strands-tealtiger package ships as a native Strands plugin — no external server, no LLM in the governance path, under 2ms per evaluation.
Why integrate TealTiger with Strands?
Strands Agents gives you a model-driven agent loop with lifecycle hooks and a plugin system. TealTiger plugs into that system to add:- Tool authorization — Allowlist and blocklist which tools the agent can call
- PII protection — Block tool calls containing SSNs, credit cards, emails, or phone numbers
- Secret detection — Catch API keys, tokens, and credentials before they leak
- Prompt injection defense — Detect adversarial inputs in tool arguments
- Cost budgets — Hard-stop when session spend exceeds your limit
- Kill switch — Freeze all tool calls instantly without restarting
- Structured audit trail — Every decision produces a traceable record
Installation
Quick start
Configuration
Tool allowlist and blocklist
Control which tools the agent can call using glob patterns:PII detection
Block tool calls containing sensitive data in their arguments:Secret detection
Block tool calls containing API keys, tokens, or credentials:sk-...), GitHub tokens (ghp_...), AWS keys (AKIA...), Slack tokens, generic API keys, and PEM private keys.
Prompt injection defense
Detect adversarial inputs in tool arguments before they reach the model:Cost budget
Hard-stop when session cost exceeds your limit:Kill switch
Freeze all tool calls immediately — no policy can override:Governance modes
Start with
OBSERVE when deploying, promote to MONITOR to see what would be blocked, then switch to ENFORCE in production:
Audit trail
Every evaluation produces a structuredGovernanceDecision:
Multi-agent support
Works with Strands multi-agent patterns (Swarm, Graph). Attach the plugin to individual agents:Complete example
How it works
TealTiger implements the StrandsPlugin interface with two @hook methods:
BeforeToolsEvent— Kill switch enforcement at the batch level. If frozen, cancels the entire batch.BeforeToolCallEvent— Per-tool policy evaluation. Checks allowlist, blocklist, injection, PII, secrets, and budget in sequence. First violation wins.
- Kill switch (risk: 100)
- Budget limit (risk: 70)
- Blocked tools (risk: 90)
- Allowed tools (risk: 80)
- Prompt injection (risk: 95)
- PII detection (risk: 90)
- Secret detection (risk: 95)

