Metadata-Version: 2.4
Name: agent-egress-guard
Version: 0.2.0
Summary: Page-level egress policy for AI agents: allow reads, deny logins, signups and every unrecognised write.
Author: Alpha Quantum
License-Expression: Apache-2.0
Project-URL: Homepage, https://www.aiagentallowlist.com/egress-guard/
Project-URL: Documentation, https://www.aiagentallowlist.com/egress-guard/#docs
Project-URL: Full rule set, https://www.aiagentallowlist.com/egress-guard/#full
Keywords: ai agents,agent security,egress control,zero trust,guardrails,playwright,mitmproxy
Classifier: Programming Language :: Python :: 3
Classifier: Topic :: Security
Classifier: Intended Audience :: Developers
Requires-Python: >=3.8
Description-Content-Type: text/markdown
License-File: LICENSE
License-File: NOTICE
Provides-Extra: requests
Requires-Dist: requests; extra == "requests"
Provides-Extra: httpx
Requires-Dist: httpx; extra == "httpx"
Provides-Extra: playwright
Requires-Dist: playwright; extra == "playwright"
Provides-Extra: mitmproxy
Requires-Dist: mitmproxy; extra == "mitmproxy"
Provides-Extra: yaml
Requires-Dist: pyyaml; extra == "yaml"
Dynamic: license-file

# Agent Egress Guard (free edition)

Page-level egress policy for AI agents. Before an agent's request leaves, Egress Guard decides whether it may be sent:
reads pass, while logins, sign-ups, password resets, cloud metadata addresses and every write the policy does not
recognise are denied.

- Runs locally, standard library only, no network calls (unless you add an API key for the page-type database).
- Hooks for `requests`, `httpx`, Playwright (sync and async) and mitmproxy, plus a command-line tool.
- Same evaluation code as the AI Agent Allowlist service: with the licensed rule files loaded it returns identical
  verdicts (checked on 726,018 real URL and method pairs).
- Apache License 2.0. Free for commercial use.

Home page and documentation: https://www.aiagentallowlist.com/egress-guard/

## Install

```
python3 -m venv .venv
. .venv/bin/activate            # Windows: .venv\Scripts\activate
pip install https://www.aiagentallowlist.com/egress-guard/agent_egress_guard-0.1.0-py3-none-any.whl
```

## Try it

```
agent-egress-guard check https://example.com/login -X POST
agent-egress-guard check https://docs.python.org/3/
agent-egress-guard replay
```

`replay` runs 24 representative requests reconstructed from public 2026 AI-agent incident disclosures and shows which ones
your policy stops. The free edition denies 15 of the 18 steps that the full policy denies; the other 3 are wiki edits
sent as plain GET requests, which only the full rule set recognises.

## In Python

```python
from agent_egress_guard import Guard

guard = Guard()
v = guard.check("https://example.com/wp-login.php", "POST")
print(v.decision, v.layer, v.rule)      # deny rules login
```

requests (`pip install requests`):

```python
import requests
from agent_egress_guard import guard_requests, EgressDenied

session = guard_requests(requests.Session())
try:
    session.post("https://example.com/login", data={"user": "agent"})
except EgressDenied as e:
    print("blocked:", e.verdict.rule)
```

httpx (`pip install httpx`):

```python
import httpx
from agent_egress_guard import httpx_hook

client = httpx.Client(event_hooks={"request": [httpx_hook()]})
```

Playwright (browser agents; `pip install playwright` and `python -m playwright install chromium`):

```python
from playwright.sync_api import sync_playwright
from agent_egress_guard import guard_playwright

with sync_playwright() as p:
    browser = p.chromium.launch()
    context = browser.new_context()
    guard_playwright(context)          # denied requests are aborted
    page = context.new_page()
    page.goto("https://example.com/")
```

mitmproxy (put any agent or container behind the policy; current mitmproxy needs Python 3.12 or newer):

```
pip install mitmproxy
mitmdump -s "$(agent-egress-guard mitm-script)"
```

## How a request is decided

1. **Host list**: hosts denied or flagged whatever the page. Free: the cloud metadata addresses (169.254.169.254 in any
   notation, metadata.google.internal).
2. **Page-type database**: the domain's verified login, sign-up, checkout, upload and read pages. Needs an API key.
3. **URL rules**: patterns that recognise risky endpoints on any domain. Free: login, sign-up, password reset.
4. **Default**: GET and HEAD pass, every other method is denied.

URLs are normalised the way servers read them before any check (percent-encoded letters, `;jsessionid` path parameters,
numeric and hexadecimal IP addresses, trailing dots), so the usual encoding tricks do not get around the rules.

## Free and full edition

| | Free | Full |
|---|---|---|
| URL rules | 3 | 40 (checkout, payment, uploads, repository writes, package publishing, wiki edits, admin panels, CI/CD...) |
| Host list | 2 | 62 (cloud consoles, package registries, paste sites, deployment APIs, webhook sinks...) |
| Page-type database | no | 40.8 million domains with verified page URLs |
| Incident replay | 15 of 18 denied | 18 of 18 denied |

URL rules alone recognise fewer than half of real login pages (many sit on paths such as `/account` or `/mon-compte`);
the page-type database identifies them per domain. Load the full edition with the same code:

```python
Guard(rules_path="page_type_rules.jsonl", hosts_path="high_value_hosts.csv", api_key="YOUR_API_KEY")
```

Details and plans: https://www.aiagentallowlist.com/egress-guard/#full

## Licence

Apache License 2.0, see `LICENSE` and `NOTICE`. Copyright 2026 Alpha Quantum.
