PyPI package · Alpha
ragleap-agents
version — loading live from PyPI…
A small agent loop over ragleap-tools Tool objects. The model proposes one action at a time and you bring it as a plain callable; the library has no provider code and no database.
pip install ragleap-agents
Highlights
- Every proposal is checked against the tool's JSON Schema; an invalid proposal stops the run and no tool executes
- Tool results are untrusted: capped, fenced in
<observation>tags, with lookalike tags neutralised case-insensitively - Taint rule: after a tool declared
taints=Truehas run, every lateroutbound=Truetool needs approval. A tool with no declared policy counts as both, so it fails closed - Pause and resume through a pluggable
StateStore; a replayed or mismatched approval raisesResumeError
Tech stack
Python 3.10 to 3.12. One dependency: ragleap-tools. No provider code, no database.
Testing
29 test functions across 2 test files, verified directly from the repo (parametrised cases count once). CI runs 41 test cases on Python 3.10, 3.11 and 3.12, with a scripted model and no network.
Verification status
- Verified: the 41 scripted-model tests; mutation checks (removing the taint rule, the fence, the exception-text rule, the resume claim, the hard cap, the fail-closed default or the bool-is-not-integer check each fails at least one test); the published 0.1.0 wheel installs on 3.10, 3.11 and 3.12 and passes a scripted smoke test.
- Not verified: any real model (no provider has been run through this loop yet), long runs, concurrent resumes across processes, and equivalence with RagLeap Core's agent loop.
Limits to know about
- It does not stop prompt injection. It limits what an injected instruction can do, and only as far as your
ToolPolicydeclarations are accurate. - Tool descriptions (capped at 300 characters) are shown to the model, so tools from an untrusted source can inject through them.
- Single agent only in v0.1.0; multi-agent crews are planned, not built.
Quickstart
from ragleap_tools import CALCULATOR_TOOL
from ragleap_agents import Agent, Policy, TRUSTED
def my_llm(prompt: str) -> str:
... # call any model, return its text
agent = Agent(
llm=my_llm,
tools=[CALCULATOR_TOOL],
policy=Policy(max_steps=4, tools={"calculator": TRUSTED}),
)
result = agent.run("What is 6 * 7?")
print(result.status, result.answer)