RuleOak v0.10.2 public preview — Agent Firewall + Flight Recorder for AI Agents Run the 60-second demo

Compatibility · v0.10.2

Tested boundaries, not universal claims

RuleOak separates automated fixture coverage from real-world integration reports and documents what has not been claimed.

Runtime support

EnvironmentStatusValidation
Node.js 22 LTSTestedFull Linux publish-readiness suite
Node.js 24 LTSTestedLinux suite plus macOS and Windows smoke tests
Node.js 26 CurrentCompatibility signalLinux CI; prefer an LTS line for production-like use
ESMTestedPublic ESM entry points and TypeScript declarations
CommonJS require()Not supportedUse ESM or dynamic import()

Integration paths

PathStatusBoundary
Node.js createRuleOak() SDKTestedCalls explicitly routed through guarded functions/tools
CLI protectTested for supported stdio trafficDoes not inspect arbitrary subprocess internals
MCP stdioFixture-testedJSON-RPC tools/call, lifecycle messages, notifications, and batches
MCP Streamable HTTPFixture-testedAuthorized requests and supported SSE responses
REST authorization APILocally testedLoopback by default; non-loopback requires explicit authentication
OpenAI-style tool-call adapterUnit-testedNormalization/authorization only; not an OpenAI network client
Shell, filesystem, HTTP adaptersUnit-testedApplication-layer normalization and policy checks

Security behavior exercised

Not claimed

RuleOak does not currently claim universal MCP client/server compatibility, OS containment, control over bypass paths, complete prompt-injection detection, tamper-proof evidence against a privileged local attacker, or independent security certification.