Regulator - Tool Governance for Pydantic AI agents. Provides tool governance, boundary enforcement, tag activation, and policy evaluation for Pydantic AI tools.
rgltr is a governance framework for PydanticAI agents, not a traditional MCP server. Tools are demonstrated across multiple examples with varying quality. Most tools have descriptions but lack comprehensive parameter documentation and output schemas. Tool naming is reasonable (verb-noun patterns like get_customer, post_to_slack, delete_account, transfer_funds) but schema documentation is sparse. No explicit input/output validation or error handling guidance visible in tool definitions. The 8 tools are spread across examples and lack centralized, production-grade schema registration. This is an alpha-stage library (v0.1.6) focused on policy enforcement rather than tool quality standards.
Deletes an account. Requires admin policy approval.
Retrieves customer information by customer ID. Tagged to activate CUSTOMERS tag.
Retrieves invoice information by invoice ID. Tagged to activate FINANCIAL tag.
Posts a message to Slack. Subject to EXTERNAL boundary.
Queries documentation. Subject to EXTERNAL boundary. Remote MCP tool from Context7.
Resolves library IDs. Tagged to activate DOCS tag. Remote MCP tool from Context7.
Transfers funds. Requires approval policy.
Missing output schemas for all tools. No documented return types or response structures visible in source code. LLMs cannot plan downstream calls or extract typed fields when return structure is undefined.
Incomplete parameter descriptions. web_search has no parameter documentation visible. transfer_funds 'amount' parameter lacks validation constraints (min/max bounds). Most tools missing guidance on when to use them vs similar tools.
No error handling or recovery guidance documented. Destructive operations (delete_account, transfer_funds) lack confirmation/dry-run patterns or error classification. LLM cannot determine if errors are retryable, user-fixable, or fatal.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 46 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
Performs web search. Subject to EXTERNAL boundary.
query-docs tool has no parameter documentation visible in source. Cannot determine expected inputs, making LLM selection and invocation unreliable.
Destructive tools (delete_account, transfer_funds) lack scope declarations and explicit permission checks documented. No audit trail or security boundary enforcement visible in tool definitions themselves.
web_search tool has minimal description ('Performs web search') and completely missing parameter documentation. Too generic for reliable LLM selection. Baseline expects 194 char descriptions; this is far shorter.