Arcezia

Arcezia / Integrations / CrewAI, AutoGen, LlamaIndex

CrewAI, AutoGen and LlamaIndex: check each tool call before it runs

Arcezia ships hookups for CrewAI, AutoGen and LlamaIndex, and a decorator for any Python function. Each checks the call before the tool runs.

Setup

Before this: install the SDK, get a key and register a contract for your tool, as in Quickstart steps 1 to 5. SQL below is the contract domain from that Quickstart, and private_key is your signing key. Make one client and open the session:

from arcezia import Arcezia

az = Arcezia(task="look up orders", on_error="review", signing_key=private_key)
az.start_session(capability_envelope={
    "allowed_domains": [SQL],
    "allowed_action_types": ["execute_sql"],
    "resource_scope": ["orders"],
})

CrewAI

from arcezia.integrations.openai import ArceziaCrewTool

class SafeDBTool(ArceziaCrewTool):
    az = az
    domain = SQL
    name = "execute_sql"
    description = "Run SQL"
    def _run(self, query: str) -> str:
        return db.execute(query)          # never reached on REVIEW or BLOCK

AutoGen, LlamaIndex and your own loop

from arcezia.integrations.autogen import ArceziaAutoGenGuard
safe_sql = ArceziaAutoGenGuard(az).wrap("execute_sql", db.execute, domain=SQL)   # wrap_async for 0.4

from arcezia.integrations.llamaindex import ArceziaLlamaToolkit
safe = ArceziaLlamaToolkit(az).wrap([sql_tool], domain_overrides={"execute_sql": SQL})

from arcezia.integrations.openclaw import DispatchGuard
DispatchGuard(az, domain=SQL).dispatch("execute_sql", {"query": "..."},
                                       fn=lambda **kw: db.execute(kw["query"]))

Any Python function

from arcezia import guard

@guard(az, domain=SQL, action_type="execute_sql")
def execute_sql(query: str) -> str:
    return db.execute(query)
# Raises ArceziaReviewError on REVIEW, ArceziaBlockError on BLOCK.

On a new key a call usually comes back REVIEW first. The answer names what would release it, for example a contract for the tool or a signed scope for the session. See Handling the answers.

Same answers everywhere. Every hookup calls the same service with the same rules. Switching frameworks does not change a verdict.