
Portable security rules for the action boundary of AI agents
Give your agents boundaries you can read. Get decisions you can verify.
What · Quickstart · How it works · SDKs · CLI · Policies · Docs · Spec
HushSpec is an open specification for the security controls an AI agent operates under. Write a policy in YAML, evaluate it in Rust, TypeScript, Python, or Go, and produce receipts that tie each decision to the policy behind it.
It covers the things agents actually touch: files, networks, shells, tools, browsers,
and code execution. The spec defines the rules and their meaning; your runtime
enforces the boundary through HushGuard or its own integration.
| Declare | Enforce | Prove |
|---|---|---|
| Reviewable YAML with reusable base policies and explicit permissions. | Consistent allow, warn, and deny decisions at the point of action. | Decision receipts, policy signatures, and verifiable logs. |
Spec 1.0.0 is stable. The document format, evaluation semantics, canonical form, and wire formats are frozen for the 1.x series. See the versioning policy and SDK conformance matrix for the contracts and their test coverage.
The 1.0 SDK release is not yet published. See the delivery status for implementation, qualification, and release evidence.
The experimental external conformance controller tests a captured executable against the L0-L3 corpus and retains its inputs, outputs and identity. The Go adapter is first-party bring-up, not independent engine or runtime-boundary qualification.
The experimental trusted invocation coordinator checks a host-qualified MCP tool and its effects against one authenticated policy snapshot, records a durable permit, then dispatches. Its isolated coding pilot tests real edits, blocked operations and crash evidence. This is a scoped first-party demonstration, not external adoption or general MCP containment.
Build the h2h CLI from this checkout:
cargo install --path crates/hushspec-cli --locked
Save this as policy.yaml. It protects credentials, restricts network access,
and asks for confirmation before a tool can write a file or push code.
hushspec: "1.0.0"
name: production-agent
rules:
forbidden_paths:
patterns: ["**/.ssh/**", "**/.aws/**", "/etc/shadow"]
egress:
allow: ["api.openai.com", "*.anthropic.com", "api.github.com"]
default: block
tool_access:
allow: [file_read, search]
block: [shell_exec, run_command]
require_confirmation: [file_write, git_push]
default: block
Validate it, then try three decisions:
h2h validate policy.yaml
h2h eval policy.yaml --type egress --target api.openai.com
# allow
h2h eval policy.yaml --type tool_call --target shell_exec
# deny
h2h eval policy.yaml --type tool_call --target file_write
# warn: confirmation required
These commands evaluate actions; they do not execute them. eval exits with
0 for allow, 1 for deny, and 4 for warn. A runtime must handle the decision
before dispatching the action. Wire it into your agent →
| Method | Install |
|---|---|
| Cargo | cargo install hushspec-cli |
| Homebrew | brew install backbay-labs/tap/h2h |
| npm | npm install -g @hushspec/cli |
| Prebuilt binaries | GitHub Releases, with checksums and provenance attestations |
Packaged installers depend on the release pipeline having published the corresponding artifacts. The source install above builds directly from this checkout.
For a scaffolded policy and test suite, run h2h init --preset default.
See the first-policy guide for the complete workflow.
HushGuard loads the policy and brings evaluation, enforcement modes, confirmation,
receipt sinks, and observers together. Call enforce before dispatching a tool:
import { HushGuard } from '@hushspec/core';
const guard = HushGuard.fromFile('./policy.yaml');
guard.enforce({ type: 'tool_call', target: 'shell_exec' });
// Throws HushSpecDenied under the quickstart policy.
A policy that fails required signature verification produces a refused guard:
every action is denied with __hushspec_policy_unverified__. A failed hot reload
keeps the last valid policy in force. Unknown fields and invalid documents are
rejected explicitly.
The enforcement boundary is the runtime's responsibility. HushSpec supplies the portable policy contract and SDK primitives to build it. Runtime integration guide →
Audited evaluation takes a resolved policy and returns a receipt containing its
canonical content_hash, the decision, actor context, rule and detection traces,
and enforcement disposition. Action content is represented by its hash and byte
size, without embedding the raw content.
# Inspect the receipt for one evaluated action.
h2h eval policy.yaml --type egress --target api.openai.com --format receipt
The evidence can travel beyond the runtime: