{"_id":"@11ai/execution-governance","_rev":"14-67b52705a60ed532290f16d9f4a757a1","name":"@11ai/execution-governance","dist-tags":{"latest":"0.4.2"},"versions":{"0.1.0":{"name":"@11ai/execution-governance","version":"0.1.0","keywords":["ai-agents","authorization","mcp","guardrails","security","policy","fail-closed","audit"],"license":"Apache-2.0","_id":"@11ai/execution-governance@0.1.0","maintainers":[{"name":"11aimain","email":"quantum@11aiblockchain.com"}],"homepage":"https://github.com/11-11AI/execution-governance#readme","bugs":{"url":"https://github.com/11-11AI/execution-governance/issues"},"bin":{"eg-verify":"dist/cli/eg-verify.js"},"dist":{"shasum":"0b027dc2ca6cba270d54f85fbfe4d84bcbc87a21","tarball":"https://registry.npmjs.org/@11ai/execution-governance/-/execution-governance-0.1.0.tgz","fileCount":44,"integrity":"sha512-J3yTfI55+A+rWXv6tioGdWtn6waPKmrYZhXce8XvHxAleyZ3uSc4OsqqINLrt78uY2rfU+j+L+pI5wSnd78u0w==","signatures":[{"sig":"MEUCIHWfkR83W9kofFq22mXt0xJ/sjit6JXJPza7RqnuFH2oAiEA6B2QLKj4H5EmTGYb/PJGPRanEoKOPg1Gqu8DsSe76qc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":78177},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"03a1f328ad5a40a8e329ad69454f661f66e1b514","scripts":{"build":"tsc -b"},"_npmUser":{"name":"11aimain","email":"quantum@11aiblockchain.com"},"deprecated":"Security: argsHash did not commit to the arguments for some inputs. See GHSA-48j6-rgwc-f6rf. Upgrade to 0.4.2 or later.","repository":{"url":"git+https://github.com/11-11AI/execution-governance.git","type":"git","directory":"packages/gate"},"_npmVersion":"10.9.2","description":"Pre-execution authorization for AI agent tool calls: allow or deny before execution, fail-closed, with a signed receipt for every decision.","directories":{},"_nodeVersion":"22.17.1","dependencies":{"yaml":"^2.4.0","@noble/hashes":"^1.4.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/execution-governance_0.1.0_1784435707712_0.9036646808504147","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@11ai/execution-governance","version":"0.1.1","keywords":["ai-agents","authorization","mcp","guardrails","security","policy","fail-closed","audit"],"license":"Apache-2.0","_id":"@11ai/execution-governance@0.1.1","maintainers":[{"name":"11aimain","email":"quantum@11aiblockchain.com"}],"homepage":"https://github.com/11-11AI/execution-governance#readme","bugs":{"url":"https://github.com/11-11AI/execution-governance/issues"},"bin":{"eg-verify":"dist/cli/eg-verify.js"},"dist":{"shasum":"c8ec985d9c3cc88bae148e33ab3e092a4911e41a","tarball":"https://registry.npmjs.org/@11ai/execution-governance/-/execution-governance-0.1.1.tgz","fileCount":44,"integrity":"sha512-m+J/Q5mgaPW7DIzzDARFWoCq8TvLTxUk92LBnenApDZadfITVWERW9v1a5fHawPej833GM3CUt+HrCRk3zgHuQ==","signatures":[{"sig":"MEUCIDexcHFAdEGv25dkg0rpOizmKHOp0zb9UT2RsoenA6B2AiEAiv1D+lARmhY2piwntJUfrlraU6E162kEThuR2L/aeP8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":78177},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"01c5e00d3a1910e4efdf607fe99349336ea6b8be","scripts":{"build":"tsc -b"},"_npmUser":{"name":"11aimain","email":"quantum@11aiblockchain.com"},"repository":{"url":"git+https://github.com/11-11AI/execution-governance.git","type":"git","directory":"packages/gate"},"_npmVersion":"10.9.2","description":"Pre-execution authorization for AI agent tool calls: allow or deny before execution, fail-closed, with a signed receipt for every decision.","directories":{},"_nodeVersion":"22.17.1","dependencies":{"yaml":"^2.4.0","@noble/hashes":"^1.4.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/execution-governance_0.1.1_1785710095778_0.04598763465971456","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Security: argsHash did not commit to the arguments for some inputs. See GHSA-48j6-rgwc-f6rf. Upgrade to 0.4.2 or later."},"0.1.2":{"name":"@11ai/execution-governance","version":"0.1.2","keywords":["ai-agents","authorization","mcp","guardrails","security","policy","fail-closed","audit","mcp-proxy","prompt-injection","agent-security","tool-calling","claude"],"license":"Apache-2.0","_id":"@11ai/execution-governance@0.1.2","maintainers":[{"name":"11aimain","email":"quantum@11aiblockchain.com"}],"homepage":"https://github.com/11-11AI/execution-governance#readme","bugs":{"url":"https://github.com/11-11AI/execution-governance/issues"},"bin":{"eg-verify":"dist/cli/eg-verify.js"},"dist":{"shasum":"fec09488aeff021692ae9f85bd3185c17dd35472","tarball":"https://registry.npmjs.org/@11ai/execution-governance/-/execution-governance-0.1.2.tgz","fileCount":44,"integrity":"sha512-JA+zaatg9M1B6sVC6caVlnQQ2Z6yNeGHgin3SNG9LSFNBFOs3TeBJTjsVkrottvWkgTQFvHrKYiOtFiX0IhVJQ==","signatures":[{"sig":"MEYCIQDnda3mTgPyj6eR/i/OP8jf5+cQ67ZTtn1wYwF7R4FkvQIhAKD3lX6VJvsvTKPBV6qO0Z7DiUt70/QPKsPGHfvX8MPh","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@11ai%2fexecution-governance@0.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":87889},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"b7580e3f41ee8e2c7e5111de1ae30a6d7a18124d","scripts":{"build":"tsc -b"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:4f2675fb-4c10-4e79-85fb-86b59be9f15a"}},"deprecated":"Security: argsHash did not commit to the arguments for some inputs. See GHSA-48j6-rgwc-f6rf. Upgrade to 0.4.2 or later.","repository":{"url":"git+https://github.com/11-11AI/execution-governance.git","type":"git","directory":"packages/gate"},"_npmVersion":"11.19.0","description":"Pre-execution authorization for AI agent tool calls: allow or deny before execution, fail-closed, with a signed receipt for every decision.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"yaml":"^2.4.0","@noble/hashes":"^1.4.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/execution-governance_0.1.2_1786269747568_0.2625069704279772","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@11ai/execution-governance","version":"0.2.0","keywords":["ai-agents","authorization","mcp","guardrails","security","policy","fail-closed","audit","mcp-proxy","prompt-injection","agent-security","tool-calling","claude"],"license":"Apache-2.0","_id":"@11ai/execution-governance@0.2.0","maintainers":[{"name":"11aimain","email":"quantum@11aiblockchain.com"}],"homepage":"https://github.com/11-11AI/execution-governance#readme","bugs":{"url":"https://github.com/11-11AI/execution-governance/issues"},"bin":{"eg-verify":"dist/cli/eg-verify.js"},"dist":{"shasum":"c3a7b9e69b442a6abe161a2a3bc2508af211cb7e","tarball":"https://registry.npmjs.org/@11ai/execution-governance/-/execution-governance-0.2.0.tgz","fileCount":48,"integrity":"sha512-e/FC9awUatkBHPzaWaByPrEebtTAhyaLTuf6icMYk1sLzHUVootQGO3fHVichNXEfOVGM5cg+z8JLk+HJh4sgA==","signatures":[{"sig":"MEUCIDPSRF45+BgUeftnfpKb32j5ahlJ4/l6D2TyyMmmCzOfAiEAhdeAwaT8pg5WkoXfD3sOx3hDqE4BAwVc9C0y0G6r/fU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@11ai%2fexecution-governance@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":103820},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"c1441567183b214955d723fbaeb6bcb30ce33a84","scripts":{"build":"tsc -b"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:4f2675fb-4c10-4e79-85fb-86b59be9f15a"}},"deprecated":"Security: argsHash did not commit to the arguments for some inputs. See GHSA-48j6-rgwc-f6rf. Upgrade to 0.4.2 or later.","repository":{"url":"git+https://github.com/11-11AI/execution-governance.git","type":"git","directory":"packages/gate"},"_npmVersion":"11.19.0","description":"Pre-execution authorization for AI agent tool calls: allow or deny before execution, fail-closed, with a signed receipt for every decision.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"yaml":"^2.4.0","@noble/hashes":"^1.4.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/execution-governance_0.2.0_1786307451180_0.3525649686453505","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@11ai/execution-governance","version":"0.2.1","keywords":["ai-agents","authorization","mcp","guardrails","security","policy","fail-closed","audit","mcp-proxy","prompt-injection","agent-security","tool-calling","claude"],"license":"Apache-2.0","_id":"@11ai/execution-governance@0.2.1","maintainers":[{"name":"11aimain","email":"quantum@11aiblockchain.com"}],"homepage":"https://github.com/11-11AI/execution-governance#readme","bugs":{"url":"https://github.com/11-11AI/execution-governance/issues"},"bin":{"eg-verify":"dist/cli/eg-verify.js"},"dist":{"shasum":"ee2853bcf3c69d5bb48223e7096924e5df5acec4","tarball":"https://registry.npmjs.org/@11ai/execution-governance/-/execution-governance-0.2.1.tgz","fileCount":49,"integrity":"sha512-san4tChoP7kG9kfruhqrOKCwCjL4IEnXQiQ/5uv/1NKZoas+oubJgOWj3+voU/k53WA4Z8Z4uGVy2xtBjQHj7g==","signatures":[{"sig":"MEYCIQCWGA/8Aoua3EyGvyremmHuOQ2ag+6AJ/uche7aD7H/0AIhAJX9zLDa1/adYyOn+U+A8FzBdSII/YXvcmgBgxGKUBCp","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@11ai%2fexecution-governance@0.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":108725},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"6073a8ffad336f3d7f2f393a544aea35e8e2b9d6","scripts":{"build":"tsc -b"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:4f2675fb-4c10-4e79-85fb-86b59be9f15a"}},"repository":{"url":"git+https://github.com/11-11AI/execution-governance.git","type":"git","directory":"packages/gate"},"_npmVersion":"11.19.0","description":"Pre-execution authorization for AI agent tool calls: allow or deny before execution, fail-closed, with a signed receipt for every decision.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"yaml":"^2.4.0","@noble/hashes":"^1.4.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/execution-governance_0.2.1_1787714361282_0.39074792585882","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Security: argsHash did not commit to the arguments for some inputs. See GHSA-48j6-rgwc-f6rf. Upgrade to 0.4.2 or later."},"0.3.0":{"name":"@11ai/execution-governance","version":"0.3.0","keywords":["ai-agents","authorization","mcp","guardrails","security","policy","fail-closed","audit","mcp-proxy","prompt-injection","agent-security","tool-calling","claude"],"license":"Apache-2.0","_id":"@11ai/execution-governance@0.3.0","maintainers":[{"name":"11aimain","email":"quantum@11aiblockchain.com"}],"homepage":"https://github.com/11-11AI/execution-governance#readme","bugs":{"url":"https://github.com/11-11AI/execution-governance/issues"},"bin":{"eg-demo":"dist/cli/eg-demo.js","eg-verify":"dist/cli/eg-verify.js"},"dist":{"shasum":"9402a1731a49234bb0dc4a498fff40695aa3d31b","tarball":"https://registry.npmjs.org/@11ai/execution-governance/-/execution-governance-0.3.0.tgz","fileCount":53,"integrity":"sha512-q72iU2SLRArMBi1DfK4Jp0d65tlwZBPucq3ScGpBo1fFkSiKUo5O922blqQuXX1IQAi4mY2qvYifEo3Gw8oGuw==","signatures":[{"sig":"MEQCIBUZBNMzHLOY4iDBAB1gcpc0eLx02w70UbP4l6RgKeRwAiB/vH4R2sRLpCXlAWrMipwqVg5lVJMl94p1RGeug8ACcA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIDGEFL0XaYy3YtgYKo6KxwkhgLaWf40QWV6xo5wIITHmAiBVdiXJjMN83LIGuFispasKuNRYU/4q32jpk9uFr1kU4w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":117206},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"32cdddbcaf881a3859a4a768149cdfacce0e2a4b","scripts":{"build":"tsc -b"},"_npmUser":{"name":"11aimain","email":"quantum@11aiblockchain.com"},"repository":{"url":"git+https://github.com/11-11AI/execution-governance.git","type":"git","directory":"packages/gate"},"_npmVersion":"10.9.2","description":"Pre-execution authorization for AI agent tool calls: allow or deny before execution, fail-closed, with a signed receipt for every decision.","directories":{},"_nodeVersion":"22.17.1","dependencies":{"yaml":"^2.4.0","@noble/hashes":"^1.4.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/execution-governance_0.3.0_1789493920042_0.1863047768995747","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Security: argsHash did not commit to the arguments for some inputs. See GHSA-48j6-rgwc-f6rf. Upgrade to 0.4.2 or later."},"0.4.0":{"name":"@11ai/execution-governance","version":"0.4.0","keywords":["ai-agents","authorization","mcp","guardrails","security","policy","fail-closed","audit","mcp-proxy","prompt-injection","agent-security","tool-calling","claude"],"license":"Apache-2.0","_id":"@11ai/execution-governance@0.4.0","maintainers":[{"name":"11aimain","email":"quantum@11aiblockchain.com"}],"homepage":"https://github.com/11-11AI/execution-governance#readme","bugs":{"url":"https://github.com/11-11AI/execution-governance/issues"},"bin":{"eg-demo":"dist/cli/eg-demo.js","eg-verify":"dist/cli/eg-verify.js","eg-conform":"dist/cli/eg-conform.js"},"dist":{"shasum":"f25c7dfc0f5691ee8bdc5aa62813fb17f440247e","tarball":"https://registry.npmjs.org/@11ai/execution-governance/-/execution-governance-0.4.0.tgz","fileCount":65,"integrity":"sha512-51y9Xek9hbGfDzhjyrDfuy4Cq/kZm/FzEyzboEUShBCPNH04uwTxZF0QvIi4jLTOU2Y/hys2YISB2r74VfVgcw==","signatures":[{"sig":"MEYCIQCnmRWp0Wkviv/dIfVgaEdOWOLvwSQi6KJ/0x0X78Y8iQIhAKK/Mj0/CVudOWLPQi5ajDpzvKZIBq2oGcj8D2av4WME","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIFGFs2WUHb2+L0bcxhx8Am70dWh+ZrLx/uFxpEu0uf44AiEAny45QwCdFQ1fBue4wuRrkGBogqeJDFtoRlJHocaIonQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":170893},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"50df412845dd5a13e6c0ec62bfe13fff8e98e615","scripts":{"build":"tsc -b"},"_npmUser":{"name":"11aimain","email":"quantum@11aiblockchain.com"},"deprecated":"Security: argsHash did not commit to the arguments for some inputs. See GHSA-48j6-rgwc-f6rf. Upgrade to 0.4.2 or later.","repository":{"url":"git+https://github.com/11-11AI/execution-governance.git","type":"git","directory":"packages/gate"},"_npmVersion":"10.9.2","description":"Pre-execution authorization for AI agent tool calls: allow or deny before execution, fail-closed, with a signed receipt for every decision.","directories":{},"_nodeVersion":"22.17.1","dependencies":{"yaml":"^2.4.0","@noble/hashes":"^1.4.0","@11ai/execution-governance":"^0.3.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/execution-governance_0.4.0_1789602471742_0.5558231044873241","host":"s3://npm-registry-packages-npm-production"}},"0.4.1":{"name":"@11ai/execution-governance","version":"0.4.1","keywords":["ai-agents","authorization","mcp","guardrails","security","policy","fail-closed","audit","mcp-proxy","prompt-injection","agent-security","tool-calling","claude"],"license":"Apache-2.0","_id":"@11ai/execution-governance@0.4.1","maintainers":[{"name":"11aimain","email":"quantum@11aiblockchain.com"}],"homepage":"https://github.com/11-11AI/execution-governance#readme","bugs":{"url":"https://github.com/11-11AI/execution-governance/issues"},"bin":{"eg-demo":"dist/cli/eg-demo.js","eg-verify":"dist/cli/eg-verify.js","eg-conform":"dist/cli/eg-conform.js"},"dist":{"shasum":"fb10eb5756e32d589599eedbf20fb466773a2f45","tarball":"https://registry.npmjs.org/@11ai/execution-governance/-/execution-governance-0.4.1.tgz","fileCount":65,"integrity":"sha512-Z5WbsfdN0zDdkfuRYCIWbEEWYW5fFSfC68pl+tVraP51Cg7HXnP3GAEBrQa2r/wrtEMoZAI3uQBloMrfDBTIxQ==","signatures":[{"sig":"MEUCIC+MbqKa/jNR7Om+QTxkyRjNUFwsE2XtGjQQnIm7pGZMAiEAhjmWQW5oEUMf48cu7Sz4JzmGKYvJQ1HrBYEBEfJaoRo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQC4CBs7DODS0MjM7XFBsKJD3G2nXWHmy41K7n4dyQlbzwIgPr7FPt22s+sz9v9CZOX6eY1nlBJpSKP2aKCmOhwJQTk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":173409},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"91dd4e159c1db8304576975ab6a47e93cb8c5e6c","scripts":{"build":"tsc -b"},"_npmUser":{"name":"11aimain","email":"quantum@11aiblockchain.com"},"repository":{"url":"git+https://github.com/11-11AI/execution-governance.git","type":"git","directory":"packages/gate"},"_npmVersion":"10.9.2","description":"Pre-execution authorization for AI agent tool calls: allow or deny before execution, fail-closed, with a signed receipt for every decision.","directories":{},"_nodeVersion":"22.17.1","dependencies":{"yaml":"^2.4.0","@noble/hashes":"^1.4.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/execution-governance_0.4.1_1789603359037_0.2741124160076669","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Security: argsHash did not commit to the arguments for some inputs. See GHSA-48j6-rgwc-f6rf. Upgrade to 0.4.2 or later."},"0.4.2":{"name":"@11ai/execution-governance","version":"0.4.2","keywords":["ai-agents","authorization","mcp","guardrails","security","policy","fail-closed","audit","mcp-proxy","prompt-injection","agent-security","tool-calling","claude"],"license":"Apache-2.0","_id":"@11ai/execution-governance@0.4.2","maintainers":[{"name":"11aimain","email":"quantum@11aiblockchain.com"}],"homepage":"https://github.com/11-11AI/execution-governance#readme","bugs":{"url":"https://github.com/11-11AI/execution-governance/issues"},"bin":{"eg-demo":"dist/cli/eg-demo.js","eg-verify":"dist/cli/eg-verify.js","eg-conform":"dist/cli/eg-conform.js"},"dist":{"shasum":"69786d118e78099c40eb8303a2c8b42695841b4b","tarball":"https://registry.npmjs.org/@11ai/execution-governance/-/execution-governance-0.4.2.tgz","fileCount":65,"integrity":"sha512-p+lKwUiW8oGdr/tEY5GwFNGFmJPOGrQ7iO/Q9XJdW/mL8Yx92xo4zCv5Tr3NDiIP99qiT2zMU1Gf8ASE5raIBQ==","signatures":[{"sig":"MEYCIQCx4ga390tMawgd9bHiLo5EvHUspADl3cwx7ASkhFLmXwIhAKYj2Npp/LUsQmKJkh/A/krYZM+lvfVAJTZ82DZKMR8F","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQDe/9Q9Kfxd+9AxD/C0tF0KTzZGAFWLHfd0c54kMCC75AIgLx2gnvF3HRvocH4HF/W21utiAH6UYOHpjysYQALeUS0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@11ai%2fexecution-governance@0.4.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":177368},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"f2efb313d113149c6ddc9656307a605a7619f8ea","scripts":{"build":"tsc -b"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:4f2675fb-4c10-4e79-85fb-86b59be9f15a"}},"repository":{"url":"git+https://github.com/11-11AI/execution-governance.git","type":"git","directory":"packages/gate"},"_npmVersion":"11.19.1","description":"Pre-execution authorization for AI agent tool calls: allow or deny before execution, fail-closed, with a signed receipt for every decision.","directories":{},"_nodeVersion":"24.20.0","dependencies":{"yaml":"^2.4.0","@noble/hashes":"^1.4.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/execution-governance_0.4.2_1789671070445_0.16374593170958351","host":"s3://npm-registry-packages-npm-production"}}},"time":{"created":"2026-07-19T04:35:07.551Z","modified":"2026-09-17T19:11:42.723Z","0.1.0":"2026-07-19T04:35:07.843Z","0.1.1":"2026-08-02T22:34:55.910Z","0.1.2":"2026-08-09T10:02:27.743Z","0.2.0":"2026-08-09T20:30:51.310Z","0.2.1":"2026-08-26T03:19:21.439Z","0.3.0":"2026-09-15T17:38:40.142Z","0.4.0":"2026-09-16T23:47:51.840Z","0.4.1":"2026-09-17T00:02:39.145Z","0.4.2":"2026-09-17T18:51:10.517Z"},"bugs":{"url":"https://github.com/11-11AI/execution-governance/issues"},"license":"Apache-2.0","homepage":"https://github.com/11-11AI/execution-governance#readme","keywords":["ai-agents","authorization","mcp","guardrails","security","policy","fail-closed","audit","mcp-proxy","prompt-injection","agent-security","tool-calling","claude"],"repository":{"url":"git+https://github.com/11-11AI/execution-governance.git","type":"git","directory":"packages/gate"},"description":"Pre-execution authorization for AI agent tool calls: allow or deny before execution, fail-closed, with a signed receipt for every decision.","maintainers":[{"name":"11aimain","email":"quantum@11aiblockchain.com"}],"readme":"<p align=\"center\">\n  <img src=\"https://11aiblockchain.com/npm-banner.png\" alt=\"11/11 AI — Execution Governance\" width=\"480\" />\n</p>\n\n# @11ai/execution-governance\n\n[![npm version](https://img.shields.io/npm/v/@11ai/execution-governance.svg)](https://www.npmjs.com/package/@11ai/execution-governance)\n[![npm downloads](https://img.shields.io/npm/dm/@11ai/execution-governance.svg)](https://www.npmjs.com/package/@11ai/execution-governance)\n[![CI](https://github.com/11-11AI/execution-governance/actions/workflows/ci.yml/badge.svg)](https://github.com/11-11AI/execution-governance/actions/workflows/ci.yml)\n[![License: Apache-2.0](https://img.shields.io/badge/license-Apache--2.0-blue.svg)](https://github.com/11-11AI/execution-governance/blob/main/LICENSE)\n[![TypeScript](https://img.shields.io/badge/types-included-blue.svg)](https://www.npmjs.com/package/@11ai/execution-governance)\n\n**Stop an AI agent's tool call _before_ it runs — not after.**\n\nEvery tool call is checked against your policy. Allow or deny, decided\nbefore execution, fail-closed by default. Every decision leaves an\nEd25519-signed, hash-chained receipt anyone can verify offline.\n\n```\nRequest → Verify → Allow / Deny → Execute → Signed receipt\n```\n\nNo API key. No network. No telemetry. Runs entirely on your machine.\n\n## 30-second start\n\n```bash\nnpm install @11ai/execution-governance\ncurl -sLO https://raw.githubusercontent.com/11-11AI/execution-governance/main/examples/quickstart/quickstart.mjs\ncurl -sLO https://raw.githubusercontent.com/11-11AI/execution-governance/main/examples/quickstart/eg-policy.yaml\nnode quickstart.mjs --key ./eg-signing.key --receipts ./eg-receipts.jsonl\n```\n\nWith the starter policy, a secret-bearing outbound POST is **denied before\n`fetch` ever runs**, a signed receipt is appended, and the run prints the exact\ncommand that checks it:\n\n```\ncreated signing key ./eg-signing.key (private: keep it out of version control)\ndenied: exfiltration: outbound call carrying secret material\nreceipt: 01a03bd6-f736-785b-a82d-62363da0273e\n\nverify it yourself:\n  npx eg-verify --receipts ./eg-receipts.jsonl --pubkey huCJiiZMYF0Ye7R6099agDYtV8TLOhmqCnv8LewTb7A\n```\n\nRun that command and you get `RESULT: VERIFIED`. The public key is yours, so it\nwill not be the one above.\n\n`--key` is the part that matters. Without a stable signing key the SDK generates\none per run, warns, and throws it away: the receipts still look fine and can\nnever be verified again, including by you a minute later.\n\nThat is the whole API:\n\n```ts\nimport { createGate } from \"@11ai/execution-governance\";\n\nconst gate = createGate({ policy: \"./eg-policy.yaml\", signingKey });\n\nconst result = await gate.govern({ sessionId: \"s1\", tool: \"http.post\", args: { url, body } }, () =>\n  fetch(url, { method: \"POST\", body }),\n);\n```\n\n`govern` runs the callback only on allow, and throws `DeniedError` on deny.\n`signingKey` is a 32-byte Ed25519 seed;\n[`examples/quickstart`](https://github.com/11-11AI/execution-governance/tree/main/examples/quickstart)\nis the file the commands above download, and shows how it is created and reused.\n\n## Try the attack demo (no keys, no network)\n\n```bash\ngit clone https://github.com/11-11AI/execution-governance\ncd execution-governance && npm install && npm run demo\n```\n\nAn agent reads a briefing carrying a prompt injection telling it to\nexfiltrate `.env`. The agent obeys. The gate denies the exfiltration\n**before it executes**, then prints a verified receipt chain proving\nexactly what was attempted and why it was stopped. Real output:\n\n```\n2. agent attempts http_post to attacker.example with .env contents\n   decision: DENY\n   reason: exfiltration: outbound POST carrying secret material\n   the http_post never ran. Nothing left the machine.\n\nreceipt chain verified: yes, 2 allows, 1 deny\n```\n\n## Why pre-execution?\n\nMost agent safety tooling is observability: it tells you what your agent\ndid after the damage is done. Logs are not authorization. This gate\nreverses the order — the action is evaluated first, and without an allow\ndecision it never runs.\n\n|                             | Logging / monitoring     | Execution Governance           |\n| --------------------------- | ------------------------ | ------------------------------ |\n| When it acts                | After execution          | **Before execution**           |\n| On failure                  | Fails open (action runs) | **Fails closed (deny)**        |\n| Output                      | Mutable logs             | **Signed, chained receipts**   |\n| Verifiable by a third party | No                       | **Yes, offline, no key to us** |\n\n## A receipt\n\n```json\n{\n  \"receiptId\": \"019f7833-fddc-7a2b-8070-fa732536e98b\",\n  \"ts\": \"2026-07-19T02:30:00.000Z\",\n  \"sessionId\": \"s1\",\n  \"tool\": \"http.post\",\n  \"argsHash\": \"…\",\n  \"decision\": \"deny\",\n  \"reason\": \"exfiltration: outbound call carrying secret material\",\n  \"policyVersion\": \"starter-1\",\n  \"prevReceiptHash\": \"genesis\",\n  \"kid\": \"4a45b7f302b1db21\",\n  \"sig\": \"…\"\n}\n```\n\nCanonical JSON, SHA3-512 hashed, Ed25519 signed, chained to the previous\nreceipt. `agentId` and `parentReceiptId` are optional and appear when\nsupplied. Verify any receipt file with no access to the system that\nproduced it:\n\n```bash\neg-verify --receipts eg-receipts.jsonl --pubkey <base64url public key>\n```\n\n`--pubkey` may also come from the `EG_PUBLIC_KEY` environment variable. The\npublic key is `gate.publicKey()` for the gate that signed the file; the\nquickstart above prints the whole command with the key already filled in.\n\n## Gate any MCP server with one line\n\nUse [`@11ai/mcp-gate`](https://www.npmjs.com/package/@11ai/mcp-gate) to\nwrap an existing MCP server in your client config — Claude Desktop, Claude\nCode, or any MCP client:\n\n```json\n{\n  \"command\": \"npx\",\n  \"args\": [\"-y\", \"@11ai/mcp-gate\", \"--policy\", \"eg-policy.yaml\", \"--\", \"node\", \"their-server.js\"]\n}\n```\n\nDenied calls are answered with a JSON-RPC error and never reach the server.\n\n## Fail-closed, measured\n\nAny error, timeout, or missing decision results in **deny**. The decision\ntimeout defaults to 2000 ms and a timeout is a deny. If a receipt cannot be\npersisted, the call throws rather than executing — proof that cannot be\nrecorded is not a permitted action. There is no fail-open path.\n\nChecked in CI on every commit: absorption, monotone evidence growth,\nnon-commutativity. **26 of 26 adversarial vectors denied** under the starter\npolicy — run it yourself:\n\n```bash\nnpx vitest run tests/vectors\n```\n\n## API surface\n\n| Export                                                                                | Purpose                                                                                              |\n| ------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- |\n| `createGate(options)`                                                                 | Construct a gate from a policy file path or a `PolicyEngine`.                                        |\n| `gate.govern(request, fn)`                                                            | Evaluate, then run `fn` only on allow. Throws `DeniedError` on deny.                                 |\n| `gate.authorize(request)`                                                             | Decision only, no execution — for your own dispatcher. Returns a `Decision` with its signed receipt. |\n| `gate.verifyReceipts(path)`                                                           | Verify a receipt file with this gate's key. Returns a `VerifyReport`.                                |\n| `gate.publicKey()`                                                                    | This gate's public key, base64url.                                                                   |\n| `verifyReceiptFile(path, publicKey)`                                                  | Standalone chain verification against any public key.                                                |\n| `LocalPolicyEngine`, `RemotePolicyEngine`                                             | The built-in engines, if you construct one directly.                                                 |\n| `generateSigningKey`, `publicKeyBytes`, `fingerprint`, `toB64u`, `fromB64u`           | Key helpers.                                                                                         |\n| `jcs`                                                                                 | The canonical-JSON serialiser the receipt hash is computed over.                                     |\n| `eg-verify` (CLI)                                                                     | Offline verification of any receipt file. No key to us, no network.                                  |\n| `Receipt`, `Decision`, `VerifyReport`, `GateOptions`, `ActionRequest`, `PolicyEngine` | TypeScript types for the receipt format and policy interface.                                        |\n\n`GateOptions` accepts `policy`, and optionally `signingKey` (32-byte Ed25519\nseed — without it an ephemeral key is generated and a warning printed),\n`receiptSink`, and `decisionTimeoutMs`.\n\n## Errors — fail-closed by type\n\n`DeniedError` is the only error class this package exports. Engine errors and\ntimeouts are converted into **deny decisions**, so they arrive as a\n`DeniedError` rather than as a distinct type — the failure mode and the policy\ndecision are deliberately indistinguishable to the caller, because both mean\nthe same thing: nothing ran.\n\n```ts\nimport { createGate, DeniedError } from \"@11ai/execution-governance\";\n\n// A malformed policy throws a plain Error here, at construction, before any\n// request can be evaluated. Nothing can execute against a policy that did not\n// parse.\nconst gate = createGate({ policy: \"./eg-policy.yaml\" });\n\ntry {\n  await gate.govern(req, exec);\n} catch (err) {\n  if (err instanceof DeniedError) {\n    // Denied. err.decision holds the signed Decision, and\n    // err.decision.receipt is the signed denial receipt.\n    console.error(err.decision.reason, err.decision.receipt.receiptId);\n  } else {\n    // Receipt persistence failure. Fail-closed: the action did not run.\n    throw err;\n  }\n}\n```\n\nA denied call **absorbs**: dependent downstream calls in the chain are\ndenied without re-evaluation.\n\n## Versioning\n\nSemver. The receipt wire format is versioned independently\n(`policyVersion`, receipt schema) — receipts written today remain\nverifiable by future verifiers. Breaking wire changes bump the major.\n\n## The @11ai packages\n\n| Package                                                                                  | What it is                                                                 |\n| ---------------------------------------------------------------------------------------- | -------------------------------------------------------------------------- |\n| [`@11ai/execution-governance`](https://www.npmjs.com/package/@11ai/execution-governance) | SDK: gate any function call. This package.                                 |\n| [`@11ai/mcp-gate`](https://www.npmjs.com/package/@11ai/mcp-gate)                         | Fail-closed MCP proxy — gate any MCP server with one line of config.       |\n| `@11ai/identity-oidc` _(coming)_                                                         | Bind OIDC-verified principals (Okta, Entra ID, Keycloak) to every receipt. |\n| `execution-governance` on PyPI _(coming)_                                                | Python SDK, same receipt format, cross-verifiable with this package.       |\n\n## FAQ\n\n**Is this actually open source?** Yes — Apache-2.0, including the local\npolicy engine, the MCP proxy, the receipt format, and the verifier. Use it\ncommercially, no strings.\n\n**What's the catch?** None for local use. A hosted control plane\n([control.11aiblockchain.com](https://control.11aiblockchain.com/demo))\nadds multi-tenant policy management, post-quantum-signed evidence, and a\npublic proof ledger for teams that need it. The npm packages work fully\nwithout it.\n\n**Does it phone home?** No. No telemetry, no network calls, no account.\n\n## Docs & links\n\n- [Receipt format & verification](https://github.com/11-11AI/execution-governance/blob/main/docs/RECEIPTS.md)\n- [Policy schema & starter policy](https://github.com/11-11AI/execution-governance/blob/main/docs/POLICY.md)\n- [Examples](https://github.com/11-11AI/execution-governance/tree/main/examples)\n- [Research corpus (Zenodo)](https://zenodo.org/communities/11-11-ai/records) · [Category paper (DOI)](https://doi.org/10.5281/zenodo.20453136)\n- [Live public proof endpoint](https://control.11aiblockchain.com/v1/public/evidence) — one `curl`, no auth, real signed decision\n\n## License\n\nApache-2.0. See [LICENSE](https://github.com/11-11AI/execution-governance/blob/main/LICENSE)\nand [NOTICE](https://github.com/11-11AI/execution-governance/blob/main/NOTICE).\n[LICENSING.md](https://github.com/11-11AI/execution-governance/blob/main/LICENSING.md)\nsets out, per component, what is open permanently and what is commercial: every\npart needed to verify a receipt is Apache-2.0 and stays that way.\nProvided as-is; you are responsible for your policy, deployment, and keys.\n","readmeFilename":"README.md"}