Crawler Summary

crewai-agentlock answer-first brief

Per-tool authorization for CrewAI agents. Every tool call gated, logged, and cryptographically signed. crewai-agentlock $1 $1 $1 $1 Per-tool authorization for CrewAI agents. Every tool call gated, logged, and cryptographically signed. The Problem CrewAI registers tools permissively by default. If an agent has a tool in its tools=[...] list, it can invoke it on any input the model produces. When one agent delegates to another, permissions are not enforced at the tool level: the receiving agent runs the call with whatev Capability contract not published. No trust telemetry is available yet. Last updated 10/9/2026.

Freshness

Last checked 10/9/2026

Best For

crewai-agentlock is best for crewai, multi-agent workflows where OpenClaw compatibility matters.

Not Ideal For

Contract metadata is missing or unavailable for deterministic execution.

Evidence Sources Checked

editorial-content, GITHUB OPENCLEW, runtime-metrics, public facts pack

Agent DossierGitHubSafety: 66/100

crewai-agentlock

Per-tool authorization for CrewAI agents. Every tool call gated, logged, and cryptographically signed. crewai-agentlock $1 $1 $1 $1 Per-tool authorization for CrewAI agents. Every tool call gated, logged, and cryptographically signed. The Problem CrewAI registers tools permissively by default. If an agent has a tool in its tools=[...] list, it can invoke it on any input the model produces. When one agent delegates to another, permissions are not enforced at the tool level: the receiving agent runs the call with whatev

OpenClawself-declared

Public facts

4

Change events

1

Artifacts

0

Freshness

Oct 9, 2026

Verifiededitorial-contentNo verified compatibility signals

Capability contract not published. No trust telemetry is available yet. Last updated 10/9/2026.

Trust evidence available

Trust score

Unknown

Compatibility

OpenClaw

Freshness

Oct 9, 2026

Vendor

Webpro255

Artifacts

0

Benchmarks

0

Last release

Unpublished

Executive Summary

Key links, install path, and a quick operational read before the deeper crawl record.

Verifiededitorial-content

Summary

Capability contract not published. No trust telemetry is available yet. Last updated 10/9/2026.

Setup snapshot

git clone https://github.com/webpro255/crewai-agentlock.git
  1. 1

    Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.

  2. 2

    Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Evidence Ledger

Everything public we have scraped or crawled about this agent, grouped by evidence type with provenance.

Verifiededitorial-content
Vendor (1)

Vendor

Webpro255

profilemedium
Observed May 18, 2026Source linkProvenance
Compatibility (1)

Protocol compatibility

OpenClaw

contractmedium
Observed May 18, 2026Source linkProvenance
Security (1)

Handshake status

UNKNOWN

trustmedium
Observed unknownSource linkProvenance
Integration (1)

Crawlable docs

6 indexed pages on the official domain

search_documentmedium
Observed Apr 15, 2026Source linkProvenance

Release & Crawl Timeline

Merged public release, docs, artifact, benchmark, pricing, and trust refresh events.

Self-declaredagent-index

Artifacts Archive

Extracted files, examples, snippets, parameters, dependencies, permissions, and artifact metadata.

Self-declaredGITHUB OPENCLEW

Extracted files

0

Examples

6

Snippets

0

Languages

python

Executable Examples

bash

pip install crewai-agentlock

python

from agentlock import AgentLockPermissions, AuthorizationGate
from crewai import Agent, Crew, Task
from crewai.tools import tool
from crewai_agentlock import agentlock_session, lock_crew

@tool
def web_search(query: str) -> str:
    """Search the web."""
    return f"results for {query}"

@tool
def write_summary(topic: str) -> str:
    """Write a summary."""
    return f"summary of {topic}"

researcher = Agent(role="researcher", goal="research", backstory="A researcher.",
                   tools=[web_search, write_summary], allow_delegation=False)
writer = Agent(role="writer", goal="write", backstory="A writer.",
               tools=[write_summary], allow_delegation=False)

crew = Crew(
    agents=[researcher, writer],
    tasks=[
        Task(description="research", expected_output="notes", agent=researcher),
        Task(description="write", expected_output="text", agent=writer),
    ],
)

gate = AuthorizationGate()
lock_crew(crew, gate, permissions={
    "web_search": AgentLockPermissions(
        risk_level="medium",
        allowed_roles=["researcher"],
        rate_limit={"max_calls": 5, "window_seconds": 60},
        scope={"data_boundary": "authenticated_user_only", "max_records": 50},
    ),
    "write_summary": AgentLockPermissions(
        risk_level="low",
        allowed_roles=["researcher", "writer"],
    ),
})

with agentlock_session(user_id="u1", role="researcher", session_id="s1"):
    crew.kickoff()

python

from crewai_agentlock import agentlock_session

with agentlock_session(user_id="u1", role="researcher"):
    # Researcher delegates to writer. The session role stays "researcher",
    # so the writer subtask can call any tool the researcher can call,
    # but tools whose allowed_roles exclude "researcher" still deny.
    result = crew.kickoff()

python

from agentlock import ContextSource
from crewai_agentlock import wrap_tool

fetch = wrap_tool(
    web_fetch, gate, fetch_perms,
    context_source=ContextSource.WEB_CONTENT,  # gate resolves to UNTRUSTED
)

python

from agentlock import AgentLockPermissions

write_file_perms = AgentLockPermissions(
    risk_level="high",
    allowed_roles=["admin"],
    modify_policy={
        "enabled": True,
        "transformations": [
            {
                "type": "regex_replace",
                "field": "path",
                "pattern": r"^\.\./",
                "replacement": "",
            },
        ],
    },
)

json

{
  "receipt_id": "rcpt_a3f7c91b2d4e6f80",
  "timestamp": 1745776800.123456,
  "decision": "allow",
  "tool_name": "web_search",
  "user_id": "u1",
  "role": "researcher",
  "parameters_hash": "9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08",
  "reason": "",
  "policy_version_hash": "c2b1...",
  "context_hash": "5e88...",
  "trust_ceiling": "derived",
  "signing_key_id": "key_0a1b2c3d",
  "signature": "f3a2..."
}

Docs & README

Full documentation captured from public sources, including the complete README when available.

Self-declaredGITHUB OPENCLEW

Docs source

GITHUB OPENCLEW

Editorial quality

ready

Per-tool authorization for CrewAI agents. Every tool call gated, logged, and cryptographically signed. crewai-agentlock $1 $1 $1 $1 Per-tool authorization for CrewAI agents. Every tool call gated, logged, and cryptographically signed. The Problem CrewAI registers tools permissively by default. If an agent has a tool in its tools=[...] list, it can invoke it on any input the model produces. When one agent delegates to another, permissions are not enforced at the tool level: the receiving agent runs the call with whatev

Full README

crewai-agentlock

PyPI version License: Apache 2.0 Tests agentlock.dev

Per-tool authorization for CrewAI agents. Every tool call gated, logged, and cryptographically signed.

The Problem

CrewAI registers tools permissively by default. If an agent has a tool in its tools=[...] list, it can invoke it on any input the model produces. When one agent delegates to another, permissions are not enforced at the tool level: the receiving agent runs the call with whatever role its own configuration grants. There is no runtime layer that evaluates whether this specific call, with these parameters, by this caller, at this point in the session, should be allowed.

Benchmark

AgentLock core ships 1041 tests as of tag v1.4.0. The v1.2.1 benchmark scored 99.5/A against 222 adversarial attack vectors across 35 categories, with a single remaining failure at the model layer. Full benchmark methodology at agentlock.dev.

Install

pip install crewai-agentlock

Quick Start

from agentlock import AgentLockPermissions, AuthorizationGate
from crewai import Agent, Crew, Task
from crewai.tools import tool
from crewai_agentlock import agentlock_session, lock_crew

@tool
def web_search(query: str) -> str:
    """Search the web."""
    return f"results for {query}"

@tool
def write_summary(topic: str) -> str:
    """Write a summary."""
    return f"summary of {topic}"

researcher = Agent(role="researcher", goal="research", backstory="A researcher.",
                   tools=[web_search, write_summary], allow_delegation=False)
writer = Agent(role="writer", goal="write", backstory="A writer.",
               tools=[write_summary], allow_delegation=False)

crew = Crew(
    agents=[researcher, writer],
    tasks=[
        Task(description="research", expected_output="notes", agent=researcher),
        Task(description="write", expected_output="text", agent=writer),
    ],
)

gate = AuthorizationGate()
lock_crew(crew, gate, permissions={
    "web_search": AgentLockPermissions(
        risk_level="medium",
        allowed_roles=["researcher"],
        rate_limit={"max_calls": 5, "window_seconds": 60},
        scope={"data_boundary": "authenticated_user_only", "max_records": 50},
    ),
    "write_summary": AgentLockPermissions(
        risk_level="low",
        allowed_roles=["researcher", "writer"],
    ),
})

with agentlock_session(user_id="u1", role="researcher", session_id="s1"):
    crew.kickoff()

The writer agent cannot call web_search even though the function is importable in the same process. Authorization is enforced at the gate, not at tool registration.

Delegation Enforcement

When Agent A delegates to Agent B, Agent B inherits the intersection of its own permissions and Agent A's permissions. A child agent can never exceed the permissions of the parent that spawned it. This is enforced through the active agentlock_session() and the role bound to it for the duration of the delegated call.

from crewai_agentlock import agentlock_session

with agentlock_session(user_id="u1", role="researcher"):
    # Researcher delegates to writer. The session role stays "researcher",
    # so the writer subtask can call any tool the researcher can call,
    # but tools whose allowed_roles exclude "researcher" still deny.
    result = crew.kickoff()

The session role is the upper bound. Even if the writer's own allowed_roles would permit a sensitive tool, the session role gates the call. Delegation cannot escalate.

Untrusted Tool Output

A tool's output is recorded in the session's provenance log. By default every wrapped tool records ContextSource.TOOL_OUTPUT, which the gate resolves to DERIVED authority: trusted. Tools that return attacker-reachable text should say so, via context_source:

from agentlock import ContextSource
from crewai_agentlock import wrap_tool

fetch = wrap_tool(
    web_fetch, gate, fetch_perms,
    context_source=ContextSource.WEB_CONTENT,  # gate resolves to UNTRUSTED
)

Use an untrusted source for web fetch, document retrieval, and peer-agent output (WEB_CONTENT, RETRIEVED_DOCUMENT, PEER_AGENT). This is what arms the gate's lineage checks: with a lineage policy enabled on the sink tool, a parameter value that traces back to that tool's output but not to the user's own request is denied on provenance, not on content.

The setting is per-tool and opt-in. The default is unchanged, so existing deployments keep their current behavior.

Scope, stated plainly. The wrapper passes each call's input arguments to the provenance write, so the engine's containment linker records a cross-hop parent link whenever a call's parameters carry a prior entry's content. Decision-time checks walk those recorded links. A value laundered through an intermediate tool that was itself called with the untrusted content is therefore denied with reason param_lineage, and the denial cites the relay entry the value came through rather than the original fetch. Enforcement is no longer single-hop.

What still bounds it, stated as plainly:

  • An uncarried value produces no link. If the intermediate tool is invoked without the untrusted content, nothing was carried, no parent is recorded, and the rewritten value reaches the sink.
  • Linking requires whole-content carriage. A prior entry's entire recorded content has to appear inside one of the call's argument values and clear the engine's containment floor. A partial quotation, or a summary the model composed rather than passed through, does not link.
  • Encoded forms are measured at the engine, not here. No encoded corpus runs through this adapter, so no adapter-level claim about encoded values is made. See the engine's own limitations record.

Both directions are pinned by tests/test_carriage.py, which measures the carried session against the uncarried one rather than asserting either alone.

Decision Types

Every gate.authorize() call returns one of five decisions:

  • ALLOW: the call meets every policy. The gate issues a single-use, parameter-bound execution token and the tool runs.
  • DENY: the call fails one or more policies (role, scope, rate limit, data classification, hardening). The tool body never executes.
  • MODIFY: the call is allowed but parameters or output are transformed first. Used when a policy can sanitize the request rather than reject it.
  • DEFER: the gate cannot decide without out-of-band human review. The tool is suspended and a deferral id is returned to the caller.
  • STEP_UP: the call requires fresh authentication beyond the existing session. Triggered on first use of high-risk tools, post-denial retries, and accumulated PII access in one session.

Example of MODIFY rewriting a path before execution:

from agentlock import AgentLockPermissions

write_file_perms = AgentLockPermissions(
    risk_level="high",
    allowed_roles=["admin"],
    modify_policy={
        "enabled": True,
        "transformations": [
            {
                "type": "regex_replace",
                "field": "path",
                "pattern": r"^\.\./",
                "replacement": "",
            },
        ],
    },
)

A request with path="../etc/passwd" is rewritten to path="etc/passwd" and runs. A whitelisted-only field that fails its allowlist escalates MODIFY to DENY automatically.

Audit Trail

Every authorization decision produces an Ed25519 signed receipt:

{
  "receipt_id": "rcpt_a3f7c91b2d4e6f80",
  "timestamp": 1745776800.123456,
  "decision": "allow",
  "tool_name": "web_search",
  "user_id": "u1",
  "role": "researcher",
  "parameters_hash": "9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08",
  "reason": "",
  "policy_version_hash": "c2b1...",
  "context_hash": "5e88...",
  "trust_ceiling": "derived",
  "signing_key_id": "key_0a1b2c3d",
  "signature": "f3a2..."
}

Receipts are hash-chained. Tamper with one and the entire chain breaks.

Related

License

This package is Apache 2.0.

It depends on AgentLock, which is licensed AGPL-3.0-or-later from v1.3.0 onward, and this package requires agentlock>=1.7. Installing it therefore pulls in AGPL code, and combined use is subject to the AGPL: if you run it in a network service or distribute software built on it, the AGPL's terms apply to the combined work. Commercial licenses for AgentLock that remove the AGPL obligations are available at [email protected].

Read the AGPL and take your own advice on what it requires of you. This note is a pointer, not legal advice.

Contract & API

Machine endpoints, protocol fit, contract coverage, invocation examples, and guardrails for agent-to-agent use.

MissingGITHUB OPENCLEW

Contract coverage

Status

missing

Auth

None

Streaming

No

Data region

Unspecified

Protocol support

OpenClaw: self-declared

Requires: none

Forbidden: none

Guardrails

Operational confidence: low

No positive guardrails captured.
Invocation examples
curl -s "https://www.xpersona.co/api/v1/agents/crewai-webpro255-crewai-agentlock/snapshot"
curl -s "https://www.xpersona.co/api/v1/agents/crewai-webpro255-crewai-agentlock/contract"
curl -s "https://www.xpersona.co/api/v1/agents/crewai-webpro255-crewai-agentlock/trust"

Reliability & Benchmarks

Trust and runtime signals, benchmark suites, failure patterns, and practical risk constraints.

Missingruntime-metrics

Trust signals

Handshake

UNKNOWN

Confidence

unknown

Attempts 30d

unknown

Fallback rate

unknown

Runtime metrics

Observed P50

unknown

Observed P95

unknown

Rate limit

unknown

Estimated cost

unknown

Do not use if

Contract metadata is missing or unavailable for deterministic execution.
No benchmark suites or observed failure patterns are available.

Media & Demo

Every public screenshot, visual asset, demo link, and owner-provided destination tied to this agent.

Missingno-media
No screenshots, media assets, or demo links are available.

Related Agents

Neighboring agents from the same protocol and source ecosystem for comparison and shortlist building.

Self-declaredprotocol-neighbors
Github ReposUpdated 11h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW
Machine Appendix

Contract JSON

{
  "contractStatus": "missing",
  "authModes": [],
  "requires": [],
  "forbidden": [],
  "supportsMcp": false,
  "supportsA2a": false,
  "supportsStreaming": false,
  "inputSchemaRef": null,
  "outputSchemaRef": null,
  "dataRegion": null,
  "contractUpdatedAt": null,
  "sourceUpdatedAt": null,
  "freshnessSeconds": null
}

Invocation Guide

{
  "preferredApi": {
    "snapshotUrl": "https://www.xpersona.co/api/v1/agents/crewai-webpro255-crewai-agentlock/snapshot",
    "contractUrl": "https://www.xpersona.co/api/v1/agents/crewai-webpro255-crewai-agentlock/contract",
    "trustUrl": "https://www.xpersona.co/api/v1/agents/crewai-webpro255-crewai-agentlock/trust"
  },
  "curlExamples": [
    "curl -s \"https://www.xpersona.co/api/v1/agents/crewai-webpro255-crewai-agentlock/snapshot\"",
    "curl -s \"https://www.xpersona.co/api/v1/agents/crewai-webpro255-crewai-agentlock/contract\"",
    "curl -s \"https://www.xpersona.co/api/v1/agents/crewai-webpro255-crewai-agentlock/trust\""
  ],
  "jsonRequestTemplate": {
    "query": "summarize this repo",
    "constraints": {
      "maxLatencyMs": 2000,
      "protocolPreference": [
        "OPENCLEW"
      ]
    }
  },
  "jsonResponseTemplate": {
    "ok": true,
    "result": {
      "summary": "...",
      "confidence": 0.9
    },
    "meta": {
      "source": "GITHUB_OPENCLEW",
      "generatedAt": "2026-10-10T05:49:40.486Z"
    }
  },
  "retryPolicy": {
    "maxAttempts": 3,
    "backoffMs": [
      500,
      1500,
      3500
    ],
    "retryableConditions": [
      "HTTP_429",
      "HTTP_503",
      "NETWORK_TIMEOUT"
    ]
  }
}

Trust JSON

{
  "status": "unavailable",
  "handshakeStatus": "UNKNOWN",
  "verificationFreshnessHours": null,
  "reputationScore": null,
  "p95LatencyMs": null,
  "successRate30d": null,
  "fallbackRate": null,
  "attempts30d": null,
  "trustUpdatedAt": null,
  "trustConfidence": "unknown",
  "sourceUpdatedAt": null,
  "freshnessSeconds": null
}

Capability Matrix

{
  "rows": [
    {
      "key": "OPENCLEW",
      "type": "protocol",
      "support": "unknown",
      "confidenceSource": "profile",
      "notes": "Listed on profile"
    },
    {
      "key": "crewai",
      "type": "capability",
      "support": "supported",
      "confidenceSource": "profile",
      "notes": "Declared in agent profile metadata"
    },
    {
      "key": "multi-agent",
      "type": "capability",
      "support": "supported",
      "confidenceSource": "profile",
      "notes": "Declared in agent profile metadata"
    }
  ],
  "flattenedTokens": "protocol:OPENCLEW|unknown|profile capability:crewai|supported|profile capability:multi-agent|supported|profile"
}

Facts JSON

[
  {
    "factKey": "vendor",
    "label": "Vendor",
    "value": "Webpro255",
    "category": "vendor",
    "href": "https://github.com/webpro255/crewai-agentlock",
    "sourceUrl": "https://github.com/webpro255/crewai-agentlock",
    "sourceType": "profile",
    "confidence": "medium",
    "observedAt": "2026-05-18T06:45:04.186Z",
    "isPublic": true,
    "metadata": {}
  },
  {
    "factKey": "protocols",
    "label": "Protocol compatibility",
    "value": "OpenClaw",
    "category": "compatibility",
    "href": "https://www.xpersona.co/api/v1/agents/crewai-webpro255-crewai-agentlock/contract",
    "sourceUrl": "https://www.xpersona.co/api/v1/agents/crewai-webpro255-crewai-agentlock/contract",
    "sourceType": "contract",
    "confidence": "medium",
    "observedAt": "2026-05-18T06:45:04.186Z",
    "isPublic": true,
    "metadata": {}
  },
  {
    "factKey": "docs_crawl",
    "label": "Crawlable docs",
    "value": "6 indexed pages on the official domain",
    "category": "integration",
    "href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
    "sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
    "sourceType": "search_document",
    "confidence": "medium",
    "observedAt": "2026-04-15T05:03:46.393Z",
    "isPublic": true,
    "metadata": {}
  },
  {
    "factKey": "handshake_status",
    "label": "Handshake status",
    "value": "UNKNOWN",
    "category": "security",
    "href": "https://www.xpersona.co/api/v1/agents/crewai-webpro255-crewai-agentlock/trust",
    "sourceUrl": "https://www.xpersona.co/api/v1/agents/crewai-webpro255-crewai-agentlock/trust",
    "sourceType": "trust",
    "confidence": "medium",
    "observedAt": null,
    "isPublic": true,
    "metadata": {}
  }
]

Change Events JSON

[
  {
    "eventType": "docs_update",
    "title": "Docs refreshed: Sign in to GitHub · GitHub",
    "description": "Fresh crawlable documentation was indexed for the official domain.",
    "href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
    "sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
    "sourceType": "search_document",
    "confidence": "medium",
    "observedAt": "2026-04-15T05:03:46.393Z",
    "isPublic": true,
    "metadata": {}
  }
]

Sponsored

Ads related to crewai-agentlock and adjacent AI workflows.