Skip to main content
New

2 minute read

Trooth command-line tool 0.13.0: the guard for agent actions, and what each public record reading rests on

The Trooth guard runs inside your agent and, before a consequential action, checks the counterparty's signed Trooth records and applies your written policy, answering allow, hold for a person, or deny. Each public record reading now names how each binding is proven, how fresh each class of evidence is, and what changed since the previous reading.

What changed

trooth guard decide, hook, ci and cache, and the trooth/guard library, check a counterparty's signed Trooth records on your machine before your agent acts: each signature, the status of the key when it signed, the entry in the log, the witness cosignatures, the freshness of each fact, and that the signed subject is the host the action names. The guard then applies your written policy and answers allow, hold for a person, or deny, with reason codes. Missing, stale or disputed evidence holds; only a failed proof or a rule you marked absolute denies. A failure to decide is a hold, never an allow, and the action is never sent to Trooth. trooth guard decide exits 0 for allow, 20 for hold and 21 for deny; trooth guard ci exits 22 when a change adds a destination host the policy does not list. Adapters cover the OpenAI Agents software development kit (SDK), LangChain, LangGraph, plain HTTP and Claude Code, and a Python package covers CrewAI and the other Python frameworks. The guard's decision and the policy it reads each have a published JSON Schema, a machine-readable description of every field. Each public record reading now records the method that proves each binding, the classes of evidence it read with their freshness and what each does not establish, and how it compares with the previous reading of the same domain; when the legal entity has changed, the two readings are never merged.

Why it changed

An agent can be told to pay or send data to a company it has never dealt with, and the instruction can come from text the agent read. A check that runs on your own machine, reads only signed and logged evidence and applies your written rules puts a person in front of the action whenever the evidence falls short. A reading that names the proof behind each binding, how long its evidence stays fresh and what changed lets a reader judge it.

Who is affected

  • Affected: Anyone whose agent pays, signs, sends data or opens accounts with other companies, and anyone relying on a company's public record.
  • Availability: npm, as trooth 0.13.0, with the trooth/guard library and its adapters. No account.
  • Release stage: Available.
  • Areas: CLI, API.

What to do

No action required. Nothing is required. To try the guard, write a policy as docs/GUARD.md describes and run trooth guard decide, or add trooth guard hook to Claude Code.

Versions and migration

  • trooth: 0.13.0

Dates

  • Announced: October 7, 2026, the day this entry was written. Entries are never backdated.
  • Released: October 7, 2026.

What this does not fix

An outside security review of the guard and production use by teams outside Trooth are still open. The guard decides about one action under your policy and does not say whether a company is safe. Domain control is not yet a signed claim, so a rule that requires it holds. A name match in a sanctions list or SAM.gov is not an identification.

Read more

Follow what changes at Trooth

Every entry by email, or a feed narrowed to one area or to the changes that need you to act.

Product updates by email

Occasional notes when something on this page changes. You get one confirmation email when you subscribe, every email carries an unsubscribe link, and the address is never sold or shared.

RSSCLI onlyNeeds action

View as agent