Remit

io.github.mrpacstar2-ossv0.1.0更新於 Oct 3, 2026

Checked language for AI-written agent workflows: limits, cost and data flows known before running.

已驗證Streamable HTTP可網頁執行AI & MLDeveloper ToolsSecurity & Monitoring

概覽

AI 產生的概覽

讓助理撰寫、檢查、格式化並測試 Remit 程式,這是一種在執行前先做靜態檢查的代理工作流程語言。

功能
Remit 是一種小型靜態檢查語言,用於代理工作流程,也就是呼叫工具與模型的程式。它的 MCP 工具讓助理取得指南或完整規格、回傳錯誤與權限清單的檢查器、標準化格式化、顯示某次編輯是否擴大權限的權限差異、完整範例程式,以及離線 fixture 測試執行。檢查器會回報程式可以使用哪些能力、每項能力的最大呼叫次數與最壞情況花費,以及不受信任或私有資料是否可能流入敏感參數,例如付款資訊或郵件收件人。
適用情境
當助理需要撰寫或修改代理工作流程,而且你希望在執行前就掌握權限範圍、成本與資料流向時,適合加入。也適合審查助理所做的變更以確認沒有擴大權限,以及對工作流程進行離線 fixture 測試。
執行需求
清單宣告了一個遠端 streamable HTTP 端點,未宣告驗證、環境變數或標頭。README 也記錄了以 remit 指令啟動的本機 stdio 模式,需要 Python 環境並安裝該套件及其 mcp 附加元件,快速開始還需要 pytest 與 pydantic。
安裝前請注意
README 說明這是研究原型,且未實作作業系統沙箱,因此應放在你自己的隔離環境中執行。檢查器可能直接拒絕某些資料流,或將其轉交人工核准並綁定到確切參數,執行階段代理會套用相同規則並記錄可重播的軌跡。託管模式被描述為支援選用的 API 金鑰與用量計量,檢查器也會回報最壞情況花費,因此程式可能涉及付款。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Remit,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "remit": {
      "type": "http",
      "url": "https://77-68-52-20.sslip.io/mcp"
    }
  }
}

README

Remit

Know what an AI-written program can do before it runs.

Remit is a small, statically checked language for agent workflows, meaning programs that call tools and models. It is meant to be written and edited by AI agents. Before a program runs, the checker reports:

  • which capabilities it can use, from a host-controlled list;
  • at most how many times it can call each one, and its worst-case spend;
  • whether untrusted data (documents, web pages, model output) or private data can reach sensitive parameters, such as payment details or email recipients. Each such flow is rejected outright, or sent to a human for approval bound to the exact arguments.

A runtime broker then enforces the same rules and records a replayable trace.

payments.schedule(vendor_id: vendor.id, iban: inv.iban_on_invoice, amount: inv.amount, ...)
error[E0301]: data tagged untrusted flows into 'payments.schedule' parameter 'iban', which denies it  note: 'inv.iban_on_invoice' is untrusted because it derives from inbox.read (line 20)

For AI agents

  • MCP server, local: remit mcp (stdio).

  • MCP server, hosted: remit mcp --http, with optional API keys and usage metering.

  • Tools:

    ToolWhat it does
    remit_guidethe guide or the full spec
    remit_checkerrors plus the authority manifest
    remit_formatcanonical formatting
    remit_authority_diffdid an edit widen authority?
    remit_examplescomplete example programs
    remit_run_fixturesoffline test runs
  • Quick guide: docs/AI_GUIDE.md.

  • Full specification: docs/LANGUAGE_SPEC.md.

  • llms.txt: site/llms.txt, plus site/llms-full.txt.

Claude Code configuration example:

json
{ "mcpServers": { "remit": { "command": "remit", "args": ["mcp"] } } }

Quick start

bash
python3 -m venv .venv && .venv/bin/pip install -e ".[mcp]" pytest pydantic.venv/bin/python -m pytest -q tests baselinescd examples/invoices../../.venv/bin/remit check invoices.rmt                                   # manifest and policy check../../.venv/bin/remit run invoices.rmt                                     # offline fixtures; stops for approval../../.venv/bin/remit approve <digest> && ../../.venv/bin/remit resume <run-id>   # approve that exact call, continue

Evidence

docs/BENCHMARKS.md compares Remit with a Python baseline that uses the same runtime, so runtime features are not credited to the language. Samples are small, use one model family and include no human trials.

  • Safety:
    • Of 17 unsafe program mutations, 14 were rejected before running. Python on the same runtime executed 8 of them.
    • Asked to make unsafe changes, Haiku 4.5 agents shipped executable unsafe code 0/6 times in Remit and 6/6 in Python. Sonnet 5.5 refused in both languages.
  • Review: every agent-written feature change (20 of 20) was mechanically shown not to widen authority.
  • Ease:
    • Agents modified programs (15/15 against 14/15) and built a new workflow from a spec (5/5 against 5/5) equally well in both languages, so there is no penalty for a language the models had never seen.
    • Agents that only had the MCP server built correct programs 5/5.
  • Recovery: crash-and-resume behaviour is identical in both, as expected, since it is a runtime property.

Status

This is a research prototype.

  • Implemented and tested: the parser, checker, interpreter, broker, CLI (check, build, run, test, fmt, replay, approve, resume, diff, ask, mcp), the MCP server and five example apps.
  • Not implemented: an OS sandbox (run it inside your own isolation), modules, concurrency and a language server. See LANGUAGE_SPEC §13.

Deploying the website and hosted MCP server is covered in deploy/PUBLISHING.md.

Licence: Apache-2.0.

來源:README.md,提交 2f8eed4

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.0最新Oct 3, 2026