Observed arrival · 2026-09-28
Writ puts an authorization gate in front of AI-agent writes
Writ describes a Python tool that adds allow-or-deny checks and audit receipts to functions that write to systems such as databases, APIs, files, and email.
- For
- Python developers building AI-agent services
- Worth noticing
- The Python AST scanner explicitly lists gaps including ORM .save() calls, raw SQL, and shared HTTP clients several layers down.
Field notes
The documented scan writes a writ-policy.json file and presents an instrumentation diff before any code is changed. Applying the diff adds a module-level helper and a check at each selected function; the page says the operation is idempotent. It also warns that discovery is not complete security coverage, naming missed patterns such as raw SQL and some shared clients, and directs users to report gaps rather than treat the scan as exhaustive.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue