First release of ragleap-agents: a small act-observe agent loop over ragleap_tools.Tool objects. llm is any callable llm(prompt) -> str. Install: pip install ragleap-agents.
What it does
- One JSON action per step, up to
max_steps(default 4, hard cap 8). Every proposal is checked against the tool's JSON Schema; an invalid proposal stops the run and nothing executes. - Tool results are untrusted: capped, fenced, and lookalike tags are neutralised case-insensitively.
ToolPolicy(taints, outbound, requires_approval)per tool. After a tainting tool has run, every later outbound tool needs approval. A tool with no declared policy counts as both (fail closed).- Pause and resume through a pluggable
StateStore(InMemoryStateStoreincluded). Replays and mismatched decisions raiseResumeError.
This does not stop prompt injection. It limits what an injected instruction can do, if the declared tool policies are accurate.
Verified
- 41 tests with a scripted model (no network). CI run 37731632860 on PR head d042333:
ragleap-agents-testspassed on Python 3.10, 3.11 and 3.12. Mutation-checked: removing the taint rule, case-insensitive fence, exception-text rule, resume claim, hard cap, fail-closed default or bool-is-not-integer check each makes at least one test fail. - Published wheel, fresh venvs on Python 3.10.12, 3.11.15 and 3.12.13: installs,
pip checkclean,__version__is 0.1.0, onlyragleap-agentsandragleap-tools0.4.0 are installed. - Smoke test of the published wheel (scripted model, 3.12): normal run, invalid arguments stop with nothing executed, fetch then send pauses for approval and does not send, reject never sends and a replay is refused, approve sends.
- Source under
packages/ragleap-agentsis unchanged between the tested head d042333 and the tagged commit.
Not verified
- Any real model. No provider has been run through this loop yet.
- Long runs, and concurrent resumes across processes (a store must make resume atomic).
- Equivalence with RagLeap Core's agent loop (it mirrors core commit 59fd555 as of 2026-10-03, which keeps changing).
- Comparisons with other frameworks. No capability or speed claim is made here.
Provenance
- Code: PR #628, merge commit d3e0c14. Release pipeline: PR #646, merge commit 0482515, which is the tagged commit. CI on 0482515: run 37889921507, success.
- Publish: tag run 37890106262, trusted publishing with attestations; no "already exists" skip, so this was the first upload.
- Digests (sha256), identical in the run log and on PyPI:
- ragleap_agents-0.1.0-py3-none-any.whl: d305238f31fa5f65adf8d6adb363bdb4f950da7763cdbb98866e0d0eb49efe01
- ragleap_agents-0.1.0.tar.gz: 44cf12676dfc3b607ef5cd08f2135bde56e90bab4a2ef5e4c2ec66121f0d50a1
Note
The CHANGELOG inside the 0.1.0 files still has this release under [Unreleased]. A published file can't be changed, so the heading is corrected on main and ships with the next version.