{"_id":"@agentwares/agentguard-core","_rev":"4-d2c4ccaab0820502aa5cc7ce5123d38b","name":"@agentwares/agentguard-core","dist-tags":{"latest":"0.1.3"},"versions":{"0.1.0":{"name":"@agentwares/agentguard-core","version":"0.1.0","keywords":["agentguard","mcp","ai-agents","spend-limit","kill-switch","policy","audit-log","dry-run"],"license":"MIT","_id":"@agentwares/agentguard-core@0.1.0","maintainers":[{"name":"umerbukhari","email":"umer.bukhari@gmail.com"}],"homepage":"https://github.com/agentwares/agentwares#readme","bugs":{"url":"https://github.com/agentwares/agentwares/issues"},"dist":{"shasum":"7e4f31fea19afa6afe842dbd799e3b280927876b","tarball":"https://registry.npmjs.org/@agentwares/agentguard-core/-/agentguard-core-0.1.0.tgz","fileCount":11,"integrity":"sha512-pzJFC2T4xxalewRmBqqF/3AI6V9NMswqBQGiL8nX2Ad1tOSYfpL4TvGIZ+niRQ6D9GpZOZgH1GN16Iyj2wW0mg==","signatures":[{"sig":"MEQCIDKvb8g4STm17Ctnsh0XMEOc3Qa26KQT6geXsfPTdEBDAiAO0A/wfmJOHMHQL0DPwRKbf8JUUGi+73D8cmW48VVZtQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":345331},"main":"./dist/index.js","type":"module","_from":"file:agentwares-agentguard-core-0.1.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./node":{"types":"./dist/node/index.d.ts","import":"./dist/node/index.js"}},"scripts":{"lint":"eslint src","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"umerbukhari","email":"umer.bukhari@gmail.com"},"_resolved":"/private/var/folders/2p/2j2wcvfs4wz6v0nfr4h455k40000gn/T/35e67b1cfe2328dc13039a258805a22e/agentwares-agentguard-core-0.1.0.tgz","_integrity":"sha512-pzJFC2T4xxalewRmBqqF/3AI6V9NMswqBQGiL8nX2Ad1tOSYfpL4TvGIZ+niRQ6D9GpZOZgH1GN16Iyj2wW0mg==","repository":{"url":"git+https://github.com/agentwares/agentwares.git","type":"git","directory":"packages/agentguard-core"},"_npmVersion":"10.9.8","description":"Policy engine behind agentguard: spend caps, destructive-action gating with approvals, kill switch, scoped agent keys, dry-run writes, semantic loop breaker, blast-radius caps and a hash-chained audit log. Web-standard core, Node stores under ./node.","directories":{},"sideEffects":false,"_nodeVersion":"22.23.2","dependencies":{"zod":"^4.5.4","yaml":"^2.9.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agentguard-core_0.1.0_1788482997105_0.1177071952676092","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@agentwares/agentguard-core","version":"0.1.1","keywords":["agentguard","mcp","ai-agents","spend-limit","kill-switch","policy","audit-log","dry-run"],"license":"MIT","_id":"@agentwares/agentguard-core@0.1.1","maintainers":[{"name":"umerbukhari","email":"umer.bukhari@gmail.com"}],"homepage":"https://github.com/agentwares/agentguard/tree/main/packages/agentguard-core#readme","bugs":{"url":"https://github.com/agentwares/agentguard/issues"},"dist":{"shasum":"84c3d3602d054a36842537faecd9a4c8e9f292d3","tarball":"https://registry.npmjs.org/@agentwares/agentguard-core/-/agentguard-core-0.1.1.tgz","fileCount":11,"integrity":"sha512-GFEWya+7NNbcyemiUfZTSuofX8D6Sm49y0fQH+R+I+9Z9JadMUCs4YMT00WRDfSkFpYgHfB//vPqs5KUnyuunw==","signatures":[{"sig":"MEUCIDA5R6+CWRPUZvnT26ZlBcwMT0eLlg7sEL465hq5ojiyAiEA/TzTZMryGVgFlO8PizwOQeOkbdYdnehYwivZAMlcPJI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":345481},"main":"./dist/index.js","type":"module","_from":"file:agentwares-agentguard-core-0.1.1.tgz","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./node":{"types":"./dist/node/index.d.ts","import":"./dist/node/index.js"}},"scripts":{"lint":"eslint src","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"umerbukhari","email":"umer.bukhari@gmail.com"},"_resolved":"/private/var/folders/2p/2j2wcvfs4wz6v0nfr4h455k40000gn/T/c07960b0b24c9d370f6c03548d439b61/agentwares-agentguard-core-0.1.1.tgz","_integrity":"sha512-GFEWya+7NNbcyemiUfZTSuofX8D6Sm49y0fQH+R+I+9Z9JadMUCs4YMT00WRDfSkFpYgHfB//vPqs5KUnyuunw==","repository":{"url":"git+https://github.com/agentwares/agentguard.git","type":"git","directory":"packages/agentguard-core"},"_npmVersion":"10.9.8","description":"Policy engine behind agentguard: spend caps, destructive-action gating with approvals, kill switch, scoped agent keys, dry-run writes, semantic loop breaker, blast-radius caps and a hash-chained audit log. Web-standard core, Node stores under ./node.","directories":{},"sideEffects":false,"_nodeVersion":"22.23.2","dependencies":{"zod":"^4.5.4","yaml":"^2.9.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agentguard-core_0.1.1_1788806948834_0.1578480883615032","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@agentwares/agentguard-core","version":"0.1.2","keywords":["agentguard","mcp","ai-agents","spend-limit","kill-switch","policy","audit-log","dry-run"],"license":"MIT","_id":"@agentwares/agentguard-core@0.1.2","maintainers":[{"name":"umerbukhari","email":"umer.bukhari@gmail.com"}],"homepage":"https://github.com/agentwares/agentguard/tree/main/packages/agentguard-core#readme","bugs":{"url":"https://github.com/agentwares/agentguard/issues"},"dist":{"shasum":"85f6e7135cb4805354fc5421fb27fd3347fb2fc5","tarball":"https://registry.npmjs.org/@agentwares/agentguard-core/-/agentguard-core-0.1.2.tgz","fileCount":11,"integrity":"sha512-fLilsLKy/hX4nKlLIdl8fj95e4kd44rT9EFqVGOpOc6gNid53eZ7Yihdk6Elt2aPmEiWEB7M1Av0Gttf85n0nA==","signatures":[{"sig":"MEYCIQDanvNtKPsqBk6sGLqQ8FBK9sCChvotstQ2mBJXG8LluwIhAOxICyJ//i8jZVIOv/iVAjp+5XiGO450CN7Sr4Peod/g","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":345597},"main":"./dist/index.js","type":"module","_from":"file:agentwares-agentguard-core-0.1.2.tgz","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./node":{"types":"./dist/node/index.d.ts","import":"./dist/node/index.js"}},"scripts":{"lint":"eslint src","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"umerbukhari","email":"umer.bukhari@gmail.com"},"_resolved":"/private/var/folders/2p/2j2wcvfs4wz6v0nfr4h455k40000gn/T/f9016ccf443cd0f6bdef53fec163f0e6/agentwares-agentguard-core-0.1.2.tgz","_integrity":"sha512-fLilsLKy/hX4nKlLIdl8fj95e4kd44rT9EFqVGOpOc6gNid53eZ7Yihdk6Elt2aPmEiWEB7M1Av0Gttf85n0nA==","repository":{"url":"git+https://github.com/agentwares/agentguard.git","type":"git","directory":"packages/agentguard-core"},"_npmVersion":"10.9.8","description":"Policy engine behind agentguard: spend caps, destructive-action gating with approvals, kill switch, scoped agent keys, dry-run writes, semantic loop breaker, blast-radius caps and a hash-chained audit log. Web-standard core, Node stores under ./node.","directories":{},"sideEffects":false,"_nodeVersion":"22.23.2","dependencies":{"zod":"^4.5.4","yaml":"^2.9.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agentguard-core_0.1.2_1788807204656_0.3986389377613968","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@agentwares/agentguard-core","version":"0.1.3","description":"Policy engine behind agentguard: spend caps, destructive-action gating with approvals, kill switch, scoped agent keys, dry-run writes, semantic loop breaker, blast-radius caps and a hash-chained audit log. Web-standard core, Node stores under ./node.","license":"MIT","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./node":{"types":"./dist/node/index.d.ts","import":"./dist/node/index.js"}},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+https://github.com/agentwares/agentguard.git","directory":"packages/agentguard-core"},"keywords":["agentguard","mcp","ai-agents","spend-limit","kill-switch","policy","audit-log","dry-run"],"sideEffects":false,"engines":{"node":">=20"},"dependencies":{"yaml":"^2.9.0","zod":"^4.5.4"},"homepage":"https://github.com/agentwares/agentguard#readme","bugs":{"url":"https://github.com/agentwares/agentguard/issues"},"scripts":{"build":"tsup","typecheck":"tsc --noEmit","lint":"eslint src","test":"vitest run"},"_id":"@agentwares/agentguard-core@0.1.3","_integrity":"sha512-W+OVGROgdPvQZNN11Jl31TZwxawn4IAT93coVm+GbHDHurc3YPP8JQwMPYMsofAeEdL0m5SA3nrw1CbMgmb+iA==","_resolved":"/private/var/folders/2p/2j2wcvfs4wz6v0nfr4h455k40000gn/T/2be8e28cf35ead00d3e51575eb065bdd/agentwares-agentguard-core-0.1.3.tgz","_from":"file:agentwares-agentguard-core-0.1.3.tgz","_nodeVersion":"22.23.2","_npmVersion":"10.9.8","dist":{"integrity":"sha512-W+OVGROgdPvQZNN11Jl31TZwxawn4IAT93coVm+GbHDHurc3YPP8JQwMPYMsofAeEdL0m5SA3nrw1CbMgmb+iA==","shasum":"f3f331ae4e2688006c28531ee3d034ef547e6b6a","tarball":"https://registry.npmjs.org/@agentwares/agentguard-core/-/agentguard-core-0.1.3.tgz","fileCount":12,"unpackedSize":352592,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDJwCNdw+ZxCDOqmOrb/7g7PHqgwFbwDY1FUQhI5v+TVgIhAOrK9L5vurNzWRE0XwoC9A0l5nvkt0f5yT4F9oS/C2u8"}]},"_npmUser":{"name":"umerbukhari","email":"umer.bukhari@gmail.com"},"directories":{},"maintainers":[{"name":"umerbukhari","email":"umer.bukhari@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/agentguard-core_0.1.3_1788820514293_0.7231787762162221"},"_hasShrinkwrap":false}},"time":{"created":"2026-09-04T00:49:56.923Z","modified":"2026-09-07T22:35:14.624Z","0.1.0":"2026-09-04T00:49:57.271Z","0.1.1":"2026-09-07T18:49:09.001Z","0.1.2":"2026-09-07T18:53:24.820Z","0.1.3":"2026-09-07T22:35:14.470Z"},"bugs":{"url":"https://github.com/agentwares/agentguard/issues"},"license":"MIT","homepage":"https://github.com/agentwares/agentguard#readme","keywords":["agentguard","mcp","ai-agents","spend-limit","kill-switch","policy","audit-log","dry-run"],"repository":{"type":"git","url":"git+https://github.com/agentwares/agentguard.git","directory":"packages/agentguard-core"},"description":"Policy engine behind agentguard: spend caps, destructive-action gating with approvals, kill switch, scoped agent keys, dry-run writes, semantic loop breaker, blast-radius caps and a hash-chained audit log. Web-standard core, Node stores under ./node.","maintainers":[{"name":"umerbukhari","email":"umer.bukhari@gmail.com"}],"readme":"# @agentwares/agentguard-core\n\nThe policy engine behind [`agentguard`](https://github.com/agentwares/agentguard/tree/main/apps/agentguard-cli#readme) (MCP proxy) and [`@agentwares/agentguard-sdk`](https://github.com/agentwares/agentguard/tree/main/packages/agentguard-sdk#readme) (middleware). Web-standard (`crypto.subtle`, no `fs`) so the same engine runs on Node, Workers and the hosted tier; Node file stores live under `@agentwares/agentguard-core/node`.\n\n```ts\nimport { Guard, loadPolicyFromYaml } from \"@agentwares/agentguard-core\";\n\nconst guard = new Guard({ policy: loadPolicyFromYaml(yamlText, { env: process.env }) });\nconst result = await guard.run(\n  {\n    tool: { name: \"crm_delete_contact\", annotations: { destructiveHint: true } },\n    args: { id: \"c_1\" },\n    runId: \"run_1\",\n  },\n  async (args) => upstream.call(args), // only runs when the policy allows\n);\n// result: { ok, value | error: { code, cause, fix, retryable }, outcome: ok|error|blocked|faked|halted|pending, faked, entry }\n```\n\n`Guard.run` applies, in order: kill switch → agent scope (allow/deny/upstreams) → classification (policy patterns → MCP annotations → verb heuristics; `unknown` is a write in enforce) → approvals (`APPROVAL_REQUIRED` bound to tool + args hash, consumed once) → semantic loop breaker (normalized args; repeats and A→B→A→B cycles) → per-run / per-day caps (counts and dollars) → dry-run synthesis from `outputSchema` or execute → spend accounting from results → hash-chained audit entry → `onEvent` for alerts.\n\nModules: `policy` (zod schema, `${ENV}` substitution, defaults), `classify`, `loop`, `caps`, `spend` (argument rules, result fields, LLM list prices), `dryrun`, `audit` (`ChainWriter`, `verifyChain`), `kill`, `approvals`, `scope` (agent keys), `report` (`buildReport`, `renderReportMarkdown`, `renderMutationDiff`), `permission-diff` (`agentguard.yaml`, `.claude/settings.json`, `mcp.json`). Stores are interfaces (`StateStore`, `AuditSink`, `KillSwitch`, `ApprovalStore`) with memory implementations here and file implementations in `./node` (`FileStateStore`, `FileAuditSink`, `FileKillSwitch`, `FileApprovalStore`, `loadPolicyFile`, `verifyAuditFile`).\n\nAudit entries: `{ seq, ts, run_id, agent?, upstream?, tool, class, verb, mode, outcome, error?, args_hash, args (redacted), result_hash?, mutation?, usd?, counters?, latency_ms?, reason, prev_hash, hash }` with `hash = sha256(prev_hash + canonical(entry))`.\n","readmeFilename":"README.md"}