cpex
CPEX - ContextForge Plugin Extensibility Framework
Decision gist · record as of 2026-08-14
Yes, if you are building AI agents or toolchains that need policy enforcement, security, or governance without tight coupling to application logic. The framework is actively maintained, has no known vulnerabilities, and uses a permissive license. However, it is early-stage (0.1.3, released 2026-03-05) with 12 GitHub stars—evaluate stability and API maturity for your use case before committing to production.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.11 or later.
- Low friction: pure Python wheel with no compiled dependencies.
- Active maintenance—last commit 2026-08-14, first release 2026-03-05.
License · maintenance · safety
Apache-2.0 (permissive) — Apache-2.0 permissive license allows commercial and private use with minimal restrictions; you must include a copy of the license and note any modifications.
last release 2026-08-06 (8 days) · last repo commit 2026-08-14 · 12 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 76,505 downloads/mo, #14,621 on PyPI
Alternatives
Verify before relying
pip install cpex
from cpex.framework import hook, Plugin, PluginResult
class MyPlugin(Plugin):
@hook("tool_pre_invoke")
async def enforce_policy(self, payload, context):
return PluginResult(continue_processing=True)- Whether the 14 runtime dependencies (particularly fastapi, prometheus-client, pygithub) are all required at import time or only for specific features.
- Production readiness and stability guarantees given the 0.1.3 version and early release date (2026-03-05).
- Performance characteristics and overhead of the plugin pipeline under high-concurrency agent workloads.
What it is and what it does
CPEX is a plugin framework designed to add policy enforcement, security, observability, and governance to AI agents and toolchains without embedding that logic into application code. It works by defining named hook points in your application (e.g., before/after tool invocation, prompt fetching, agent execution), then registering plugins that attach to those hooks and run automatically when triggered. Plugins can allow, block, or modify payloads; they execute in ordered phases (sequential, transform, audit, concurrent, fire-and-forget) to support different enforcement and observability patterns.
The framework comes with built-in hooks for common AI operations (tool_pre_invoke, tool_post_invoke, prompt_pre_fetch, etc.) and lets you define custom hooks with your own payload types. It handles plugin registration, ordering, timeouts, and error isolation automatically. With 14 runtime dependencies including fastapi, pydantic, prometheus-client, and rich, it's designed for production agent systems that need structured policy pipelines and observability.
Use it for
- Enforce access control and rate limiting on tool calls in multi-agent systems without modifying agent code.
- Detect and block prompt injection attempts or policy violations at hook points before operations execute.
- Collect audit logs, request tracing, and metrics on agent operations through observe-only audit plugins.
- Implement data loss prevention by transforming or redacting sensitive data in payloads before they leave the system.
- Build approval workflows or compliance validation gates that run automatically at critical agent operations.
- Add circuit breakers and response validation to agent tool invocations without changing core agent logic.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are building AI agents or toolchains that need policy enforcement, security, or governance without tight coupling to application logic.
The framework is actively maintained, has no known vulnerabilities, and uses a permissive license. However, it is early-stage (0.1.3, released 2026-03-05) with 12 GitHub stars—evaluate stability and API maturity for your use case before committing to production.
Install
cpex on PyPI
Before you install
Low friction: pure Python wheel with no compiled dependencies. Active maintenance—last commit 2026-08-14, first release 2026-03-05. Fourteen runtime dependencies (fastapi, httpx, pydantic, prometheus-client, etc.) add moderate weight but are all standard, well-maintained packages.
Requires Python 3.11 or later.
License in practice
Apache-2.0 permissive license allows commercial and private use with minimal restrictions; you must include a copy of the license and note any modifications.
Quickstart
pip install cpex
from cpex.framework import hook, Plugin, PluginResult
class MyPlugin(Plugin):
@hook("tool_pre_invoke")
async def enforce_policy(self, payload, context):
return PluginResult(continue_processing=True)
Verify before relying
- Whether the 14 runtime dependencies (particularly fastapi, prometheus-client, pygithub) are all required at import time or only for specific features.
- Production readiness and stability guarantees given the 0.1.3 version and early release date (2026-03-05).
- Performance characteristics and overhead of the plugin pipeline under high-concurrency agent workloads.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.11 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 14 packagesfastapihttpxinquirerjinja2mcporjsonpackagingprometheus-clientprometheus-fastapi-instrumentatorpydantic-settingspydanticpygithubpyyamlrich |
| Maintenance | Actively maintained 8 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 76,505 / month, #14,621 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Topic :: Scientific/Engineering :: Artificial IntelligenceTopic :: Software Development :: Libraries :: Application FrameworksTopic :: Software Development :: Libraries :: Python Modules |
Evidence: cpex-0.1.3-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “policy enforcement hooks”
- cpexCPEX is a plugin framework that lets you intercept and enforce…
- commit-checkValidates Git commit messages, branch names, author identity, and…
- tachTach enforces module boundaries, dependency rules, and public…
Give your agent the search over MCP, or paste the wish link into any chat.
More Python Modules packages
Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.
Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.
Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.
PyYAML parses and emits YAML 1.1 data format, enabling serialization and deserialization of configuration files and Python objects to and from human-readable YAML text.
Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.
Provides reusable metadata objects for use with PEP-593 `typing.Annotated` to express common constraints like bounds, collection sizes, and predicates on types.
Install it if you use or build libraries that need to express type constraints in a standardized, inspectable way—or if you want to annotate your own types with…
Provides runtime tools to inspect and introspect Python type annotations, enabling programmatic examination of type hints at execution time.
See also agent_governance_toolkit · agent-governance-toolkit-core · microsoft-agents-a365-observability-core · agent-framework-purview · agent-governance-toolkit-cli · plugin-scanner · hol-guard · apm-cli · microsoft-agents-a365-runtime · strands-agents-builder