Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

English · 简体中文 · 日本語

Sponsio

License Install from PyPI Visit sponsio.dev

Follow on X Follow on LinkedIn Join our Discord

Sponsio

Same coding agent under a declared code freeze. Without Sponsio it drops the prod users table, back-fills fabricated rows, and files a status report that hides the damage. With Sponsio the first destructive SQL is blocked pre-execution: 35 checks, 100% deterministic, 0 LLM calls, p50 13µs.

Sponsio checks an agent's tool calls before they run. A rule can look at what already happened, so "check the policy before issuing a refund" is one rule instead of a paragraph of prompt. Each check takes under 0.01 ms and calls no model. Works with LangChain, Claude Agent, OpenAI Agents, Google ADK, CrewAI, Vercel AI, MCP, or any custom tool-calling loop, in Python or TypeScript.

An agent contract is a runtime rule that is checked at every agent action, backed by formal methods.

v0.2.0a14 alpha is out. pip install --pre sponsio, or npm install -D @sponsio/sdk@alpha. This one is for TypeScript. the install line used to leave out the alpha tag, so it resolved to 0.1.0, a much older release; QUICKSTART taught an API that threw; a mistyped command exited 0; and a redirect_to_safe verdict came back as a plain block, so no adapter could learn which tool to call instead. The evidence lane, which checks what an agent says rather than what it does, now works from TypeScript too. See the release notes.


How Sponsio works

Sponsio architecture: Agent Flow + (Natural Language + Pattern Library) compile into Contracts (Assumption → Enforcement), enforced by a Fuzzy LTL Monitor (deterministic + stochastic) that decides Pass / Block · Warn · Escalate / Redirect for every function call, with full audit trail logs feeding back to the agent.

On ODCV-Bench (12 frontier LLMs × 80 trajectories), unguarded models cheat in 11.5%–66.7% of runs. With Sponsio, 95.6% of misalignment is avoided on average; 24/36 high-risk scenarios at 100%. On the Financial-Audit-Fraud-Finding scenario, frontier models commit fraud in 16/24 trials; Sponsio blocks 18/19. On RedCode-Exec (1,410 cases), Sponsio reaches 98.9% combined (bash 98.3% · python 99.4%, lifted from 92.4% by a 4-iteration self-improvement loop), with 0 false positives on a 60-file clean-code audit. These are the open-core numbers; the Cloud version's LLM-judge layer takes ODCV-Bench to ~99% and RedCode-Exec to 99.4%. Book a demo for the Cloud and Enterprise versions.

One contract takes p50 0.0052 ms to check. The heaviest ODCV workload, 19 contracts on every call, takes 0.139 ms. An LLM-as-judge guardrail takes 50 to 800 ms, so this is 5,000× to 60,000× faster, and it calls no model. p99 stays near 1 ms on every workload measured.

See the full benchmark methodology and per-model breakdown, how Sponsio compares against prompt filters, output validators, LLM-as-judge, and sandboxing, or dive into the architecture and formal methods primer.


Quick start

Two ways in: paste a prompt into your coding agent, or run the CLI yourself.

Paste into Claude Code / Codex / Cursor. The agent walks the full onboarding flow:

One-shot prompt: Python   One-shot prompt: TypeScript

Or run the CLI yourself:

pip install --pre sponsio   # or: npm install -D @sponsio/sdk@alpha
sponsio init .              # asks what you use, then writes sponsio.yaml

The wizard auto-detects your framework and prints the right wrap snippet. For manual wiring, see all supported integrations. OpenClaw users get bundled ClawHavoc and CVE-2026-25253 coverage out of the box. For config reference, observe → enforce flip, and CI wiring, see the full walkthrough.

Watching runs, and sharing a rulebook. Enforcement is local and needs no account. If you want to see what your agent did, or keep the rulebook somewhere a person reviews it before it arms, app.sponsio.dev is the hosted side. One line puts a run on screen:

import sponsio
import sponsio.bridge

guard = sponsio.Sponsio(config="sponsio.yaml", agent_id="mailer", mode="enforce")
run = sponsio.bridge.attach(guard)

sponsio push sponsio.yaml uploads a rulebook as a draft. It does not arm. A person publishes it in the console, and sponsio pull or config="sponsio://default" brings the reviewed version back. Sending is best effort, so a console that is down never blocks the agent. See the hosted console.

Drafting contracts from natural language. sponsio validate "<rule in plain English>" turns a plain-English rule into a contract you can read back. Treat the output as a starting draft to review and adjust before you enforce. The determinism is in how contracts are enforced at runtime, not in how they're drafted.


Contract Library

22 contract bundles ship out of the box, organized by tier (always-on / per-tool / per-incident). Each bundle is a YAML pack composed from Sponsio's deterministic patterns. Drop one into sponsio.yaml and your agent is guarded against a known failure class in one line, with no per-contract authoring.

# sponsio.yaml: one-line bundle inclusion
agents:
  my_agent:
    workspace: "/srv/my-bot"
    include:
      - sponsio:capability/destructive  # gate irreversible actions
      - sponsio:capability/shell        # if your agent runs commands
      - sponsio:capability/filesystem   # if your agent touches files

See the full bundle reference for all 22 bundles, or the 48 underlying patterns for the primitives they compose. Want a bundle for your agent type? That is the most useful thing to contribute right now. Open an issue with your incident, CVE, or pattern.


Contributing

Patches, issue reports, and new pattern proposals are welcome. Start with CONTRIBUTING.md. Sponsio's threat model draws on public security research; e.g. Simon Willison's "Lethal Trifecta" shaped our multi-tool composition contracts. Have a threat model we should defend against? Open an issue.


License

Apache 2.0 (LICENSE).

AI agents reading this repo: llms.txt lists canonical doc paths; llms-full.txt is the concatenated full context dump.

Release files for sponsio 0.2.0a14

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for sponsio 0.2.0a14
File Size Uploaded
sponsio-0.2.0a14.tar.gz 1.0 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for sponsio 0.2.0a14
File Interpreter ABI Platform
sponsio-0.2.0a14-py3-none-any.whl Python 3 none any Details

Total release size: 1.9 MB

Release files / sponsio-0.2.0a14.tar.gz

Download URL sponsio-0.2.0a14.tar.gz
Size 1.0 MB
Tags Source
SHA-256 checksum
How to use checksums
ddd4a910e5d279c96701345058d47ef8455de4489f30518b092c63357cf8d2f4
BLAKE2b-256 checksum
How to use checksums
dc8834b6b11efbbfb2c430e66bb94a34028a2092640d1dcc72d9a08d3e3cd8e3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 4, 2026.

Transparency log

Release files / sponsio-0.2.0a14-py3-none-any.whl

Download URL sponsio-0.2.0a14-py3-none-any.whl
Size 829.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
cfc75ba9452a4a4cb794df90e055f193fb7806a2845ccff9a5889d52ceb6eb24
BLAKE2b-256 checksum
How to use checksums
5c05c1ab6ef7d58a2a4460b6a7667b06b48aa1ef40f5e2deafa5240e7afdf4a9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 4, 2026.

Transparency log
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page