
Remit
io.github.mrpacstar2-ossv0.1.0更新于 Oct 3, 2026
Checked language for AI-written agent workflows: limits, cost and data flows known before running.
概览
让助手编写、检查、格式化并测试 Remit 程序,这是一种在运行前进行静态检查的智能体工作流语言。
- 功能
- Remit 是一种小型静态检查语言,用于智能体工作流,即调用工具和模型的程序。它的 MCP 工具让助手获取指南或完整规范、返回错误与权限清单的检查器、规范化格式化、显示某次编辑是否扩大权限的权限差异、完整示例程序,以及离线夹具测试运行。检查器会报告程序可以使用哪些能力、每项能力的最大调用次数与最坏情况花费,以及不可信或私有数据是否可能流入敏感参数,例如付款信息或邮件收件人。
- 适用场景
- 当助手需要编写或修改智能体工作流,并且你希望在运行前就了解权限范围、成本和数据流向时,适合添加。也适合审查助手所做的改动以确认没有扩大权限,以及对工作流进行离线夹具测试。
- 运行要求
- 清单声明了一个远程 streamable HTTP 端点,未声明认证、环境变量或请求头。README 还记录了以 remit 命令启动的本地 stdio 模式,需要 Python 环境并安装该包及其 mcp 附加组件,快速开始还需 pytest 和 pydantic。
安装
在 SourceWeft 中
- 打开 控制台中的 Remit,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。
其他 MCP 客户端
把它添加到你客户端的 mcpServers 配置中。
{
"mcpServers": {
"remit": {
"type": "http",
"url": "https://77-68-52-20.sslip.io/mcp"
}
}
}README
Remit
Know what an AI-written program can do before it runs.
Remit is a small, statically checked language for agent workflows, meaning programs that call tools and models. It is meant to be written and edited by AI agents. Before a program runs, the checker reports:
- which capabilities it can use, from a host-controlled list;
- at most how many times it can call each one, and its worst-case spend;
- whether untrusted data (documents, web pages, model output) or private data can reach sensitive parameters, such as payment details or email recipients. Each such flow is rejected outright, or sent to a human for approval bound to the exact arguments.
A runtime broker then enforces the same rules and records a replayable trace.
For AI agents
-
MCP server, local:
remit mcp(stdio). -
MCP server, hosted:
remit mcp --http, with optional API keys and usage metering. -
Tools:
-
Quick guide: docs/AI_GUIDE.md.
-
Full specification: docs/LANGUAGE_SPEC.md.
-
llms.txt: site/llms.txt, plus site/llms-full.txt.
Claude Code configuration example:
Quick start
Evidence
docs/BENCHMARKS.md compares Remit with a Python baseline that uses the same runtime, so runtime features are not credited to the language. Samples are small, use one model family and include no human trials.
- Safety:
- Of 17 unsafe program mutations, 14 were rejected before running. Python on the same runtime executed 8 of them.
- Asked to make unsafe changes, Haiku 4.5 agents shipped executable unsafe code 0/6 times in Remit and 6/6 in Python. Sonnet 5.5 refused in both languages.
- Review: every agent-written feature change (20 of 20) was mechanically shown not to widen authority.
- Ease:
- Agents modified programs (15/15 against 14/15) and built a new workflow from a spec (5/5 against 5/5) equally well in both languages, so there is no penalty for a language the models had never seen.
- Agents that only had the MCP server built correct programs 5/5.
- Recovery: crash-and-resume behaviour is identical in both, as expected, since it is a runtime property.
Status
This is a research prototype.
- Implemented and tested: the parser, checker, interpreter, broker, CLI (
check,build,run,test,fmt,replay,approve,resume,diff,ask,mcp), the MCP server and five example apps. - Not implemented: an OS sandbox (run it inside your own isolation), modules, concurrency and a language server. See LANGUAGE_SPEC §13.
Deploying the website and hosted MCP server is covered in deploy/PUBLISHING.md.
Licence: Apache-2.0.
来源:README.md,提交 2f8eed4
工具
0版本历史
1- v0.1.0最新Oct 3, 2026

