DeadBolt, a new local execution gate for software agents, has released version 1.0.3 under an Apache-2.0 license. The tool, developed by NextEleven LLC, sits between an agent's decision to act and the actual execution of that action. It forces operators to define policy and approval controls before any side effect occurs, effectively putting a bouncer at the door of your agent's tool calls. This addresses a critical gap in agentic workflows: the lack of deterministic, local control over irreversible actions.

How It Works

The architecture is straightforward but powerful. Developers embed DeadBolt directly into their Rust applications, call it as a local sidecar from Python or Node, or wrap a trusted stdio MCP server. The core mechanism involves a dispatch function that wraps the actual action, such as writing a file or sending an email. Before the callback executes, DeadBolt checks the configured policy. If the action is denied, the body is never called. This ensures that a misbehaving model cannot accidentally delete your production database without explicit operator permission.

Key Controls and Features

DeadBolt offers several layers of control. It supports tool allow-lists, destination tokens, and reported-spend caps. A standout feature is the use of leases with a default 60-second sliding TTL, which ensures that stale actions are automatically killed. Operator kills are persistent; once an ID is killed, it stays killed, along with its registered descendants. For sensitive, irreversible tools, the system supports broad one-shot approvals, which in the upcoming 1.1.0-rc.1 prerelease will include review of exact arguments like recipient, body, and amount.

Integration and Limitations

Integration is flexible, with native ZIPs available for Linux, Windows, and macOS. However, developers must understand the boundaries. DeadBolt does not isolate arbitrary code or stop a model provider from running. It also does not make external effects transactional with admission. The MCP child is trusted and has OS access, meaning startup and non-tool MCP methods fall outside the gate. Additionally, identity and tool routing must be handled by trusted application code, as DeadBolt is not a network interception tool.

Key Takeaways

  • DeadBolt v1.0.3 provides a local, deterministic gate for agent side effects, preventing unauthorized actions before execution.
  • The tool supports Rust embedding, local sidecars for Python/Node, and stdio MCP wrapping, with native binaries for major OS platforms.
  • Critical limitations exist: it does not isolate arbitrary code, stop model providers, or make external effects transactional with admission.
  • The upcoming 1.1.0-rc.1 prerelease adds exact-argument review for irreversible tools and installable Python packages.

The Bottom Line

DeadBolt is a necessary primitive for serious agentic deployments. By enforcing local policy gates, it moves us away from 'hope the model behaves' toward deterministic safety. It's not a silver bullet for all AI risks, but for controlling side effects, it's a sharp, practical tool.