$npx skillfedfor your agent

toolguard

Policy adherence code generation for guarding AI agent tools

With conditionsPyPI Artificial IntelligenceReleased Jun 2026171.8K downloads / mopermissive licensePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — toolguard-0.2.21-py3-none-any.whl
v0.2.21 · released 2026-06-30 · Python <3.15,>=3.10 · 12 runtime deps: datamodel-code-generator, fastmcp, langchain-core, litellm, loguru, markdown, pydantic, pyright

Yes, if you need deterministic policy enforcement on AI agent tools and can invest in the buildtime setup (policy document, LLM configuration, tool specs). The package is actively maintained, has low install friction, and solves a real problem in agentic systems. Not suitable if you need runtime-only policy injection without code generation, or if you lack access to an LLM provider for the buildtime phase.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10+.
  • Buildtime API requires an LLM provider (e.g., Azure OpenAI) configured via litellm.
  • Policy documents and tool OpenAPI specs must be provided.

License · maintenance · safety

permissive license (permissive) — Apache License 2.0 (permissive). You may use, modify, and distribute this package freely in commercial and private projects, provided you include the license and document any changes.

last release 2026-06-30 (45 days)

0 known vulnerabilities (OSV.dev, 2026-08-14) · 171,769 downloads/mo, #10,356 on PyPI

Verify before relying

pip install toolguard

from toolguard.buildtime import generate_guard_specs, LitellmModel
from toolguard.runtime import load_toolguards, ToolFunctionsInvoker

# Step 1: Generate specs from policy document and tools
specs = await generate_guard_specs(policy_text, tools, llm=llm_model)

# Step 2: Generate guard code
guards = await generate_guards_code(tool_specs=specs, tools=tools, llm=llm_model)

# Step 3: Load and use at runtime
with load_toolguards("output") as toolguard:
    invoker = ToolFunctionsInvoker(tools)
    await toolguard.guard_toolcall("tool_name", {"param": value}, invoker)
  • Whether the generated guard code is guaranteed to be deterministic or only intended to be so in practice.
  • Performance overhead of guard evaluation at runtime for large numbers of tools or complex policies.
  • How well the tool handles edge cases in policy interpretation or ambiguous policy language.
  • Support for dynamic policy updates without regenerating all guard code.
Same gist for agents: .md · .json

What it is and what it does

Toolguard is a two-phase system for enforcing business policies on AI agent tool calls. It bridges the gap between traditional hard-coded policy enforcement and the non-deterministic best-effort approach of appending policies to agent prompts. The package generates deterministic Python guard code that validates tool invocations against policy constraints before execution, preventing unauthorized calls or unsafe parameter values.

The workflow is split into buildtime (policy analysis and code generation) and runtime (guard execution). At buildtime, you provide a policy document and a set of tools (as Python functions or OpenAPI specs), and the package uses an LLM to extract policy requirements, generate test cases, and produce executable guard code. At runtime, you load the generated guards and invoke tools through a guard wrapper that checks preconditions before allowing execution. The package depends on langchain-core, litellm, pydantic, and testing utilities to orchestrate LLM calls, manage tool schemas, and validate generated code.

Use it for

  • Enforce financial transaction limits or approval workflows in agent-driven banking systems before tools execute.
  • Prevent unauthorized data access by validating agent tool calls against role-based policies before database queries run.
  • Block division-by-zero or invalid parameter combinations in computational tools by checking preconditions deterministically.
  • Ensure compliance with data residency or privacy policies by guarding tool invocations that access sensitive data.
  • Generate audit trails of policy checks by logging guard evaluations before tool execution.
  • Validate multi-step agent workflows against operational constraints (e.g., 'do not multiply if operand KDI value equals X').

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you need deterministic policy enforcement on AI agent tools and can invest in the buildtime setup (policy document, LLM configuration, tool specs).

The package is actively maintained, has low install friction, and solves a real problem in agentic systems. Not suitable if you need runtime-only policy injection without code generation, or if you lack access to an LLM provider for the buildtime phase.

Install

toolguard on PyPI

Before you install

Low install friction with a pure Python wheel. Active maintenance (45 days since latest release). Depends on 12 runtime packages including langchain-core, litellm, pydantic, and pytest utilities—a substantial but standard AI/LLM stack.

Requires Python 3.10+. Buildtime API requires an LLM provider (e.g., Azure OpenAI) configured via litellm. Policy documents and tool OpenAPI specs must be provided.

License in practice

Apache License 2.0 (permissive). You may use, modify, and distribute this package freely in commercial and private projects, provided you include the license and document any changes.

Quickstart

pip install toolguard

from toolguard.buildtime import generate_guard_specs, LitellmModel
from toolguard.runtime import load_toolguards, ToolFunctionsInvoker

# Step 1: Generate specs from policy document and tools
specs = await generate_guard_specs(policy_text, tools, llm=llm_model)

# Step 2: Generate guard code
guards = await generate_guards_code(tool_specs=specs, tools=tools, llm=llm_model)

# Step 3: Load and use at runtime
with load_toolguards("output") as toolguard:
    invoker = ToolFunctionsInvoker(tools)
    await toolguard.guard_toolcall("tool_name", {"param": value}, invoker)

Verify before relying

  • Whether the generated guard code is guaranteed to be deterministic or only intended to be so in practice.
  • Performance overhead of guard evaluation at runtime for large numbers of tools or complex policies.
  • How well the tool handles edge cases in policy interpretation or ambiguous policy language.
  • Support for dynamic policy updates without regenerating all guard code.

Package facts

Licensepermissive license permissive
Python supportSupports the current Python release <3.15,>=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
12 packages
datamodel-code-generatorfastmcplangchain-corelitellmlogurumarkdownpydanticpyrightpytest-asynciopytest-json-reportpytestsmolagents
MaintenanceActively maintained 45 days since the last release
First released
Downloads171,769 / month, #10,356 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
License :: OSI Approved :: Apache Software LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3

Evidence: toolguard-0.2.21-py3-none-any.whl

Tags

Capabilities
ai agent policy enforcementtool guard constraintspolicy compliance code generationagent tool preconditionsbusiness policy guardrailsdeterministic policy validationagent tool policy checks
Topics
agent-guardrailspolicy-as-codellm-codegen

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “tool guard constraints”

  • toolguardGenerates deterministic Python code that enforces business policy…
  • tdd-guard-pytestA pytest plugin that captures test results and integrates them with…
  • phantom-typesPhantom types enable you to create type-safe wrappers around base…

Give your agent the search over MCP, or paste the wish link into any chat.

More Artificial Intelligence packages

litellm With conditions
PyPI · Artificial Intelligence · released Aug 2026

LiteLLM provides a unified Python interface to call 100+ LLM providers (OpenAI, Anthropic, Gemini, Bedrock, Azure, and others) using OpenAI-compatible API format, available as both a Python SDK and a self-hosted AI Gateway proxy server.

Install it if you need to work with multiple LLM providers or want to centralize LLM routing in your organization.

MITcompiled wheel
682.8Mdownloads / mo
huggingface-hub Worth it
PyPI · Artificial Intelligence · released Aug 2026

Client library and CLI tool for downloading, uploading, and managing models, datasets, and repositories on the Hugging Face Hub platform.

Install it if you work with Hugging Face Hub models or datasets.

Apache-2.0pure Python · 3.10.0+
442.4Mdownloads / mo
langchain Worth it
PyPI · Python Modules · released Aug 2026

LangChain provides a framework for building agents and LLM-powered applications by composing language models, tools, and memory through a unified API that abstracts over multiple model providers.

MITpure Python
315.4Mdownloads / mo
hf-xet With conditions
PyPI · Artificial Intelligence · released Aug 2026

hf-xet provides chunk-based deduplication and efficient file transfer for the Hugging Face Hub, enabling faster uploads and downloads of large files with local disk caching.

Apache-2.0compiled wheel · 3.8+
258.4Mdownloads / mo
tokenizers Worth it
PyPI · Artificial Intelligence · released Apr 2026

Tokenizers converts raw text into token sequences for NLP models, with support for training custom vocabularies and using pre-built tokenizers (BPE, WordPiece) optimized for speed via Rust.

Apache-2.0compiled wheel · 3.10+
222.9Mdownloads / mo
transformers Worth it
PyPI · Artificial Intelligence · released Aug 2026

Transformers provides a unified framework for loading, fine-tuning, and running state-of-the-art pretrained models across text, vision, audio, video, and multimodal tasks using PyTorch, JAX, or TensorFlow.

Install it if you need to run or train any transformer-based model for NLP, vision, audio, or multimodal tasks.

permissive licensepure Python · 3.10.0+
186.6Mdownloads / mo

See also datarobot-moderations · guardrails-ai · regopy · pydantic-ai-shields · llm-guard · pulumi-policy · agentops · microsoft-agents-a365-observability-core · datarobot-genai · agent_governance_toolkit

Further reading