-
Notifications
You must be signed in to change notification settings - Fork 20
Expand file tree
/
Copy path62-cli-tool-guardrails.ts
More file actions
89 lines (78 loc) · 2.97 KB
/
Copy path62-cli-tool-guardrails.ts
File metadata and controls
89 lines (78 loc) · 2.97 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
/**
* 62 - CLI Tool with Guardrails — safe command execution.
*
* Demonstrates tool-level guardrails on CLI commands. The agent can run
* whitelisted commands, but guardrails block dangerous patterns.
*
* Requirements:
* - Conductor server with LLM support
* - CONDUCTOR_SERVER_URL=http://localhost:8080/api
* - CONDUCTOR_AGENT_LLM_MODEL=openai/gpt-4o-mini
*/
import { Agent, AgentRuntime, RegexGuardrail } from '@io-orkes/conductor-javascript/agents';
import { llmModel } from './settings';
// -- Guardrails --------------------------------------------------------------
const blockDestructive = new RegexGuardrail({
patterns: [
'rm\\s+-rf\\s+/', // rm -rf /
'mkfs\\.', // mkfs.ext4, mkfs.xfs, ...
'\\bdd\\s+if=', // dd if=/dev/zero ...
],
mode: 'block',
name: 'block_destructive',
message: 'Destructive system commands are not allowed.',
onFail: 'raise', // hard stop -- no retry
});
const reviewSudo = new RegexGuardrail({
patterns: ['\\bsudo\\b'],
mode: 'block',
name: 'review_sudo',
message:
'Commands requiring sudo are not permitted. ' +
'Rewrite the command without elevated privileges.',
onFail: 'retry', // LLM gets another chance
maxRetries: 2,
});
// -- Agent -------------------------------------------------------------------
export const opsAgent = new Agent({
name: 'ops_agent',
model: llmModel,
instructions:
'You are a DevOps assistant. Use the run_command tool to help ' +
'the user inspect and manage their system. You can list files, ' +
'check disk usage, read logs, and run git commands.\n\n' +
'IMPORTANT: Never use sudo or destructive commands like rm -rf.',
cliConfig: {
enabled: true,
allowedCommands: ['ls', 'cat', 'df', 'du', 'git', 'ps', 'uname', 'wc'],
timeout: 15,
},
// Guardrails are declared at the agent level; they gate the CLI tool's input.
guardrails: [blockDestructive, reviewSudo],
});
// -- Run ---------------------------------------------------------------------
const prompt = 'Show me the disk usage summary and list files in the current directory.';
async function main() {
const runtime = new AgentRuntime();
try {
console.log('='.repeat(60));
console.log(' CLI Tool with Guardrails');
console.log(' Allowed: ls, cat, df, du, git, ps, uname, wc');
console.log(' Blocked: rm -rf, sudo, mkfs, dd');
console.log('='.repeat(60));
console.log(`\nPrompt: ${prompt}\n`);
const result = await runtime.run(opsAgent, prompt);
result.printResult();
// Production pattern:
// 1. Deploy once during CI/CD (optional -- serve() below also deploys):
// await runtime.deploy(opsAgent);
// CLI alternative:
// conductor deploy --package examples/agents --agents ops_agent
//
// 2. In a separate long-lived worker process (deploys + registers workers + starts polling):
// await runtime.serve(opsAgent);
} finally {
await runtime.shutdown();
}
}
main().catch(console.error);