Deterministic, sub-millisecond execution circuit breaker for autonomous AI agent tool-calls.

Standard LLM guardrails (RLHF, system prompt boundaries) operate in-band: models evaluate their own compliance. When autonomous agents are granted tool-calling access to system shells, databases, or financial disbursement rails, adversarial injections or goal drift can bypass prompt restrictions via Base64 obfuscation, polyglot payloads, or velocity micro-drains.

aw1-breaker enforces an out-of-band execution interlock between the agent reasoning node and downstream execution sockets.

aw1-breaker is open-source under the MIT license and free for local development, research, and testing.

For teams deploying autonomous agents to production environments requiring centralized audit logs, dedicated support, and production-tier execution guarantees:

🛡️ Get AW-1 Pro Production License ($49/mo) →

Includes cryptographically verifiable production runtime keys, automated webhook provisioning, and priority security SLA.

👉 Direct Checkout: Purchase an aw1-breaker Pro Production License

Each subscription automatically provisions a cryptographically verifiable license key to unlock production runtime validation and priority security patches.

pip install aw1-breaker

---

## Quickstart

```python

from aw1 import ExecutionBreaker

breaker = ExecutionBreaker(baseline_velocity=50000.0)

result = breaker.intercept(

actor_id="agent_treasury_01",

tool_name="disburse_funds",

payload='{"target": "core_ledger", "action": "payout"}',

amount=12000.0

)

print(result)

Wrap any tool or Model Context Protocol (MCP) server handler to block prompt injections and unauthorized tool-calling in 0.014ms before execution:

from aw1 import ExecutionBreaker

# Initialize sub-millisecond out-of-band AST breaker

breaker = ExecutionBreaker(baseline_velocity=50000.0)

# Protect any agent tool or MCP server handler before execution:

@breaker.guard(actor="claude_desktop_worker")

async def execute_query(query: str):

# Deterministically inspected in 0.014ms.

# Blocked immediately if AST contains shell escapes, eval/exec, or OS tampering.

return await db.execute(query)- Sub-Millisecond AST Evaluation: Evaluates token trees and command ASTs in <0.02ms, bypassing the 500ms–1500ms latency of LLM-as-a-judge approaches.

- Zero External Dependencies: Built purely using Python standard library primitives (ast,token,hmac), ensuring zero supply-chain attack surface.

- Velocity & Drift Containment: Prevents agent infinite recursion and high-frequency micro-drain attempts against production infrastructure.

- Auditable Cryptographic Tokens: Permits valid execution only upon issuing signed, time-bound execution receipts.

MIT License. Designed and maintained by Laveto Labs.