Arcezia / Integrations / Anthropic tool use
Anthropic tool use: check each tool call before it runs
When Claude returns a tool_use block, check it with ArceziaAnthropicGuard before you run the tool.
Setup
Before this: install the SDK, get a key and register a contract for your tool, as in Quickstart steps 1 to 5. SQL below is the contract domain from that Quickstart, and private_key is your signing key. Make one client and open the session:
from arcezia import Arcezia
az = Arcezia(task="look up orders", on_error="review", signing_key=private_key)
az.start_session(capability_envelope={
"allowed_domains": [SQL],
"allowed_action_types": ["execute_sql"],
"resource_scope": ["orders"],
})
Check the tool use
from arcezia.integrations.anthropic import ArceziaAnthropicGuard
g = ArceziaAnthropicGuard(az, domain_map={"execute_sql": SQL})
cert = g.verify_tool_use("execute_sql", {"query": "SELECT COUNT(*) FROM orders"})
Handle the answer
cert = az.verify(action_type=tool, action_description=desc, domain=domain)
if cert.allow:
run_tool(credential=cert.credential)
elif cert.review:
for item in cert.release: # e.g. "approval:user", "check:verified_recent_backup"
handle(item) # see the table below, then check the same call again
else: # BLOCK
log.warning("refused: %s (%s)", cert.summary, cert.reason)
if cert.fabrication_detected:
alert_security(cert)
Only ALLOW may reach the tool. A REVIEW names what would release it; a BLOCK names why. Details: Handling the answers.
On a new key a call usually comes back REVIEW first. The answer names what would release it, for example a contract for the tool or a signed scope for the session. See Handling the answers.
Same answers everywhere. Every hookup calls the same service with the same rules. Switching frameworks does not change a verdict.