Open source · Apache-2.0

Delegation without escalation.

attenu-guard checks every agent tool call in your process, narrows permissions at each handoff, and logs every decision in a verifiable chain. Works with 19 frameworks. No dependencies.

pip install attenu-guard
attenu-guard demo

Runs offline · No API key · Chain verified

How a sub-agent pushed a workflow file its parent was held on: the Open SWE write-up

AssistantAI agent

Refund order #58231.

Allowed to

Read ordersRead policiesIssue refundsSend email

RecordsSub-agent

Allowed to

Read orders

Read orders✓ Allowed

ReportsSub-agent

Allowed to

Read policies

Export data✕ Not granted

PaymentsSub-agent

Allowed to

Issue refunds

Issue refundsHeld for you✓ Approved by you

What you get

  1. One check on every tool call, inside your process, across 19 Python frameworks and A2A, with a TypeScript port.
  2. Permissions that only narrow at each handoff, down any chain, with typed limits (rows, spend, calls) and cascade revocation.
  3. A hash-chained, signable ledger of every allow and deny, for security audit, verified offline with the vendor absent.
  4. Observe mode records everything and blocks nothing. Each decision can stream to your own endpoint as it happens.
  5. No network in the deny path. Revoke at runtime; stream to your own endpoint when you want one.
  6. Tested: 1,415 test functions, a red-team harness and property invariants in CI.

Proof

Merged fixes and third-party runs.

Every line is a fact with a public link.

Reported by us, fixed natively by them

  • LangChain Open SWEGHSA-wpjg-64mw-3qj9 · published 18 September 2026

    Open SWE held a parent agent’s push of a workflow file for approval. A sub-agent it delegated to pushed the same file without asking. Reported on 7 September 2026 with a reproducer and a patch; LangChain merged a native fix the same day and published the advisory on 18 September: CWE-862, moderate severity, credited to Rafael Asor (Attenu). Fixed in Open SWE 0.2.8.

  • Yuxixerrors/Yuxi#1001 · merged 8 September 2026

    The default approval mode hid the write, edit and execute tools from sub-agents without intercepting them, so in the demonstrated path a sub-agent wrote with no approval interrupt. The native fix we sent, which refuses those tools instead of hiding them, was merged with its tests.

  • minion-agentfemto/minion-agent#7 · merged 8 September 2026

    A managed sub-agent’s configuration was dropped on the way in: a child configured for a Docker executor and 3 steps ran with the local executor and 20. The native fix we sent, which passes the configuration through, was merged with regression tests.

  • Merged upstream as contributionsnot endorsements

    A recipe that depends on attenu-guard is merged in Google’s ADK recipes repository (8 September 2026). Attenu Guard is listed in LangChain’s integrations docs (28 August 2026).

Our test corpora, scored by outside verifiers

  • @safal207Python and Node.js · 3 and 6 September 2026

    The released bundle corpus: 12 of 12 with a stdlib-only Python verifier. The 20 Delegation Token vectors: 20 of 20 in Node.js, under the corpus’s single-signer HS256 test profile and draft steps 1 to 5; DPoP, Token Status List and actual-action authorization were not run. His boundary: corpus conformance for the released fixtures, not verifier completeness, runtime correctness or certification.

  • Xuebin Ma, agent-guardRust · 2 and 7 September 2026

    The released bundle corpus: 8 of 8, written from the format description alone, by his account. The observer-envelope corpus, revision 1.2: 19 of 19. His boundary: independent reproduction of the released corpus at that pin, not verifier completeness, runtime correctness or certification.

  • Kieran Sweeney, Credthe Cred protocol’s own harness · 3 September 2026

    The 20 Delegation Token vectors, run through Cred’s own verifier: 17 of 20, 0 fail, 3 declared gaps. His commit message states the gaps as properties that only matter for offline verification of a foreign token, which is not Cred’s model. A run by a second delegation protocol, not by a general-purpose verifier.

Run today on attenu-guard 0.18.0

  • Red-team harness28 September 2026

    17 attacks on the handoff rules: 15 defended, 2 documented limitations, 0 broken. The two limitations, an aggregate budget reached through an undeclared quantity and a re-seal inside the same process, are written up in the red-team report.

  • Property invariants28 September 2026

    Five invariants, 4,000 random trials each, all held: a delegated authority was never wider than its parent or its request; every node in a chain stayed inside the root; a scope a parent dropped never reappeared below it; a revoked subtree denied everything; a clean log verified and every tampered one was detected.

Compared with

The alternatives, in their own words.

Every cell is sourced from the other project’s own page or a run in our repository.

Tenuo gives each task authority that “can only shrink when handed off” and is “Verified offline”; Apache-2.0, in Python, Rust and TypeScript (beta). Keel defines a permit chain in which each child’s authority envelope “is mechanically constrained to be a subset of its parent’s”, with artifacts “verifiable without contacting the issuer”; its specification and verifier are public, its reference server is Keel-internal. What we can state on our side: attenu-guard has zero runtime dependencies in the core and is pure Python, and its primary artifact is a hash-chained log of every check, exported as a bundle a third party verifies. Tenuo · Keel

attenu-guardTenuoKeelFramework hooksOPA · Cedar · Casbin
Every tool call checked in-process✓✓n/a, spec names no runtime✓✓
Child ⊆ parent, enforced at handoff✓ built in✓✓✗ child ran a tool the parent never held (all four, run 28 Sep 2026)you write the rule
Holds at any chain depth✓—✓✗ no parent relation—
Cascade revocation✓————
Typed limits that only shrink✓————
Hash-chained log of every decision✓receipts, opt-in———
Offline verification✓✓✓—n/a
Observe mode✓✓———
Outside verifiers scored our vectors✓ three——n/an/a
Agent-framework adapters19 + A2Aown list—n/a—
Runtime dependenciesnonepyyaml, pydanticn/an/a—
Open source you can runApache-2.0, all of itApache-2.0spec + verifier public; server internaln/aApache-2.0

✓ stated on the project’s own pages or shown by a run in our repository · ✗ its own pages or a run say no · — not stated on the pages we read; silence is not a no. Framework hooks: Deep Agents, CrewAI, the OpenAI Agents SDK and Google ADK, each through its own hook API. Every cell’s source is on the full comparison. If a cell no longer matches its source, open an issue with the page and the date; the cell is corrected, not argued.

The token and identity standards (OAuth, SPIFFE, macaroons, Biscuit) and each alternative in its own words: the full comparison. Cedar, OPA and Casbin in depth: Cedar vs OPA vs Casbin vs attenu-guard.

Open source

Three packages, Apache-2.0.

The library that enforces, the engine that works out permissions, and the TypeScript port. Install one, run the demo without a key, verify a bundle with nothing but the verifier.

attenu-guard

pip install 'attenu-guard[langgraph]'

Least privilege for agents that hand work on: a sub-agent never holds more than the agent that delegated to it, checked inside your process, written to a hash-chained log. No runtime dependencies in the core. Getting started · Verify a bundle · GitHub

attenu-derive

pip install attenu-derive

Reads your agent app and works out the permissions each task needs. You approve them once. Payments, mail, deletes and code execution are never granted automatically. The engine · GitHub

attenu-guard-ts

npm install attenu-guard

The same check in TypeScript and Node.js: every tool call against the agent’s permissions, a sub-agent never wider than its parent, the same hash-chained log. One adapter so far, LangGraph.js. No runtime dependencies. TypeScript · GitHub

Examples inside the tools you already use: Google ADK, LangGraph, OpenAI Agents SDK, Omnigent, Claude Code and MCP, each offline, each with one real denial and one offline verification. All documentation · Roadmap · Changelog

Works with

Plus deepagents, a multi-agent application on LangChain. AstrBot is an application too, tested from a pinned checkout.

Nineteen frameworks and the A2A protocol, integrated without patching their source. A pinned matrix runs in CI, and a weekly job checks the latest release of each framework except OpenHands and AstrBot.

See it on your own app

Start in observe mode: it records what each agent does and denies nothing, so you see what would have been held before anything is enforced. Reverting is one configuration change. If you would like a walkthrough on your app, or want the engine inside your product, get in touch. We reply within two working days.