ragleap-agents
A small agent loop over ragleap-tools
Tool objects. The model proposes one action at a time, sees the result,
and proposes the next, up to a hard step cap. You bring the model as a plain
callable; the library has no provider code and no database.
pip install ragleap-agents
# or: uv add ragleap-agents
Quickstart
from ragleap_tools import CALCULATOR_TOOL
from ragleap_agents import Agent, Policy, TRUSTED
def my_llm(prompt: str) -> str:
... # call any model, return its text
agent = Agent(
llm=my_llm,
tools=[CALCULATOR_TOOL],
policy=Policy(max_steps=4, tools={"calculator": TRUSTED}),
)
result = agent.run("What is 6 * 7?")
print(result.status, result.answer) # done, a short summary of what was found
for step in result.steps: # the transcript: tool, arguments, status, observation
print(step["tool"], step["arguments"], step["status"])
Approval gates: pause and resume
from ragleap_agents import ToolPolicy
policy = Policy(tools={"write_file": ToolPolicy(taints=False, outbound=True, requires_approval=True)})
agent = Agent(my_llm, tools, policy, store=my_store)
result = agent.run("save the report")
if result.status == "awaiting_approval":
call = result.pending # {"call_id", "tool", "arguments", "forced"}
# ... show it to a human, then, in this process or another one:
result = agent.resume(result.run_id, {call["call_id"]: True}) # or False to reject
A paused run is a plain JSON dict in a StateStore (save/load). The
in-memory store is included; write your own for a file, Redis or a database.
resume() raises ResumeError if the run is unknown, not awaiting approval,
or the decision does not match the pending call, so an approval cannot be replayed.
The safety model
- Every proposal is checked. The tool must exist and the arguments must fit
its JSON Schema (required keys, unknown keys, type and enum only; no
$reforoneOf). Anything else stops the run withstop_reason="invalid_plan"; no tool runs. - Tool results are untrusted data. They are capped (1,500 characters each,
4,000 in the prompt), fenced in
<observation>tags, and lookalike tags inside them are neutralised, case-insensitively. - Taint rule. Declare each tool with a
ToolPolicy:taints(its result is external content) andoutbound(it acts on the outside world). Once a tainting tool has run, every later outbound tool needs approval, whatever else is configured. The policy can only tighten. - Fail closed. A tool with no declared policy counts as both tainting and outbound.
Use
TRUSTEDonly for tools that neither return external content nor act outside. - Limits.
max_steps(default 4, hard cap 8), a duplicate-action stop, and a deadline checked between calls (a running tool is not interrupted). - Failures stay contained.
run()does not raise for model or tool failures. A tool's exception text is never shown to the model or returned; only its type is.
What this does not do: it does not stop prompt injection. It limits what an
injected instruction can do, and only as far as your ToolPolicy declarations are
accurate. Tool descriptions are shown to the model too (capped at 300 characters),
so tools from an untrusted source (for example a remote MCP server) can inject
through them. Approval prompts are only as good as the human reading them.
Status
v0.1.0, alpha. 41 tests with a scripted model on Python 3.10, 3.11 and 3.12 (see
tests/); each safety property above has a test that fails if the property is broken.
Not verified: any real model (no provider has been run through this loop yet),
long runs, concurrent resumes across processes (your store must make resume atomic),
and equivalence with RagLeap Core's own agent loop, which this mirrors as of core
commit 59fd555 (see docs/design/agent-loop.md).
License
MIT
Metadata
Release files for ragleap-agents 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| ragleap_agents-0.1.0.tar.gz | 14.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| ragleap_agents-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 25.3 kB
Release files / ragleap_agents-0.1.0.tar.gz
| Download URL | ragleap_agents-0.1.0.tar.gz |
|---|---|
| Size | 14.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
44cf12676dfc3b607ef5cd08f2135bde56e90bab4a2ef5e4c2ec66121f0d50a1
|
|
BLAKE2b-256 checksum How to use checksums |
8529ea80291e22911224e333252c830f881855bb67746e10bc7b7c5e60ae2780
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 9, 2026.
Transparency logRelease files / ragleap_agents-0.1.0-py3-none-any.whl
| Download URL | ragleap_agents-0.1.0-py3-none-any.whl |
|---|---|
| Size | 10.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
d305238f31fa5f65adf8d6adb363bdb4f950da7763cdbb98866e0d0eb49efe01
|
|
BLAKE2b-256 checksum How to use checksums |
9cf53f74dda51da2f5ce2f614bf45195f8dbbf08020acd662bd039cc93b3bafa
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 9, 2026.
Transparency log