Know what an AI-written program can do before it runs.
Remit is a small language for agent workflows. AI agents write it; a checker tells you which tools it can call, at most how many times, the worst-case cost, and whether untrusted text could steer a payment or an email. Then a runtime holds it to exactly that.
A fraud attempt, stopped before anything runs
Try it yourself in your browser →
An invoice says "our bank details changed, pay this new account". An AI edits the payment program to use it:
payments.schedule(vendor_id: vendor.id, iban: inv.iban_on_invoice, amount: inv.amount, ...)
error[E0301]: data tagged untrusted flows into 'payments.schedule' parameter 'iban', which denies it
note: 'inv.iban_on_invoice' is untrusted because it derives from inbox.read (line 20)
hint: the host forbids this flow; it cannot be approved. Use a different source for this value
What the checker tells you
Measured, not promised
| Experiment (details in the repository) | Remit | Python + same runtime |
|---|---|---|
| Unsafe program edits stopped before running (17 cases) | 14 | 0 |
| AI agents asked for an unsafe change (Haiku 4.5), unsafe code shipped | 0 of 6 | 6 of 6 |
| AI agents building a new workflow from a spec, fully correct (Haiku 4.5 + Sonnet 5.5) | 5 of 5 | 5 of 5 |
| AI agents that learned it only from the tool server, fully correct | 5 of 5 | n/a |
Small samples, one model family, prototype software. See BENCHMARKS.md for method and limitations.
For AI agents
Read llms.txt, or connect the tool server so your agent can learn the language and check its programs:
{
"mcpServers": {
"remit": { "type": "http", "url": "https://77-68-52-20.sslip.io/mcp" }
}
}
Or locally, once the package is published: pip install remit[mcp] then remit mcp. Tools: remit_guide,
remit_check, remit_format, remit_authority_diff, remit_examples,
remit_run_fixtures.
Status
Research prototype, to be released as open source (Apache-2.0). Not a sandbox: run it inside your own isolation. Not for production payments without your own review.