Skip to main content

🧵 Loom

PyPI CI Python License: MIT

English · 中文

The black box, firewall & debugger for AI agents.

Your agent ran — touched files, called tools, spent tokens — and you have no idea what it did or why. Loom records every action, replays it byte-for-byte for $0, firewalls dangerous calls before they run, and lets you step through the whole run like a debugger. Works with any Claude/OpenAI-API agent — Claude Code, LangGraph, CrewAI, your own.

pip install loom-harness          # zero dependencies
loom record claude "fix the failing test" --safe
recorded 17 steps · 42k tokens → session.loom.json
🛡  firewall blocked 1 risky call:  Read(".env")
🔬 loom debug session.loom.json   # step through it, fork any turn live

Loom's step-debugger: walk a multi-agent run — reasoning, tools, the exact context the model saw, and fork any turn live

Step through any agent run — the reasoning, the tools, the exact context the model saw, and fork any turn live.


Why Loom

  • 🎥 Record any agent — proxy Claude Code / Codex / Cursor / your own, one command, zero code changes.
  • Replay for $0 — every call recorded at one boundary → byte-identical, offline. Deterministic CI for a stochastic agent.
  • 🔬 Step-debug it — walk each step, see the exact context the model saw, then edit a turn and re-run it live.
  • 🕸 Any multi-agent framework — LangGraph · CrewAI · AutoGen · OpenAI-Agents · Claude-SDK, recovered into one agent tree from the wire, zero code changes.
  • 🛡 Firewall it — deny / confirm dangerous calls before they run, by capability (cap:money_movement) or sequence (after Read(.env): deny network).
  • 🕵 Catch exfiltration — a secret flowing to an egress, even base64-encoded or paraphrased, confirmed by an LLM judge.
  • Undo the world — revert the files an agent changed, or snapshot & restore a whole workspace + database.

The debugger

loom debug run.loom.json (or loom live to watch it run) opens a step-debugger in your browser:

  • Step through every action — the model's reasoning, the tool call + args, the world-diff (file / SQL row / DOM), risk, tokens.
  • Context frame — the exact conversation the model saw at each step: the debugger's stack & variables.
  • Fork & re-run live — inject a message or switch the model at any turn; only the divergent tail costs a call, and the branch appears beside the original.
  • Multi-agent tree — a supervisor/sub-agent system (yours or a third-party framework) recovered from the wire and shown as a collapsible tree, laned by agent.
  • Ask & assert — send the live agent a new message, or check plain-English expectations (never issue_refund, output contains …) as a CI gate.

loom studio <trace> freezes the whole UI into one shareable HTML file (no server, no agent).


Debug a live agent

loom live --agent app:agent        # watch it run, send follow-ups, fork any turn

Behind a gRPC / HTTP endpoint? Point your server at the recording proxy and drive it from the same debugger — no code, just your grpcurl:

loom live --proxy-port 9000 \
  --trigger 'grpcurl -d "{\"prompt\": $LOOM_PROMPT_JSON}" -plaintext :50051 agent.Agent/Run'
# then start your server with ANTHROPIC_BASE_URL=http://127.0.0.1:9000

Loom reconstructs the agent's full internal hierarchy even though it's behind an endpoint.


Use it as a Python harness

from loom import Agent, tool, Policy

@tool
def search(q: str) -> str:
    "Search the docs."
    return db.search(q)

agent = Agent(model="claude-opus-4-8", tools=[search],
              policy=Policy(deny=["issue_refund*"], budget_tokens=50_000))  # in-loop firewall
run = agent.run("What changed in the API last week?")

run.replay()        # byte-identical, no API calls
run.fork(at=3)      # rewind to turn 3, continue live on a new branch

One effect boundary records every model + tool call — so replay, fork, free CI, human-in-the-loop, the firewall, and every analyzer fall out of the same primitive. The kernel is zero-dependency.


A few more commands

loom replay <trace> re-run byte-identical, $0, offline
loom taint · loom dlp --judge exfiltration lineage · semantic DLP
loom redteam run --generate <m> AI red-teamer — invents attacks for your tool surface
loom mcp gateway -- <server> firewall + record any MCP server
loom undo <trace> revert the files the agent changed

Run loom --help for the full set — record, replay, debug, live, studio, firewall, taint, dlp, redteam, mcp, undo, cost, rootcause, experiment, and more.


Install

pip install loom-harness                # kernel + CLI, zero deps
pip install "loom-harness[anthropic]"   # + live Claude
pip install "loom-harness[mcp]"         # + MCP gateway

Python 3.10–3.13 · MIT · import loom

Loom shrinks an agent's blast radius and makes its behavior inspectable — it is not a guarantee a model can't misbehave. See the threat model.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

loom_harness-0.33.8.tar.gz (2.4 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

loom_harness-0.33.8-py3-none-any.whl (396.2 kB view details)

Uploaded Python 3

File details

Details for the file loom_harness-0.33.8.tar.gz.

File metadata

  • Download URL: loom_harness-0.33.8.tar.gz
  • Upload date:
  • Size: 2.4 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.11

File hashes

Hashes for loom_harness-0.33.8.tar.gz
Algorithm Hash digest
SHA256 7c8f7f0b536fb4f662311f765c27149f5468a002ac90108b4b427680b06d0e68
MD5 54eb3dee23db8d97df9543e05a83faf6
BLAKE2b-256 66758c2c9740caf1946991805ccf0f083a9de54ae3180331bfba4290c2952388

See more details on using hashes here.

File details

Details for the file loom_harness-0.33.8-py3-none-any.whl.

File metadata

  • Download URL: loom_harness-0.33.8-py3-none-any.whl
  • Upload date:
  • Size: 396.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.11

File hashes

Hashes for loom_harness-0.33.8-py3-none-any.whl
Algorithm Hash digest
SHA256 c3c15f24786275012db40a658b91f1d0ada9f0d7aecfa9a3cf2b90b0d237bae6
MD5 510cd98415031d8ba4e79f0baac9d4c4
BLAKE2b-256 6e8378ad29ef49ad0ceb9083779e2ceafdad28a6c5934da476dfd22815bafe00

See more details on using hashes here.

Release history Release notifications | RSS feed

0.33.12

2 files

0.33.11

2 files

0.33.10

2 files

0.33.9

2 files

This release

0.33.8 This release

2 files

0.33.7

2 files

0.33.6

2 files

0.33.5

2 files

0.33.4

2 files

0.33.3

2 files

0.33.2

2 files

0.33.1

2 files

0.33.0

2 files

0.32.4

2 files

0.32.3

2 files

0.32.2

2 files

0.32.1

2 files

0.32.0

2 files

0.31.4

2 files

0.31.3

2 files

0.31.2

2 files

0.31.1

2 files

0.31.0

2 files

0.30.0

2 files

0.29.0

2 files

0.28.0

2 files

0.27.0

2 files

0.26.0

2 files

0.25.0

2 files

0.24.0

2 files

0.23.0

2 files

0.22.0

2 files

0.21.0

2 files

0.20.0

2 files

0.19.0

2 files

0.18.0

2 files

0.17.0

2 files

0.16.0

2 files

0.15.0

2 files

0.14.0

2 files

0.13.0

2 files

0.12.0

2 files

0.11.0

2 files

0.10.0

2 files

0.9.0

2 files

0.8.0

2 files

0.7.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page