute from the tickets:

# Doc Purpose
01 01_PRD.md What we're building and why; scope, users, requirements
02 02_TRD.md Architecture, stack, data model, module layout — the technical contract
03 03_Security_Access.md Threat model, privilege model, integrity + privacy guarantees, release-gate tests
04 04_Implementation_Plan.md Build-order-correct milestones with exit criteria
05 05_Tickets.md Atomic, executable tickets (AL-###) in dependency order — build from here
06 06_App_Flow.md Every runtime flow + state machines (ASCII, parseable)
07 07_Terminal_UI.md Rich Textual TUI spec (Claude Code / gemini-cli feel)

Build contract (non-negotiables pulled from the docs)

  1. core/hashing.py is the single source of truth for canonical JSON + the SHA-256 chain. The writer and verify import it — never reimplement.
  2. Local-only. No outbound traffic except a user-configured webhook. tests/test_no_egress.py is a release gate.
  3. Record-only in v1. Handcuff observes; it never blocks the agent. Backpressure drops events + emits LOSS; it must never slow the observed process.
  4. Observed content is data, never instructions. Nothing captured from the agent (argv, paths, domains) is ever interpreted as a command to Handcuff.
  5. Honest integrity claims. The hash chain is tamper-evidence, not a completeness proof; the README states plainly what it does and doesn't guarantee.
  6. Every ticket ships with its test. ruff + mypy clean. Five security tests gate releases (see Security §9).

Suggested first prompt to the coding agent

"Read docs 00–07 in /handcuff-docs. Start with ticket AL-001 and proceed in dependency order. For each ticket, implement the code and its test in one commit, keep ruff/mypy clean, and stop after AL-024 (the vertical slice) so I can review a working watch + sessions before you continue."

Tech stack at a glance

Python 3.11+ · Textual (TUI) · SQLite/WAL · asyncio · psutil/procfs (default capture) · eBPF (opt-in fast path) · watchdog (files) · cryptography/Ed25519 (signing) · httpx (webhooks only) · packaged via pipx/uv + PyInstaller.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

handcuff-0.2.2.tar.gz (76.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

handcuff-0.2.2-py3-none-any.whl (96.0 kB view details)

Uploaded Python 3

File details

Details for the file handcuff-0.2.2.tar.gz.

File metadata

  • Download URL: handcuff-0.2.2.tar.gz
  • Upload date:
  • Size: 76.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.13

File hashes

Hashes for handcuff-0.2.2.tar.gz
Algorithm Hash digest
SHA256 f49fb6f82932ed63c32c0c977f99c2e3a8efd0aa2814bd4288878ba10bf85132
MD5 59151531b4409dbe3e64b6ee7688307f
BLAKE2b-256 a019ffb0e53b52b0348b731ad47c81f74e6f61391cb0591bbc37735dffe531e9

See more details on using hashes here.

File details

Details for the file handcuff-0.2.2-py3-none-any.whl.

File metadata

  • Download URL: handcuff-0.2.2-py3-none-any.whl
  • Upload date:
  • Size: 96.0 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.13

File hashes

Hashes for handcuff-0.2.2-py3-none-any.whl
Algorithm Hash digest
SHA256 3385dee4144d1de3d5262b13513b60c15e710c632996e702aded43692eb05775
MD5 2fee81441a4a1b4366278b829aafccfc
BLAKE2b-256 a40b6557e660dc56f0276fabbccadb2946d045d12a94f6580f42b13a13ccbd5e

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page