Arcezia / Integrations / CrewAI, AutoGen, LlamaIndex
CrewAI, AutoGen and LlamaIndex: check each tool call before it runs
Arcezia ships hookups for CrewAI, AutoGen and LlamaIndex, and a decorator for any Python function. Each checks the call before the tool runs.
Setup
Before this: install the SDK, get a key and register a contract for your tool, as in Quickstart steps 1 to 5. SQL below is the contract domain from that Quickstart, and private_key is your signing key. Make one client and open the session:
from arcezia import Arcezia
az = Arcezia(task="look up orders", on_error="review", signing_key=private_key)
az.start_session(capability_envelope={
"allowed_domains": [SQL],
"allowed_action_types": ["execute_sql"],
"resource_scope": ["orders"],
})
CrewAI
from arcezia.integrations.openai import ArceziaCrewTool
class SafeDBTool(ArceziaCrewTool):
az = az
domain = SQL
name = "execute_sql"
description = "Run SQL"
def _run(self, query: str) -> str:
return db.execute(query) # never reached on REVIEW or BLOCK
AutoGen, LlamaIndex and your own loop
from arcezia.integrations.autogen import ArceziaAutoGenGuard
safe_sql = ArceziaAutoGenGuard(az).wrap("execute_sql", db.execute, domain=SQL) # wrap_async for 0.4
from arcezia.integrations.llamaindex import ArceziaLlamaToolkit
safe = ArceziaLlamaToolkit(az).wrap([sql_tool], domain_overrides={"execute_sql": SQL})
from arcezia.integrations.openclaw import DispatchGuard
DispatchGuard(az, domain=SQL).dispatch("execute_sql", {"query": "..."},
fn=lambda **kw: db.execute(kw["query"]))
Any Python function
from arcezia import guard
@guard(az, domain=SQL, action_type="execute_sql")
def execute_sql(query: str) -> str:
return db.execute(query)
# Raises ArceziaReviewError on REVIEW, ArceziaBlockError on BLOCK.
On a new key a call usually comes back REVIEW first. The answer names what would release it, for example a contract for the tool or a signed scope for the session. See Handling the answers.
Same answers everywhere. Every hookup calls the same service with the same rules. Switching frameworks does not change a verdict.