Deterministic, sub-millisecond execution circuit breaker for autonomous AI agent tool-calls.
Standard LLM guardrails (RLHF, system prompt boundaries) operate in-band: models evaluate their own compliance. When autonomous agents are granted tool-calling access to system shells, databases, or financial disbursement rails, adversarial injections or goal drift can bypass prompt restrictions via Base64 obfuscation, polyglot payloads, or velocity micro-drains.
aw1-breaker enforces an out-of-band execution interlock between the agent reasoning node and downstream execution sockets.
aw1-breaker is open-source under the MIT license and free for local development, research, and testing.
For teams deploying autonomous agents to production environments requiring centralized audit logs, dedicated support, and production-tier execution guarantees:
🛡️ Get AW-1 Pro Production License ($49/mo) →
Includes cryptographically verifiable production runtime keys, automated webhook provisioning, and priority security SLA.
👉 Direct Checkout: Purchase an aw1-breaker Pro Production License
Each subscription automatically provisions a cryptographically verifiable license key to unlock production runtime validation and priority security patches.
pip install aw1-breaker
---
## Quickstart
```python
from aw1 import ExecutionBreaker
breaker = ExecutionBreaker(baseline_velocity=50000.0)
result = breaker.intercept(
actor_id="agent_treasury_01",
tool_name="disburse_funds",
payload='{"target": "core_ledger", "action": "payout"}',
amount=12000.0
)
print(result)
Wrap any tool or Model Context Protocol (MCP) server handler to block prompt injections and unauthorized tool-calling in 0.014ms before execution:
from aw1 import ExecutionBreaker
# Initialize sub-millisecond out-of-band AST breaker
breaker = ExecutionBreaker(baseline_velocity=50000.0)
# Protect any agent tool or MCP server handler before execution:
@breaker.guard(actor="claude_desktop_worker")
async def execute_query(query: str):
# Deterministically inspected in 0.014ms.
# Blocked immediately if AST contains shell escapes, eval/exec, or OS tampering.
return await db.execute(query)- Sub-Millisecond AST Evaluation: Evaluates token trees and command ASTs in <0.02ms, bypassing the 500ms–1500ms latency of LLM-as-a-judge approaches.
- Zero External Dependencies: Built purely using Python standard library primitives (ast,token,hmac), ensuring zero supply-chain attack surface.
- Velocity & Drift Containment: Prevents agent infinite recursion and high-frequency micro-drain attempts against production infrastructure.
- Auditable Cryptographic Tokens: Permits valid execution only upon issuing signed, time-bound execution receipts.
MIT License. Designed and maintained by Laveto Labs.