Skip to main content

XORAS Agentic Environment & Governance Framework v2.0

XORAS Hero Banner

PyPI Version License AST Security Build

XORAS Agentic Environment & Governance Framework is an enterprise-grade multi-agent runtime, dynamic AST security scanner, and cryptographic provenance platform developed by XORAS Systems LLC.


🛡️ AST Security Architecture & Guardrails

XORAS AST Security Shield Architecture

Key Features

  • AST Static Security Gating (env-integrity-sentry): Real-time Abstract Syntax Tree parsing and secret scanning that intercepts dangerous code injections (eval, exec, subprocess shell=True) and credential leaks prior to execution.
  • Cryptographic Trace Receipts (xoras.evidence.v1): Every agent state transition and tool invocation generates an Ed25519 / HMAC SHA-256 signed JSON-L trace receipt for 100% zero-falsification audit trails.
  • Swarm Agent Orchestrator: Multi-agent state graph pipeline coordinating Architect, Engineer, and Auditor roles with consensus gating and fallback remediation.
  • Zero-Drift Specification (.xorasrules & xoras.env.yaml): Standardized environment rules, role permissions, memory hierarchies, and workspace boundary controls.
  • Interactive Web Dashboard & Product Landing Page: Embedded web UI serving live trace logs, AST playgrounds, and product metrics (xoras serve).

Architecture Overview

flowchart TD
    UserRequest["User / Trigger Payload"] --> SwarmOrchestrator["Swarm Orchestrator (Architect)"]
    SwarmOrchestrator --> ASTEngine["AST Security Engine (Auditor)"]
    
    ASTEngine -- "Pass (Safety Score = 1.0)" --> RuntimeHarness["XORAS Runtime Harness (Engineer)"]
    ASTEngine -- "Fail (Restricted Token)" --> RejectReceipt["Log Rejection & Signed Receipt"]
    
    RuntimeHarness --> ToolExec["Subprocess / File I/O Sandbox"]
    ToolExec --> EvidenceSigner["Cryptographic Signer (HMAC / Ed25519)"]
    EvidenceSigner --> JSONLTrace["xoras_agent_traces.jsonl"]

Quickstart & Installation

1. Install Package

pip install xoras-agent-framework

2. Initialize Governance Environment

xoras init

This generates .xorasrules and xoras.env.yaml in your workspace root.

3. Scan Scripts for AST Violations

xoras scan my_script.py

4. Run Scripts in Isolated Sandbox

xoras run my_script.py

5. Serve Interactive Web Dashboard

xoras serve --port 8080

Open http://localhost:8080 to view the live product landing page and interactive AST playground.


Python API Usage

from xoras import XORASAgentEnvironment, SwarmOrchestrator

# Initialize environment
env = XORASAgentEnvironment(config_path="xoras.env.yaml")

# Run multi-agent orchestrator pipeline
orchestrator = SwarmOrchestrator(env=env)
result = orchestrator.run_pipeline(
    task_description="Deploy verified configuration file",
    code_payload='{"status": "active", "version": "2.0.0"}',
    target_path="artifacts/deploy_config.json"
)

print("Pipeline Success:", result["success"])
print("Trace Signature:", result["last_signature"])

Testing

Run the automated test suite:

PYTHONPATH=. pytest tests/

Documentation


License

Distributed under the MIT Enterprise License. See LICENSE for details.
© 2026 XORAS Systems LLC. All rights reserved.

Metadata

Release files for xoras-agent-framework 2.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for xoras-agent-framework 2.2.0
File Size Uploaded
xoras_agent_framework-2.2.0.tar.gz 25.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for xoras-agent-framework 2.2.0
File Interpreter ABI Platform
xoras_agent_framework-2.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 55.3 kB

Release files / xoras_agent_framework-2.2.0.tar.gz

Download URL xoras_agent_framework-2.2.0.tar.gz
Size 25.0 kB
Tags Source
SHA-256 checksum
How to use checksums
3f05e2b484fd43e351d6cefe1a837573657a4980d403126606599299fa99929d
BLAKE2b-256 checksum
How to use checksums
b9385cfc33dbb5aa3a8c06c73f7f47ed53575ae59fd93f627afa90530d9bb300
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.7

Release files / xoras_agent_framework-2.2.0-py3-none-any.whl

Download URL xoras_agent_framework-2.2.0-py3-none-any.whl
Size 30.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ceac4db124b7037017a934903889201f60f602ea519fab5b033624cef78a6e3b
BLAKE2b-256 checksum
How to use checksums
9d229997bba5ef332c1b4203e6b907e5eee42ccfe2cca3ef0b20f288b2cbd14f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.7

Release history Release notifications | RSS feed

2.3.0

2 release files

This release

2.2.0 This release

2 release files

2.1.0

2 release files

2.0.1

2 release files

2.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page