RagLeap
ragleap-agents · release notes

ragleap-agents v0.1.0

First release of ragleap-agents: a small act-observe agent loop over ragleap_tools.Tool objects. llm is any callable llm(prompt) -> str. Install: pip install ragleap-agents.

What it does

  • One JSON action per step, up to max_steps (default 4, hard cap 8). Every proposal is checked against the tool's JSON Schema; an invalid proposal stops the run and nothing executes.
  • Tool results are untrusted: capped, fenced, and lookalike tags are neutralised case-insensitively.
  • ToolPolicy(taints, outbound, requires_approval) per tool. After a tainting tool has run, every later outbound tool needs approval. A tool with no declared policy counts as both (fail closed).
  • Pause and resume through a pluggable StateStore (InMemoryStateStore included). Replays and mismatched decisions raise ResumeError.

This does not stop prompt injection. It limits what an injected instruction can do, if the declared tool policies are accurate.

Verified

  • 41 tests with a scripted model (no network). CI run 37731632860 on PR head d042333: ragleap-agents-tests passed on Python 3.10, 3.11 and 3.12. Mutation-checked: removing the taint rule, case-insensitive fence, exception-text rule, resume claim, hard cap, fail-closed default or bool-is-not-integer check each makes at least one test fail.
  • Published wheel, fresh venvs on Python 3.10.12, 3.11.15 and 3.12.13: installs, pip check clean, __version__ is 0.1.0, only ragleap-agents and ragleap-tools 0.4.0 are installed.
  • Smoke test of the published wheel (scripted model, 3.12): normal run, invalid arguments stop with nothing executed, fetch then send pauses for approval and does not send, reject never sends and a replay is refused, approve sends.
  • Source under packages/ragleap-agents is unchanged between the tested head d042333 and the tagged commit.

Not verified

  • Any real model. No provider has been run through this loop yet.
  • Long runs, and concurrent resumes across processes (a store must make resume atomic).
  • Equivalence with RagLeap Core's agent loop (it mirrors core commit 59fd555 as of 2026-10-03, which keeps changing).
  • Comparisons with other frameworks. No capability or speed claim is made here.

Provenance

  • Code: PR #628, merge commit d3e0c14. Release pipeline: PR #646, merge commit 0482515, which is the tagged commit. CI on 0482515: run 37889921507, success.
  • Publish: tag run 37890106262, trusted publishing with attestations; no "already exists" skip, so this was the first upload.
  • Digests (sha256), identical in the run log and on PyPI:
    • ragleap_agents-0.1.0-py3-none-any.whl: d305238f31fa5f65adf8d6adb363bdb4f950da7763cdbb98866e0d0eb49efe01
    • ragleap_agents-0.1.0.tar.gz: 44cf12676dfc3b607ef5cd08f2135bde56e90bab4a2ef5e4c2ec66121f0d50a1

Note

The CHANGELOG inside the 0.1.0 files still has this release under [Unreleased]. A published file can't be changed, so the heading is corrected on main and ships with the next version.

View on GitHub Package page All releases

Release notes mirrored from GitHub Releases.