openai-agents-relayshield
OpenAI Agents SDK tools and a mandatory pre-execution gate for RelayShield's agentic-security endpoints — MCP server registry risk and AI-agent-sourced credential breach detection.
Install
pip install openai-agents-relayshield
Tools
from agents import Agent, Runner
from openai_agents_relayshield import check_mcp_server_risk, check_prompt_injection_breach
agent = Agent(
name="Assistant",
tools=[check_mcp_server_risk, check_prompt_injection_breach],
)
result = await Runner.run(
agent,
"Is it safe to connect to the MCP server at https://mcp.example.com/sse? My RelayShield key is rs_live_...",
)
check_mcp_server_risk— flags known-malicious IOC matches, typosquat domains, and newly-registered domains hosting an MCP server, before an agent connects to or installs it.check_prompt_injection_breach— checks whether an email appears in RelayShield's stolen-session corpus with a suspected-agentic-source marker (a session/token exposure that shows signs of having been captured via a compromised AI agent).
Both tools take api_key as a call argument rather than reading it from the environment implicitly — a shared agent process can act safely on behalf of multiple callers with different RelayShield keys.
Get a key at api.relayshield.net/developers.
Mandatory gate
Most "AI agent security" checks are optional — the agent can call them, but nothing stops it skipping the call and taking the risky action anyway. relayshield_mcp_gate is the other kind: a gate the framework enforces before a protected action (connecting to or installing an MCP server) can happen at all, built on the SDK's @tool_input_guardrail hook.
from openai_agents_relayshield.guardrail import relayshield_mcp_gate
# Attach directly to your own connect/install tool(s) — the guardrail is
# scoped by which tools you assign it to, not by matching tool names inside it.
connect_mcp_server.tool_input_guardrails = [relayshield_mcp_gate]
Properties, all non-negotiable by design:
- A hook exception defaults to
defer(blocked, with an explanatory message), never silently toallow— a gate failure must not become a pass. - Bounded retry applies only to transient upstream failures (timeout/429/5xx) — auth failures, malformed responses, and payment-required states are terminal after one attempt.
- The gate logs the decision, reason codes, check version, target, and timestamp — never keys, payment proofs, or session material.
- The raw connect/install tool should never be bound to the model directly in a real deployment — only route access to it through the gate.
Same normalized policy as langchain-relayshield's RelayShieldMCPGateMiddleware and its original standalone reference implementation, relayshield-langchain-gate — ported rather than imported, so this package has no dependency on LangChain/LangGraph.
License
MIT
Metadata
Release files for openai-agents-relayshield 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| openai_agents_relayshield-0.1.1.tar.gz | 8.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| openai_agents_relayshield-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 18.0 kB
Release files / openai_agents_relayshield-0.1.1.tar.gz
| Download URL | openai_agents_relayshield-0.1.1.tar.gz |
|---|---|
| Size | 8.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
ebd812c53e368d859514cbf0ee04c9c479f08432514fd25e2900d36652b9c6e5
|
|
BLAKE2b-256 checksum How to use checksums |
f83e173d20df8cceb33c6252d316a18cd3eab4d807d49f395d8fe7923f56c8d1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|
Release files / openai_agents_relayshield-0.1.1-py3-none-any.whl
| Download URL | openai_agents_relayshield-0.1.1-py3-none-any.whl |
|---|---|
| Size | 9.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
6b264de43e2ea06fa928b9f68190793e1870e07b2f6f257f9138fdeaa6a3185a
|
|
BLAKE2b-256 checksum How to use checksums |
c7d4537335a2e9d912c597719e09d8926e7754b6877d917e8a9fb07d3ef78190
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|