Developers · SDK
The AgentSafe Guard SDK
A zero-dependency drop-in for any Node agent (OpenClaw, LangChain, custom). It signs, calls the gate, and refuses blocked or escalated actions — so governance is decided by policy, never by the LLM.
01
Install
@metamynd/agentsafe-guard needs only Node 18+ (built-in Ed25519 + fetch) and has no dependencies. Or scaffold a complete governed agent — login, one-call provisioning, config, and a runnable example — with npx create-metamynd-agent.
02
What the guard does
- createGuardFromConfig() — load the onboarding config
- guardTool(action, handler, mapArgs) — gate a tool
- authorize() — allow / observe / block / escalate, fail-closed
- capture() — settle an approved hold (two-phase)
- escalationStatus() — poll a human decision
- verifyKey() — prove a bring-your-own-key
- evaluateLocally() — cooperative-mode local eval
- handshake() — mutual DID proof with a service
03
Fail-closed by design
If the gate is unreachable the guard returns block, so an agent can never proceed blind. Signed request fields always override the unsigned context, so a forged context key can't slip a cheaper amount past a rule.
Example
See it in code
install.sh
# Add the guard to an existing agent
npm i @metamynd/agentsafe-guard
# …or scaffold a whole governed agent:
npx create-metamynd-agent # login → provision → runnable example
npx create-metamynd-agent --sandbox # no login, no KYB — try it instantly
npx create-metamynd-agent --byok # bring your own key (never leaves your box)