Rank
65
LangChain/LangGraph tools for AI agent x402 payments on X1
Traction
No public download signal
Freshness
Updated 4mo ago
Crawler Summary
Privacy audit for multi-agent AI systems (CrewAI · LangGraph · AutoGen) — detect compositional data leaks without the central auditor ever seeing raw content. Federated Agent Audit **Privacy audit for multi-agent AI systems — without touching raw data.** $1 $1 $1 $1 $1 $1 Audit multi-agent systems (CrewAI · LangGraph · AutoGen · OpenAI Agents) for compositional privacy leaks the central auditor can never see the raw data behind. --- 30-Second Quick Start Scan any text for sensitive content: Or from the command line: Protect Your LLM Calls Intercept every OpenAI/Anthropic r Capability contract not published. No trust telemetry is available yet. 2 GitHub stars reported by the source. Last updated 5/30/2026.
Freshness
Last checked 5/30/2026
Best For
federated-agent-audit is best for crewai, multi-agent workflows where OpenClaw compatibility matters.
Not Ideal For
Contract metadata is missing or unavailable for deterministic execution.
Evidence Sources Checked
editorial-content, GITHUB REPOS, runtime-metrics, public facts pack
Privacy audit for multi-agent AI systems (CrewAI · LangGraph · AutoGen) — detect compositional data leaks without the central auditor ever seeing raw content. Federated Agent Audit **Privacy audit for multi-agent AI systems — without touching raw data.** $1 $1 $1 $1 $1 $1 Audit multi-agent systems (CrewAI · LangGraph · AutoGen · OpenAI Agents) for compositional privacy leaks the central auditor can never see the raw data behind. --- 30-Second Quick Start Scan any text for sensitive content: Or from the command line: Protect Your LLM Calls Intercept every OpenAI/Anthropic r
Public facts
4
Change events
0
Artifacts
0
Freshness
May 30, 2026
Capability contract not published. No trust telemetry is available yet. 2 GitHub stars reported by the source. Last updated 5/30/2026.
Trust score
Unknown
Compatibility
OpenClaw
Freshness
May 30, 2026
Vendor
Justin0504
Artifacts
0
Benchmarks
0
Last release
Unpublished
Key links, install path, and a quick operational read before the deeper crawl record.
Summary
Capability contract not published. No trust telemetry is available yet. 2 GitHub stars reported by the source. Last updated 5/30/2026.
Setup snapshot
Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Everything public we have scraped or crawled about this agent, grouped by evidence type with provenance.
Vendor
Justin0504
Protocol compatibility
OpenClaw
Adoption signal
2 GitHub stars
Handshake status
UNKNOWN
Merged public release, docs, artifact, benchmark, pricing, and trust refresh events.
Extracted files, examples, snippets, parameters, dependencies, permissions, and artifact metadata.
Extracted files
0
Examples
6
Snippets
0
Languages
python
text
pip install federated-agent-audit
python
from federated_agent_audit import scan
result = scan("Zhang Wei's SSN is 123-45-6789, salary $185,000")
print(result["clean"]) # False
print(result["detected"]) # ['SSN', 'salary']
print(result["text"]) # "Zhang Wei's [REDACTED] is [SSN], [REDACTED] [DOLLAR_AMOUNT]"bash
federated-audit scan "My email is [email protected]" # REDACTED Detected: email # Output: My [REDACTED] is [EMAIL_ADDRESS] echo "credit card 4532-1234-5678-9012" | federated-audit scan # REDACTED Detected: credit card
python
from federated_agent_audit import firewall fw = firewall(["salary", "SSN", "diagnosis"]) fw.patch_openai() # done — every response is now checked # Normal usage — firewall is invisible response = client.chat.completions.create(model="gpt-4o", messages=[...]) # Sensitive content in response is already redacted
text
+---------------+
| Central | Phase 2: Network audit
| Auditor | (desensitized metadata only)
+-------+-------+
|
+---------------+---------------+
| | |
+------+------+ +----+----+ +--------+------+
| Local Audit | | Local | | Local Audit | Phase 1
| (Agent A) | | (Agt B) | | (Agent C) |
+-------------+ +---------+ +---------------+
raw content raw content raw content
stays here stays here stays herepython
from federated_agent_audit import (
FederatedAudit, PrivacyPolicy, NetworkAuditor,
RiskAggregator, ComplianceEngine,
)
# 1. Define policies
policy_hr = PrivacyPolicy(agent_id="hr_bot", must_not_share=["salary", "SSN"])
policy_ext = PrivacyPolicy(agent_id="notify_bot", must_not_share=["salary", "SSN", "email"])
# 2. Record interactions (each agent audits locally)
audit_hr = FederatedAudit(policy=policy_hr)
audit_hr.record_outgoing("Zhang Wei earns $185k", to_agent="summary_bot")
audit_ext = FederatedAudit(policy=policy_ext)
audit_ext.record_outgoing("Candidate update sent", to_agent="external")
# 3. Central audit (only sees desensitized metadata — never raw text)
net = NetworkAuditor()
net.ingest_report(audit_hr.get_report())
net.ingest_report(audit_ext.get_report())
result = net.audit()
# 4. Compliance check
compliance = ComplianceEngine(eu_users=True).evaluate(result)
print(f"Compliance: {compliance.overall_score:.0%} — {compliance.status.value}")
for gap in compliance.gaps():
print(f" {gap.regulation} {gap.article}: {gap.title}")Full documentation captured from public sources, including the complete README when available.
Docs source
GITHUB REPOS
Editorial quality
ready
Privacy audit for multi-agent AI systems (CrewAI · LangGraph · AutoGen) — detect compositional data leaks without the central auditor ever seeing raw content. Federated Agent Audit **Privacy audit for multi-agent AI systems — without touching raw data.** $1 $1 $1 $1 $1 $1 Audit multi-agent systems (CrewAI · LangGraph · AutoGen · OpenAI Agents) for compositional privacy leaks the central auditor can never see the raw data behind. --- 30-Second Quick Start Scan any text for sensitive content: Or from the command line: Protect Your LLM Calls Intercept every OpenAI/Anthropic r
Privacy audit for multi-agent AI systems — without touching raw data.
pip install federated-agent-audit
Audit multi-agent systems (CrewAI · LangGraph · AutoGen · OpenAI Agents) for compositional privacy leaks the central auditor can never see the raw data behind.
Scan any text for sensitive content:
from federated_agent_audit import scan
result = scan("Zhang Wei's SSN is 123-45-6789, salary $185,000")
print(result["clean"]) # False
print(result["detected"]) # ['SSN', 'salary']
print(result["text"]) # "Zhang Wei's [REDACTED] is [SSN], [REDACTED] [DOLLAR_AMOUNT]"
Or from the command line:
federated-audit scan "My email is [email protected]"
# REDACTED Detected: email
# Output: My [REDACTED] is [EMAIL_ADDRESS]
echo "credit card 4532-1234-5678-9012" | federated-audit scan
# REDACTED Detected: credit card
Intercept every OpenAI/Anthropic response automatically:
from federated_agent_audit import firewall
fw = firewall(["salary", "SSN", "diagnosis"])
fw.patch_openai() # done — every response is now checked
# Normal usage — firewall is invisible
response = client.chat.completions.create(model="gpt-4o", messages=[...])
# Sensitive content in response is already redacted
Multi-agent systems (CrewAI, LangGraph, AutoGen, OpenAI Agents) create compound privacy risks that single-agent tools can't detect:
Existing observability tools (LangSmith, Langfuse) require uploading raw prompts to their servers. This framework audits agent interactions without the central auditor ever seeing raw content.
📖 Worked case study — a leak that emerges only from combining two policy-compliant agents, caught with the raw PHI/PII never leaving the agents' environments (python examples/case_study_healthcare_leak.py).
+---------------+
| Central | Phase 2: Network audit
| Auditor | (desensitized metadata only)
+-------+-------+
|
+---------------+---------------+
| | |
+------+------+ +----+----+ +--------+------+
| Local Audit | | Local | | Local Audit | Phase 1
| (Agent A) | | (Agt B) | | (Agent C) |
+-------------+ +---------+ +---------------+
raw content raw content raw content
stays here stays here stays here
from federated_agent_audit import (
FederatedAudit, PrivacyPolicy, NetworkAuditor,
RiskAggregator, ComplianceEngine,
)
# 1. Define policies
policy_hr = PrivacyPolicy(agent_id="hr_bot", must_not_share=["salary", "SSN"])
policy_ext = PrivacyPolicy(agent_id="notify_bot", must_not_share=["salary", "SSN", "email"])
# 2. Record interactions (each agent audits locally)
audit_hr = FederatedAudit(policy=policy_hr)
audit_hr.record_outgoing("Zhang Wei earns $185k", to_agent="summary_bot")
audit_ext = FederatedAudit(policy=policy_ext)
audit_ext.record_outgoing("Candidate update sent", to_agent="external")
# 3. Central audit (only sees desensitized metadata — never raw text)
net = NetworkAuditor()
net.ingest_report(audit_hr.get_report())
net.ingest_report(audit_ext.get_report())
result = net.audit()
# 4. Compliance check
compliance = ComplianceEngine(eu_users=True).evaluate(result)
print(f"Compliance: {compliance.overall_score:.0%} — {compliance.status.value}")
for gap in compliance.gaps():
print(f" {gap.regulation} {gap.article}: {gap.title}")
| Risk | What happens | How we catch it | |------|-------------|-----------------| | Cross-domain leak | Health data reaches social media agent | Domain boundary analysis on metadata | | Compositional inference | Agent collects health + identity = reidentification | Quasi-identifier assembly detection | | Aggregation attack | 3 agents each share a fragment → hub reconstructs full profile | Multi-source convergence analysis | | Cascading injection | Prompt injection propagates agent-to-agent like a worm | Infection tree + patient-zero attribution | | Behavioral drift | Agent suddenly changes behavior (possible compromise) | Cross-session z-score monitoring | | Negative inference | "I can't share that" confirms the data exists | Refusal pattern detection | | Regulatory gap | EU AI Act / GDPR / COPPA requirements unmet | Per-article compliance scoring |
# Scan text for sensitive content
federated-audit scan "Patient SSN is 123-45-6789"
echo "salary: $200k" | federated-audit scan --protect salary
# Validate policy files
federated-audit validate policies/*.yaml
# Run a demo
federated-audit demo
# Start the central audit server
federated-audit server --port 8000
# policies/hr_bot.yaml
agent_id: hr_bot
must_not_share:
- salary
- SSN
- performance review
acceptable_abstractions:
salary: compensation level
SSN: employee identifier
sensitivity_threshold: 3
from federated_agent_audit import load_policy
policy = load_policy("policies/hr_bot.yaml")
Built-in regulatory mapping for EU AI Act, GDPR, CA SB 243, and COPPA:
from federated_agent_audit import ComplianceEngine
engine = ComplianceEngine(eu_users=True, california_users=True, involves_children=False)
report = engine.evaluate(audit_result)
print(report.overall_score) # 0.0 - 1.0
print(report.status) # compliant / partial / non_compliant
for gap in report.gaps():
print(f"{gap.regulation} {gap.article}: {gap.remediation}")
The integrations capture the real agent-to-agent interaction graph — who
sent what to whom — which is exactly what the compositional / cascade /
cross-domain detectors analyze. Everything is built on MultiAgentTracer,
which works with any framework (or none):
from federated_agent_audit import MultiAgentTracer, PrivacyPolicy
tracer = MultiAgentTracer()
tracer.register_agent("hr_bot", PrivacyPolicy(agent_id="hr_bot", must_not_share=["salary"]))
# Each call is a real directed edge; taint (domains, sensitivity, origin,
# hop count) propagates across hops automatically.
tracer.record_handoff("hr_bot", "summary_bot", "Zhang Wei earns $185k", origin="zhang_wei")
tracer.record_handoff("summary_bot", "external_bot", "candidate compensation summary")
result = tracer.network_audit() # Phase-2 central audit
incidents = tracer.aggregated() # denoised, actionable alerts
It catches the compound leak no single agent's policy can see — and the central
auditor still never touched the raw data (python examples/multiagent_trace_demo.py):
Incidents: 5 alert_summary={'critical': 3, 'high': 2}
[CRITICAL] cross_domain_leak — Sensitive health data reaches social domain via 2-agent chain
[CRITICAL] cross_domain_leak — Sensitive finance data reaches social domain via 2-agent chain
[CRITICAL] taint_spreading — Data from origin 'zhang_wei' spread to 4 agents across the network
[HIGH] inference_accumulation — external_bot accumulated high inference risk (77%)
[HIGH] compound_scope_escalation — 3 agent pairs exceed authorized scope
Privacy verification (central reports): hr_bot → clean health_bot → clean summary_bot → clean
# CrewAI — captures agent delegation (Delegate/Ask coworker) as A→B edges
from federated_agent_audit.sdk import crew_audit
crew = crew_audit(crew, default_policy=policy) # or policies={role: policy}
crew.kickoff()
result = crew._federated_tracer.network_audit()
# LangChain / LangGraph — per-node identity + node-to-node hand-offs
from federated_agent_audit.sdk import langchain_callback
handler = langchain_callback(default_policy=policy) # asynchronous=True for async graphs
graph.invoke(input, config={"callbacks": [handler]})
result = handler.tracer.network_audit()
# AutoGen / AG2 — hooks every agent-to-agent message
from federated_agent_audit.sdk import autogen_audit
tracer = autogen_audit([assistant, user_proxy, critic], default_policy=policy)
user_proxy.initiate_chat(assistant, message="...")
result = tracer.network_audit()
# OpenAI Agents SDK — captures first-class handoffs
from federated_agent_audit.sdk import openai_agents_hooks
hooks = openai_agents_hooks(default_policy=policy)
await Runner.run(triage_agent, input="...", hooks=hooks)
result = hooks.tracer.network_audit()
# Generic Python — single-agent decorator
from federated_agent_audit import audited
@audited(policy, to_agent="downstream")
def my_agent(input_text: str) -> str:
return process(input_text)
The LLM firewall hardens this for production — fail-open (audit never crashes the app), streaming responses blocked the moment a violation accumulates, and sensitive content inspected inside tool-call arguments:
from federated_agent_audit import firewall
fw = firewall(["salary", "SSN"]); fw.patch_openai() # streaming + tool calls covered
pip install federated-agent-audit # core
pip install "federated-agent-audit[transport]" # + audit server
pip install "federated-agent-audit[yaml]" # + YAML policies
pip install "federated-agent-audit[langchain]" # + LangChain
pip install "federated-agent-audit[all]" # everything
48 modules · 597 tests · 0 external API calls required
Local (Phase 1): Network (Phase 2):
PrivacyGate (regex + PII) Cross-domain flow detection
SemanticDetector (4-tier) Compositional leak detection
TaintTracker (info flow) Cascade infection tracking
Desensitizer (6-layer) Topology analysis
MemoryAuditor (write audit) Blame attribution
Compliance engine
Privacy guarantee: The central auditor architecturally cannot see raw content. Data is hashed, pseudonymized, and DP-noised before leaving local agents. Merkle tree commitments ensure tamper-proof audit trails without revealing entries.
A labeled benchmark of multi-agent scenarios (real compositional leaks vs. benign traffic) measures detection quality, not just speed:
python benchmarks/detection_eval.py # precision / recall / F1
python benchmarks/detection_eval.py --sweep # threshold robustness
On the current scenario set (15 leak + 12 benign, incl. adversarial cases:
noise-buried leaks, diamond multi-path, partial-shared-origin hubs, same-domain
laundering, an injection worm, sensitivity under-reporting evasion, high-volume
benign hubs, cross-subject convergence) the pipeline reaches precision 1.0 /
recall 1.0 / F1 1.0 with zero raw-content leakage into central reports,
stable across thresholds 0.3–0.8. Pure structural signals
(topology, timing, behavioral) are reported separately and not counted as
privacy-leak detections. The harness is the place to add adversarial scenarios;
tests/test_detection_benchmark.py locks the metrics as a regression gate.
Validated live against LangGraph (free, in-suite) and CrewAI + OpenAI streaming (opt-in examples, need an API key).
git clone https://github.com/Justin0504/federated-agent-audit
cd federated-agent-audit
pip install -e ".[dev,transport,yaml]"
pytest # 597 tests
ruff check src/ tests/ # lint
python examples/crewai_audit_demo.py # run the demo
Apache 2.0
Machine endpoints, protocol fit, contract coverage, invocation examples, and guardrails for agent-to-agent use.
Contract coverage
Status
missing
Auth
None
Streaming
No
Data region
Unspecified
Protocol support
Requires: none
Forbidden: none
Guardrails
Operational confidence: low
curl -s "https://www.xpersona.co/api/v1/agents/crewai-justin0504-federated-agent-audit/snapshot"
curl -s "https://www.xpersona.co/api/v1/agents/crewai-justin0504-federated-agent-audit/contract"
curl -s "https://www.xpersona.co/api/v1/agents/crewai-justin0504-federated-agent-audit/trust"
Trust and runtime signals, benchmark suites, failure patterns, and practical risk constraints.
Trust signals
Handshake
UNKNOWN
Confidence
unknown
Attempts 30d
unknown
Fallback rate
unknown
Runtime metrics
Observed P50
unknown
Observed P95
unknown
Rate limit
unknown
Estimated cost
unknown
Do not use if
Every public screenshot, visual asset, demo link, and owner-provided destination tied to this agent.
Neighboring agents from the same protocol and source ecosystem for comparison and shortlist building.
Rank
65
LangChain/LangGraph tools for AI agent x402 payments on X1
Traction
No public download signal
Freshness
Updated 4mo ago
Rank
65
An implementation of a multi-agent swarm using LangGraph
Traction
No public download signal
Freshness
Updated 4mo ago
Rank
65
LangGraph Multi-Agent Supervisor
Traction
No public download signal
Freshness
Updated 4mo ago
Rank
65
LangChain tools for OceanBus — give your LangChain and CrewAI agents a global identity, encrypted messaging, and Yellow Pages service discovery with a single import.
Traction
No public download signal
Freshness
Updated 4mo ago
Contract JSON
{
"contractStatus": "missing",
"authModes": [],
"requires": [],
"forbidden": [],
"supportsMcp": false,
"supportsA2a": false,
"supportsStreaming": false,
"inputSchemaRef": null,
"outputSchemaRef": null,
"dataRegion": null,
"contractUpdatedAt": null,
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Invocation Guide
{
"preferredApi": {
"snapshotUrl": "https://www.xpersona.co/api/v1/agents/crewai-justin0504-federated-agent-audit/snapshot",
"contractUrl": "https://www.xpersona.co/api/v1/agents/crewai-justin0504-federated-agent-audit/contract",
"trustUrl": "https://www.xpersona.co/api/v1/agents/crewai-justin0504-federated-agent-audit/trust"
},
"curlExamples": [
"curl -s \"https://www.xpersona.co/api/v1/agents/crewai-justin0504-federated-agent-audit/snapshot\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/crewai-justin0504-federated-agent-audit/contract\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/crewai-justin0504-federated-agent-audit/trust\""
],
"jsonRequestTemplate": {
"query": "summarize this repo",
"constraints": {
"maxLatencyMs": 2000,
"protocolPreference": [
"OPENCLEW"
]
}
},
"jsonResponseTemplate": {
"ok": true,
"result": {
"summary": "...",
"confidence": 0.9
},
"meta": {
"source": "GITHUB_REPOS",
"generatedAt": "2026-10-08T22:21:34.654Z"
}
},
"retryPolicy": {
"maxAttempts": 3,
"backoffMs": [
500,
1500,
3500
],
"retryableConditions": [
"HTTP_429",
"HTTP_503",
"NETWORK_TIMEOUT"
]
}
}Trust JSON
{
"status": "unavailable",
"handshakeStatus": "UNKNOWN",
"verificationFreshnessHours": null,
"reputationScore": null,
"p95LatencyMs": null,
"successRate30d": null,
"fallbackRate": null,
"attempts30d": null,
"trustUpdatedAt": null,
"trustConfidence": "unknown",
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Capability Matrix
{
"rows": [
{
"key": "OPENCLEW",
"type": "protocol",
"support": "unknown",
"confidenceSource": "profile",
"notes": "Listed on profile"
},
{
"key": "crewai",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "multi-agent",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
}
],
"flattenedTokens": "protocol:OPENCLEW|unknown|profile capability:crewai|supported|profile capability:multi-agent|supported|profile"
}Facts JSON
[
{
"factKey": "vendor",
"label": "Vendor",
"value": "Justin0504",
"category": "vendor",
"href": "https://github.com/Justin0504/federated-agent-audit",
"sourceUrl": "https://github.com/Justin0504/federated-agent-audit",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-05-30T06:41:20.258Z",
"isPublic": true,
"metadata": {}
},
{
"factKey": "protocols",
"label": "Protocol compatibility",
"value": "OpenClaw",
"category": "compatibility",
"href": "https://www.xpersona.co/api/v1/agents/crewai-justin0504-federated-agent-audit/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/crewai-justin0504-federated-agent-audit/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-05-30T06:41:20.258Z",
"isPublic": true,
"metadata": {}
},
{
"factKey": "traction",
"label": "Adoption signal",
"value": "2 GitHub stars",
"category": "adoption",
"href": "https://github.com/Justin0504/federated-agent-audit",
"sourceUrl": "https://github.com/Justin0504/federated-agent-audit",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-05-30T06:41:20.258Z",
"isPublic": true,
"metadata": {}
},
{
"factKey": "handshake_status",
"label": "Handshake status",
"value": "UNKNOWN",
"category": "security",
"href": "https://www.xpersona.co/api/v1/agents/crewai-justin0504-federated-agent-audit/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/crewai-justin0504-federated-agent-audit/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true,
"metadata": {}
}
]Change Events JSON
[]
Sponsored
Ads related to federated-agent-audit and adjacent AI workflows.