{"_id":"@aroha-sdk/policy","_rev":"5-0ed7a4a4089027101ca0bf0f1ce43a52","name":"@aroha-sdk/policy","dist-tags":{"latest":"1.3.0"},"versions":{"1.0.0":{"name":"@aroha-sdk/policy","version":"1.0.0","_id":"@aroha-sdk/policy@1.0.0","maintainers":[{"name":"aroha-labs","email":"projectmed99@gmail.com"}],"dist":{"shasum":"6c93a0a37978afe53bd5f6ca108ccc391ed27165","tarball":"https://registry.npmjs.org/@aroha-sdk/policy/-/policy-1.0.0.tgz","fileCount":7,"integrity":"sha512-RWG8TMg6T9dqcugg7MsxcpnckPubdgxRWKtkbeCX30oVHb60RAadywAn2icb+Y8kqaasWK05+VSnsXlCBLimIQ==","signatures":[{"sig":"MEUCIBWt7j3hSSd/+ZkJLhbUkAx+jYIz75p03acdik+WPhFPAiEA6zZA8HYgDDit5sVUqj9F2lSu0ohOAKkkVYMSv3nMj28=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":24141},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"67cbe687cd0664deb4374aaa75788c9d7119d74b","scripts":{"dev":"tsc -p tsconfig.json --watch","test":"vitest run --passWithNoTests","build":"tsc -p tsconfig.json"},"_npmUser":{"name":"aroha-labs","email":"projectmed99@gmail.com"},"_npmVersion":"11.13.0","description":"Aroha Policy-as-Code — deterministic JSON boundary enforcement before LLM agents see requests","directories":{},"_nodeVersion":"24.16.0","dependencies":{"@aroha-sdk/core":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^1.6.0","typescript":"^5.4.5","@types/node":"^20.14.0"},"_npmOperationalInternal":{"tmp":"tmp/policy_1.0.0_1782173748047_0.39190650353505463","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@aroha-sdk/policy","version":"1.2.0","_id":"@aroha-sdk/policy@1.2.0","maintainers":[{"name":"aroha-labs","email":"projectmed99@gmail.com"}],"dist":{"shasum":"3bfc9208957cad155f6a3a88632cd5ccebf4ad05","tarball":"https://registry.npmjs.org/@aroha-sdk/policy/-/policy-1.2.0.tgz","fileCount":26,"integrity":"sha512-oisFdQUg9BgWiR5QunMHGxmYYksrpAopWx2uktl37xrzdErFGVoQlLYaT4/oeBoBSxd3amQy9y9BYPQd2n4wlQ==","signatures":[{"sig":"MEQCIDnTyLhlRogBR5IpwCgOSPvFuNThGnvvGTQtVF4ROAxmAiB+sG9EKBEhDF6OfYO07ChHyGuVLGEaVLA0q8AZAtm4Bg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":70807},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"3fd6d5ab883e07e6c38989dc642f87ef70bb6320","scripts":{"dev":"tsc -p tsconfig.json --watch","test":"vitest run --passWithNoTests","build":"tsc -p tsconfig.json"},"_npmUser":{"name":"aroha-labs","email":"projectmed99@gmail.com"},"_npmVersion":"11.13.0","description":"Aroha Policy-as-Code â€” deterministic JSON boundary enforcement before LLM agents see requests","directories":{},"_nodeVersion":"24.16.0","dependencies":{"@aroha-sdk/core":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^1.6.0","typescript":"^5.4.5","@types/node":"^20.14.0"},"_npmOperationalInternal":{"tmp":"tmp/policy_1.2.0_1782181551453_0.7976209148300091","host":"s3://npm-registry-packages-npm-production"}},"1.2.1":{"name":"@aroha-sdk/policy","version":"1.2.1","_id":"@aroha-sdk/policy@1.2.1","maintainers":[{"name":"aroha-labs","email":"projectmed99@gmail.com"}],"dist":{"shasum":"21d41277d5540a7331e86cb06a92fcd38e87d984","tarball":"https://registry.npmjs.org/@aroha-sdk/policy/-/policy-1.2.1.tgz","fileCount":36,"integrity":"sha512-5LWZepDXRYrbfcvzZCFJCxigJq/vea+6UhO843IZI1PRhWX7A3Fj2JWra7xTZreXxPQib+rSw8YbxH+xqTn/1A==","signatures":[{"sig":"MEYCIQDSee33Hzp4iYcyOKddC2O6mG5+v3vliBTx6mGBLzRKDwIhAIHjeVWYpKrXaCL4kfbN18zkGZEqQk80w5t56XgQ+OX3","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":102923},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"a7fc3b14f2e9a4b83b1483442dc68e46d0ac4872","scripts":{"dev":"tsc -p tsconfig.json --watch","test":"vitest run --passWithNoTests","build":"tsc -p tsconfig.json"},"_npmUser":{"name":"aroha-labs","email":"projectmed99@gmail.com"},"_npmVersion":"11.16.0","description":"Aroha Policy-as-Code â€” deterministic JSON boundary enforcement before LLM agents see requests","directories":{},"_nodeVersion":"24.18.0","dependencies":{"@aroha-sdk/core":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^1.6.0","typescript":"^5.4.5","@types/node":"^20.14.0"},"_npmOperationalInternal":{"tmp":"tmp/policy_1.2.1_1783118062554_0.87994845941808","host":"s3://npm-registry-packages-npm-production"}},"1.2.2":{"name":"@aroha-sdk/policy","version":"1.2.2","license":"MIT","_id":"@aroha-sdk/policy@1.2.2","maintainers":[{"name":"aroha-labs","email":"projectmed99@gmail.com"}],"dist":{"shasum":"0041428590417f57365a2d0d7c62904f8549256f","tarball":"https://registry.npmjs.org/@aroha-sdk/policy/-/policy-1.2.2.tgz","fileCount":36,"integrity":"sha512-ptMNDB5ysO3EOD4D1HI6ZqYCg+uv86jWdW54Lw6QAXdlPYAegC+aZylDC312Fib8d1imgzwUmwLzd9bEQYswqQ==","signatures":[{"sig":"MEUCIHopm4XP5YQSr1841+T7IBrJbxoZ3YEi6qTId+vxQPTFAiEAvHUO912Q2HwpfTZ7mtUzd2fyonh3BqF6njZ0eRe54QU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":102986},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"ca0800d55b453d5e9b38ffce3dff055f010619eb","scripts":{"dev":"tsc -p tsconfig.json --watch","test":"vitest run --passWithNoTests","build":"tsc -p tsconfig.json"},"_npmUser":{"name":"aroha-labs","email":"projectmed99@gmail.com"},"_npmVersion":"11.16.0","description":"Aroha Policy-as-Code â€” deterministic JSON boundary enforcement before LLM agents see requests","directories":{},"_nodeVersion":"24.18.0","dependencies":{"@aroha-sdk/core":"^1.0.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^1.6.0","typescript":"^5.4.5","@types/node":"^20.14.0"},"_npmOperationalInternal":{"tmp":"tmp/policy_1.2.2_1783119740276_0.6450504506440564","host":"s3://npm-registry-packages-npm-production"}},"1.3.0":{"name":"@aroha-sdk/policy","version":"1.3.0","description":"Aroha Policy-as-Code â€” deterministic JSON boundary enforcement before LLM agents see requests","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"}},"scripts":{"build":"tsc -p tsconfig.json","test":"vitest run --passWithNoTests","dev":"tsc -p tsconfig.json --watch"},"dependencies":{"@aroha-sdk/core":"^1.0.0"},"devDependencies":{"typescript":"^5.4.5","vitest":"^1.6.0","@types/node":"^20.14.0"},"license":"MIT","engines":{"node":">=18.0.0"},"gitHead":"8fa8563aea2cc73fcd7a82d1c56063a3d9edc7d6","_id":"@aroha-sdk/policy@1.3.0","_nodeVersion":"24.19.0","_npmVersion":"11.17.0","dist":{"integrity":"sha512-+GEtki/60w2Tz40xI+03bIYvMx4klVYl7rHusrMAgNqqJhMIOChO84dhHhZ2awneOC9NkXfUWpg41dUqSqHoQQ==","shasum":"73be75354a53eed72e67056d0e6de40a18d706dd","tarball":"https://registry.npmjs.org/@aroha-sdk/policy/-/policy-1.3.0.tgz","fileCount":47,"unpackedSize":132701,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIGtvsDbqxtGiUz0W0nOMBDCeGg2fhoAiBj7IAtNo7ayMAiBOvx9qyGD2i1AQD3KUxTni6FwqTSlExl1N+Vu+AxNdoQ=="}]},"_npmUser":{"name":"aroha-labs","email":"projectmed99@gmail.com"},"directories":{},"maintainers":[{"name":"aroha-labs","email":"projectmed99@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/policy_1.3.0_1787073852386_0.19017619646345474"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-23T00:15:47.808Z","modified":"2026-08-18T17:24:12.729Z","1.0.0":"2026-06-23T00:15:48.179Z","1.2.0":"2026-06-23T02:25:51.595Z","1.2.1":"2026-07-03T22:34:22.704Z","1.2.2":"2026-07-03T23:02:20.439Z","1.3.0":"2026-08-18T17:24:12.515Z"},"license":"MIT","description":"Aroha Policy-as-Code â€” deterministic JSON boundary enforcement before LLM agents see requests","maintainers":[{"name":"aroha-labs","email":"projectmed99@gmail.com"}],"readme":"# @aroha-sdk/policy\n\nPre-LLM policy guardrails for Aroha agents — declarative rules that run before the model is called, complementing cryptographic mandate bounds.\n\n## Install\n\n```bash\nnpm install @aroha-sdk/policy\n```\n\n## Quick example\n\n```typescript\nimport { PolicyEngine } from \"@aroha-sdk/policy\";\n\nconst policy = new PolicyEngine({\n  rules: [\n    // Block requests that exceed the mandate's allowed actions\n    {\n      name: \"allowed-actions\",\n      check: (req, mandate) =>\n        mandate.constraints.allowedActions.includes(req.action),\n      onViolation: \"reject\",\n      message: \"Action not permitted by mandate\",\n    },\n    // Rate-limit to protect the spending cap\n    {\n      name: \"rate-limit\",\n      check: (req, mandate) => rateLimiter.allow(mandate.granteeDID),\n      onViolation: \"reject\",\n      message: \"Rate limit exceeded\",\n    },\n    // Flag suspicious prompts for review before calling the LLM\n    {\n      name: \"prompt-injection-guard\",\n      check: (req) => !containsInjectionPattern(req.message),\n      onViolation: \"flag\",\n    },\n  ],\n});\n\nserve({\n  name: \"my-agent\", did, privateKey,\n  onRequest: async (req) => {\n    const { allowed, reason } = await policy.evaluate(req, req.mandate);\n    if (!allowed) return { error: reason, status: 403 };\n    // ... call LLM\n  },\n});\n```\n\n## Why this exists in the mandate chain\n\nCryptographic mandate bounds enforce what an agent is *authorized* to do. Policy rules enforce what it *should* do — prompt injection guards, rate limits, content filters, and action-allow-lists that run before the LLM ever sees the request.\n\n## API\n\n- `PolicyEngine(opts)` — create a policy engine with a list of named rules.\n  - `engine.evaluate(req, mandate)` — run all rules. Returns `{ allowed, reason?, flagged? }`.\n- `PolicyRule` — `{ name, check(req, mandate): boolean | Promise<boolean>, onViolation: \"reject\" | \"flag\", message? }`.\n- `buildDefaultPolicy()` — sensible default ruleset: prompt injection guard, action allowlist, and spend-cap pre-check.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}