Portable security rules for AI agents.
HushSpec is an open specification for declaring what an agent may access, invoke, and send at the tool boundary: one rule language across runtimes, frameworks, and languages.
hushspec: "1.0.0"
name: coding-agent-quickstart
rules:
forbidden_paths:
patterns: ["**/.env", "**/.ssh/**"]
tool_access:
allow: [read_file, search]
block: [deploy]
require_confirmation: [write_file]
default: block
Declare what, never how.
AI agents interact with tools: file systems, network APIs, shell commands, MCP servers. HushSpec is a standard way to declare which of those interactions are allowed, blocked, or require confirmation.
Policy declares the boundary. The specification defines portable decisions and evidence. Your host mediates the actual effects.
Start with the runtime integration guide to check actions before dispatch. For engines such as Clawdstrike, verify the supported policy version and capabilities in the compatibility guide.
Twelve rules, one language.
Choose from twelve rule blocks. Compose them with conditions, inheritance, and optional extensions. A valid evaluation resolves to allow, warn, or deny; invalid policies are refused before use.
Field-level documentation for every rule lives in the rules reference.
Four languages, a shared core.
All four SDKs support parsing, validation, resolution, evaluation, guards, receipts, and signing. Feature flags and lifecycle APIs differ by language. The conformance matrix separates feature availability from verified claims.
| SDK | Parse | Validate | Merge | Resolve | Evaluate | Receipts | Detection |
|---|---|---|---|---|---|---|---|
| Rust | yes | yes | yes | yes | yes | yes | yes |
| TypeScript | yes | yes | yes | yes | yes | yes | yes |
| Python | yes | yes | yes | yes | yes | yes | yes |
| Go | yes | yes | yes | yes | yes | yes | yes |
Each language has a complete, tested guard example with a denied effect and an explicitly confirmed warning. Signing requires Rust's signing feature and Python's signing extra. Full detail in the SDK conformance matrix.
The h2h command line.
h2h, hush to hush: one binary for the whole policy lifecycle. Validate, test, lint, and diff policies in CI; sign and verify them for distribution; flip the panic switch when something goes wrong.
Selected commands shown. All commands, options and exit statuses are in the CLI reference.
Rulesets, ready to extend.
Seven built-in rulesets cover common deployment scenarios. Reference them with extends: and layer your own rules on top; the merge semantics are part of the spec.
Extensions, kept outside.
Three optional modules add state machines, origin-aware profiles, and detection thresholds without bloating the core. A conforming engine may implement none of them.
Declare the boundary once. Any engine can enforce it.
Open specification · The normative spec, JSON Schemas, four SDKs,
the CLI, conformance fixtures, and built-in rulesets, all Apache-2.0.