Skip to main content

openai-agents-relayshield

OpenAI Agents SDK tools and a mandatory pre-execution gate for RelayShield's agentic-security endpoints — MCP server registry risk and AI-agent-sourced credential breach detection.

Install

pip install openai-agents-relayshield

Tools

from agents import Agent, Runner
from openai_agents_relayshield import check_mcp_server_risk, check_prompt_injection_breach

agent = Agent(
    name="Assistant",
    tools=[check_mcp_server_risk, check_prompt_injection_breach],
)

result = await Runner.run(
    agent,
    "Is it safe to connect to the MCP server at https://mcp.example.com/sse? My RelayShield key is rs_live_...",
)
  • check_mcp_server_risk — flags known-malicious IOC matches, typosquat domains, and newly-registered domains hosting an MCP server, before an agent connects to or installs it.
  • check_prompt_injection_breach — checks whether an email appears in RelayShield's stolen-session corpus with a suspected-agentic-source marker (a session/token exposure that shows signs of having been captured via a compromised AI agent).

Both tools take api_key as a call argument rather than reading it from the environment implicitly — a shared agent process can act safely on behalf of multiple callers with different RelayShield keys.

Get a key at api.relayshield.net/developers.

Mandatory gate

Most "AI agent security" checks are optional — the agent can call them, but nothing stops it skipping the call and taking the risky action anyway. relayshield_mcp_gate is the other kind: a gate the framework enforces before a protected action (connecting to or installing an MCP server) can happen at all, built on the SDK's @tool_input_guardrail hook.

from openai_agents_relayshield.guardrail import relayshield_mcp_gate

# Attach directly to your own connect/install tool(s) — the guardrail is
# scoped by which tools you assign it to, not by matching tool names inside it.
connect_mcp_server.tool_input_guardrails = [relayshield_mcp_gate]

Properties, all non-negotiable by design:

  • A hook exception defaults to defer (blocked, with an explanatory message), never silently to allow — a gate failure must not become a pass.
  • Bounded retry applies only to transient upstream failures (timeout/429/5xx) — auth failures, malformed responses, and payment-required states are terminal after one attempt.
  • The gate logs the decision, reason codes, check version, target, and timestamp — never keys, payment proofs, or session material.
  • The raw connect/install tool should never be bound to the model directly in a real deployment — only route access to it through the gate.

Same normalized policy as langchain-relayshield's RelayShieldMCPGateMiddleware and its original standalone reference implementation, relayshield-langchain-gate — ported rather than imported, so this package has no dependency on LangChain/LangGraph.

License

MIT

Metadata

Release files for openai-agents-relayshield 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for openai-agents-relayshield 0.1.1
File Size Uploaded
openai_agents_relayshield-0.1.1.tar.gz 8.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for openai-agents-relayshield 0.1.1
File Interpreter ABI Platform
openai_agents_relayshield-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 18.0 kB

Release files / openai_agents_relayshield-0.1.1.tar.gz

Download URL openai_agents_relayshield-0.1.1.tar.gz
Size 8.9 kB
Tags Source
SHA-256 checksum
How to use checksums
ebd812c53e368d859514cbf0ee04c9c479f08432514fd25e2900d36652b9c6e5
BLAKE2b-256 checksum
How to use checksums
f83e173d20df8cceb33c6252d316a18cd3eab4d807d49f395d8fe7923f56c8d1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.6

Release files / openai_agents_relayshield-0.1.1-py3-none-any.whl

Download URL openai_agents_relayshield-0.1.1-py3-none-any.whl
Size 9.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
6b264de43e2ea06fa928b9f68190793e1870e07b2f6f257f9138fdeaa6a3185a
BLAKE2b-256 checksum
How to use checksums
c7d4537335a2e9d912c597719e09d8926e7754b6877d917e8a9fb07d3ef78190
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.6

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page