Glossary · term

AgentSpec runtime-enforcement DSL

Here, AgentSpec means Wang, Poskitt and Sun's domain-specific language for applying runtime constraints to LLM agents, not the other systems that share its name. An AgentSpec rule binds a trigger to a conjunction of Boolean predicates and one or more enforcement actions. Triggers can fire on a state change, before an action, or when the agent finishes. If the trigger occurs and every predicate evaluates true, the runtime can stop, request user inspection, invoke a predefined alternative action, or ask the LLM to reconsider its plan.

Safety2025-03-24Wave 3 · 2025–26Maturity: 3/5

Origin and context

The first public preprint appeared in March 2025; a revised version was accepted to the ICSE 2026 Research Track. The accompanying prototype parses rules with ANTLR4 and inserts checks into a LangChain agent's execution loop before actions, after observations and at task completion. Domain-specific checks are Python predicates registered with the interpreter, so the DSL separates rule structure from orchestration logic but does not eliminate application-specific implementation work.

Sources: s1, s2, s3

Why it matters

A policy written only in a prompt depends on the model following it. AgentSpec instead gives the surrounding runtime a visible place to inspect a proposed action and intervene before a side effect. That makes rules easier to review, test and change independently of model weights. The value is conditional, however: the runtime enforces only the events and predicates it observes, and a missing hook, incomplete rule, stale state or unsafe substitute action can leave a gap.

Sources: s2, s3, s4

Example

Suppose a code agent plans to call a Python execution tool. A before-action rule can run predicates that inspect the proposed code for a sensitive-file operation and an untrusted network destination. If both conditions hold, the rule may stop the call or pause for user inspection. This illustrates an enforcement point; it does not show that the predicates recognize every harmful program or that approval makes the operation safe.

Sources: s2, s3

How it differs

AI Guardrails

AI guardrails are the broader family of controls over inputs, outputs, retrieval, dialogue and actions. AgentSpec is one named research framework within that family: it provides a particular trigger–check–enforce DSL and a LangChain-oriented prototype. The two labels are related, not synonyms, and evidence for general guardrail products does not establish adoption of AgentSpec.

Maturity and evidence

Maturity is rated 3. AgentSpec has a peer-reviewed ICSE paper, a public prototype, independent peer-reviewed citation, and an independent ICLR study that implemented it as an embodied-agent baseline. That is more than a single-source proposal. It remains below 4 because no reviewed source documents production deployment, a stable packaged release, interoperability, or broad organizational adoption, and the independent evaluation exposes important coverage limits.

Sources: s1, s2, s3, s4, s5, s9

Limits and open questions

The authors describe deterministic checks at discrete execution points, not prediction of long-horizon consequences. Their LLM-generated predicates missed risky cases and sometimes over-blocked benign behavior. RoboSafe's independent comparison found the static AgentSpec rules weak on contextual, temporal and jailbreak hazards, although they preserved benign-task execution relatively well in that experiment. Results from code benchmarks, simulators and selected driving scenarios must not be presented as certified safety, complete security, legal compliance or field effectiveness. The short name is also ambiguous: Oracle's Agent Spec describes portable agent configurations, while two 2026 papers use AgentSpec for embodied-scaffold composition and speculative decoding. Always retain the runtime-enforcement qualifier.

Sources: s2, s3, s4, s6, s7, s8

Related terms

References

Last updated: 2026-09-07

In the Skills Atlas

This term is also covered in the Skills Atlas as ai guardrails skill.

In the Skills Atlas

This term is also covered in the Skills Atlas as nemo guardrails skill.