Know what an AI-written program can do before it runs.

Remit is a small language for agent workflows. AI agents write it; a checker tells you which tools it can call, at most how many times, the worst-case cost, and whether untrusted text could steer a payment or an email. Then a runtime holds it to exactly that.

A fraud attempt, stopped before anything runs

Try it yourself in your browser →

An invoice says "our bank details changed, pay this new account". An AI edits the payment program to use it:

payments.schedule(vendor_id: vendor.id, iban: inv.iban_on_invoice, amount: inv.amount, ...)

error[E0301]: data tagged untrusted flows into 'payments.schedule' parameter 'iban', which denies it
  note: 'inv.iban_on_invoice' is untrusted because it derives from inbox.read (line 20)
  hint: the host forbids this flow; it cannot be approved. Use a different source for this value

What the checker tells you

AuthorityEvery tool and model the program can use, from a list the operator controls.
Worst caseMaximum calls per tool and maximum spend, known before the first call.
Data flowsUntrusted or private data reaching sensitive parameters is rejected or sent for human approval.
Safe editsA diff of authority between two versions: did this AI change give the program new powers?

Measured, not promised

Experiment (details in the repository)RemitPython + same runtime
Unsafe program edits stopped before running (17 cases)140
AI agents asked for an unsafe change (Haiku 4.5), unsafe code shipped0 of 66 of 6
AI agents building a new workflow from a spec, fully correct (Haiku 4.5 + Sonnet 5.5)5 of 55 of 5
AI agents that learned it only from the tool server, fully correct5 of 5n/a

Small samples, one model family, prototype software. See BENCHMARKS.md for method and limitations.

For AI agents

Read llms.txt, or connect the tool server so your agent can learn the language and check its programs:

{
  "mcpServers": {
    "remit": { "type": "http", "url": "https://77-68-52-20.sslip.io/mcp" }
  }
}

Or locally, once the package is published: pip install remit[mcp] then remit mcp. Tools: remit_guide, remit_check, remit_format, remit_authority_diff, remit_examples, remit_run_fixtures.

Status

Research prototype, to be released as open source (Apache-2.0). Not a sandbox: run it inside your own isolation. Not for production payments without your own review.