Skip to main content

Victor Contracts

Protocol and type definitions for building Victor verticals without pulling in the Victor runtime.

Overview

Use the contracts package when you want to author or publish a vertical package. Use victor-ai when you want to run a vertical inside the Victor host runtime.

The supported external authoring model is contract-first:

  • vertical packages depend on victor-contracts
  • verticals declare tools, capabilities, prompts, teams, and workflow metadata through the contracts package
  • victor-ai remains responsible for runtime concerns such as agent creation, capability injection, and tool execution

Installation

Contract-only authoring

pip install victor-contracts

Runtime usage

pip install victor-ai

Stable Contract Surface

The core authoring surface is available from the top-level package:

from victor_contracts import (
    CURRENT_DEFINITION_VERSION,
    CapabilityIds,
    CapabilityRequirement,
    ToolNames,
    ToolRequirement,
    VerticalBase,
    VerticalDefinition,
)

Key pieces:

  • VerticalBase: contract base class for external verticals
  • ToolNames: canonical contract-owned tool identifiers
  • CapabilityIds: canonical contract-owned runtime capability identifiers
  • ToolRequirement / CapabilityRequirement: typed requirement declarations
  • VerticalDefinition: validated serializable manifest returned by get_definition()

Quick Start

from victor_contracts import (
    CapabilityIds,
    CapabilityRequirement,
    ToolNames,
    ToolRequirement,
    VerticalBase,
)


class SecurityVertical(VerticalBase):
    name = "security"
    description = "Security analysis and audit workflows"
    version = "1.0.0"

    @classmethod
    def get_name(cls) -> str:
        return cls.name

    @classmethod
    def get_description(cls) -> str:
        return cls.description

    @classmethod
    def get_tool_requirements(cls) -> list[ToolRequirement]:
        return [
            ToolRequirement(ToolNames.READ, purpose="inspect code and configs"),
            ToolRequirement(ToolNames.GREP, purpose="search for vulnerable patterns"),
            ToolRequirement(ToolNames.SHELL, required=False, purpose="run scanners"),
            ToolRequirement(ToolNames.WEB_SEARCH, required=False, purpose="look up CVEs"),
        ]

    @classmethod
    def get_capability_requirements(cls) -> list[CapabilityRequirement]:
        return [
            CapabilityRequirement(
                capability_id=CapabilityIds.FILE_OPS,
                purpose="read repository contents",
            ),
            CapabilityRequirement(
                capability_id=CapabilityIds.WEB_ACCESS,
                optional=True,
                purpose="fetch external security references",
            ),
        ]

    @classmethod
    def get_system_prompt(cls) -> str:
        return "You are a security-focused assistant."

    @classmethod
    def get_prompt_templates(cls) -> dict[str, str]:
        return {
            "audit": "Audit the target for security issues and explain severity."
        }

    @classmethod
    def get_task_type_hints(cls) -> dict[str, dict[str, object]]:
        return {
            "audit": {
                "hint": "Start with read-first reconnaissance, then validate findings.",
                "tool_budget": 12,
                "priority_tools": [ToolNames.READ, ToolNames.GREP, ToolNames.SHELL],
            }
        }

    @classmethod
    def get_team_declarations(cls) -> dict[str, dict[str, object]]:
        return {
            "security_review_team": {
                "name": "Security Review Team",
                "formation": "pipeline",
                "members": [
                    {
                        "role": "researcher",
                        "goal": "Inspect the target and identify likely risks.",
                    },
                    {
                        "role": "reviewer",
                        "goal": "Validate findings before escalation.",
                    },
                ],
            }
        }


definition = SecurityVertical.get_definition()
assert definition.definition_version == "1.0"
assert definition.tools == [ToolNames.READ, ToolNames.GREP, ToolNames.SHELL, ToolNames.WEB_SEARCH]
assert definition.team_metadata.teams[0].team_id == "security_review_team"

Definition Contract

VerticalBase.get_definition() is the preferred contract API. It returns a validated VerticalDefinition manifest that contains:

  • definition_version
  • canonical tool identifiers
  • typed tool and capability requirements
  • system prompt text
  • prompt metadata and task-type hints
  • team metadata such as declarative team layouts and the default team identifier
  • declarative stage definitions
  • workflow metadata such as initial stage, provider hints, and evaluation criteria

Compatibility note:

  • get_config() still exists as a bridge for current victor-ai integrations
  • VerticalDefinition.to_config() / from_config() bridge the legacy config shape
  • VerticalDefinition.from_dict() supports serialized manifest round-tripping

Packaging

Register the vertical via the standard Victor entry point:

[project]
name = "victor-security"
version = "1.0.0"
dependencies = ["victor-contracts>=1.0.0"]

[project.entry-points."victor.plugins"]
security = "victor_security:plugin"

Discovery

Victor discovers external vertical packages through victor.plugins entry points, then each plugin registers one or more contract vertical definitions:

from victor_contracts.discovery import get_global_registry

registry = get_global_registry()
verticals = registry.get_verticals()

Guides And Examples

Testing

pip install -e ".[dev]"
pytest victor-contracts/tests -q

To verify compatibility with the runtime as well:

pip install -e ".[dev]" victor-ai
pytest victor-contracts/tests/unit tests/integration/test_contracts_integration.py -q

Versioning

The package follows semantic versioning, and the manifest contract is versioned separately via VerticalDefinition.definition_version. External verticals should treat the contracts package as the source of truth for supported identifiers and manifest fields.

Per-surface stability tiers and the deprecation policy (warn at least one minor release before removal; removals only in minor bumps) are defined in CONTRACT_STABILITY.md. Releases are recorded in CHANGELOG.md.

Links

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

victor_contracts-0.9.1.tar.gz (127.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

victor_contracts-0.9.1-py3-none-any.whl (170.9 kB view details)

Uploaded Python 3

File details

Details for the file victor_contracts-0.9.1.tar.gz.

File metadata

  • Download URL: victor_contracts-0.9.1.tar.gz
  • Upload date:
  • Size: 127.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for victor_contracts-0.9.1.tar.gz
Algorithm Hash digest
SHA256 a5cc2c7b50ebaabdf6f696eb73bfbfe52e99a6e76d95199a782d05873993a6a1
MD5 4e2a2cc4bd9df6b136493e48b084f344
BLAKE2b-256 84d1a32dbb6d6a8db26e98ca76178596d1328559868abdf79a028346a4dd6697

See more details on using hashes here.

Provenance

The following attestation bundles were made for victor_contracts-0.9.1.tar.gz:

Publisher: release-contracts.yml on anvai-labs/victor

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file victor_contracts-0.9.1-py3-none-any.whl.

File metadata

File hashes

Hashes for victor_contracts-0.9.1-py3-none-any.whl
Algorithm Hash digest
SHA256 f5e43aa12dd49caf5f911ac42ccce4d55f30c5887b4b9db1ba200ed3ed2edb38
MD5 45f1056b6235572b0df62963f15de8eb
BLAKE2b-256 3d0628787dc1bac7cdc81b80c0f9c2918391e7f480a0e3e119bca58b5f76e464

See more details on using hashes here.

Provenance

The following attestation bundles were made for victor_contracts-0.9.1-py3-none-any.whl:

Publisher: release-contracts.yml on anvai-labs/victor

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

This release

0.9.1 This release

2 files

0.9.0

2 files

0.7.3

2 files

0.7.2

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page