RTQ — Risk-Adaptive Capability Security Runtime. Dependency-free capability-security pipeline for AI agents.
TypeScript
4
0 commits
updated Sep 23, 2026
RTQ is a security-focused capability-security runtime for Node.js, TypeScript, Model Context Protocol (MCP) servers, and mobile approval hosts. Security-critical packages declare zero third-party npm runtime dependencies. It turns "can this agent/tool do this?" into an evidence-backed security pipeline:
Command → Capability (registered) → Risk (authoritative) → Policy (default-deny)
→ Clarification (missing critical params) → Approval (human/device)
→ Authorization Ticket (signed, single-use, bound) → Execution (OS-sandboxed)
→ Audit (structured, redacted)
While developing Aartiq, a disproportionate amount of engineering time was spent repeatedly implementing OS-level sandboxing, capability scoping, fine-grained permission gating, and challenge-response authorization from scratch.
RTQ was created to solve this problem for developers everywhere — packaging a security-focused capability security runtime into a clean suite of reusable packages. Developed and validated through automated security testing, RTQ allows developers to integrate capability security, OS-enforced sandboxing, Model Context Protocol (MCP) policy enforcement, and mobile QR challenge-response approvals into their applications without having to build security infrastructure from scratch.
To provide full transparency, RTQ clearly delineates what is implemented, what is verified in CI, and what is outside its current scope:
sandbox-exec), Linux bubblewrap (bwrap), and Windows AppContainer + Job Objects.flutter_secure_storage utilizing Android Keystore / iOS Keychain where supported by OS and hardware capabilities).system.execute) remains part of the host application's trusted computing base.Install the main façade package in your project:
npm install @rtq/security
Or install the RTQ CLI globally:
npm install -g @rtq/cli
import { createRTQ } from "@rtq/security";
// Initialize runtime with signing key from environment
const rtq = createRTQ({
signingKey: process.env.RTQ_SIGNING_KEY!,
});
// Step 1: Explicitly register capabilities (no ambient execution)
rtq.registerCapability({
name: "files.read",
version: 1,
description: "Read a file inside the workspace",
inputSchema: {
type: "object",
properties: { path: { type: "string" } },
required: ["path"],
additionalProperties: false,
},
risk: { base: "low" },
execute: async (ctx, input) => ({ ok: true, data: { path: input.path } }),
});
// Step 2: Register policy (default-deny: unlisted capabilities are denied)
rtq.registerPolicy({
kind: "allow",
capability: "files.read",
reason: "Allow workspace file reads",
});
// Step 3: Authorize operation (receives cryptographically signed ticket)
const auth = await rtq.authorize({
capability: "files.read",
version: 1,
input: { path: "/workspace/report.md" },
});
if (auth.decision === "allowed") {
// Step 4: Execute inside OS sandbox with single-use ticket
const outcome = await rtq.execute(auth.ticketId);
console.log("Result:", outcome.result);
} else if (auth.decision === "approval_required") {
console.log(
"Human/Mobile approval required. Challenge ID:",
auth.challengeId,
);
}
The @rtq/cli package provides actionable security inspection and testing commands:
# Inspect registered capabilities
RTQ_SIGNING_KEY=secret npx rtq capabilities --config settings/config.js
# Test policy enforcement against a candidate command
RTQ_SIGNING_KEY=secret npx rtq policy check command.json --config settings/config.js --origin remote
# Run real OS-level sandbox enforcement checks
npx rtq sandbox test
# Verify an authorization ticket signature
RTQ_SIGNING_KEY=secret npx rtq verify signature --ticket ticket.json
# Run environment and platform security diagnostics
npx rtq diagnostics
Protect MCP servers with RTQ's security gateway:
import { createMCPGateway } from "@rtq/mcp";
const gateway = createMCPGateway({
signingKey: process.env.RTQ_SIGNING_KEY!,
enforceSandboxing: true,
});
// Register MCP tool mapping to capability
// Note: RTQ enforces authorization & sandboxing, but handler safety remains part of host TCB
gateway.registerToolCapability({
toolName: "execute_script",
capabilityName: "system.execute",
version: 1,
});
For high-risk operations requiring user verification:
approval_required, it renders a single-use QR challenge.flutter_secure_storage utilizing Android Keystore / iOS Keychain where supported).npm run typecheck # Whole-repo TypeScript validation
npm run format:check # Code formatting validation
npm run build # Build all 12 packages
npm test # Run 430+ unit, contract & security tests
Apache-2.0. See LICENSE and NOTICE. RTQ is an original implementation created by Latestinssan.
RTQ — Risk-Adaptive Capability Security Runtime. Dependency-free capability-security pipeline for AI agents.
TypeScript
4
0 commits
updated Sep 23, 2026
RTQ is a security-focused capability-security runtime for Node.js, TypeScript, Model Context Protocol (MCP) servers, and mobile approval hosts. Security-critical packages declare zero third-party npm runtime dependencies. It turns "can this agent/tool do this?" into an evidence-backed security pipeline:
Command → Capability (registered) → Risk (authoritative) → Policy (default-deny)
→ Clarification (missing critical params) → Approval (human/device)
→ Authorization Ticket (signed, single-use, bound) → Execution (OS-sandboxed)
→ Audit (structured, redacted)
While developing Aartiq, a disproportionate amount of engineering time was spent repeatedly implementing OS-level sandboxing, capability scoping, fine-grained permission gating, and challenge-response authorization from scratch.
RTQ was created to solve this problem for developers everywhere — packaging a security-focused capability security runtime into a clean suite of reusable packages. Developed and validated through automated security testing, RTQ allows developers to integrate capability security, OS-enforced sandboxing, Model Context Protocol (MCP) policy enforcement, and mobile QR challenge-response approvals into their applications without having to build security infrastructure from scratch.
To provide full transparency, RTQ clearly delineates what is implemented, what is verified in CI, and what is outside its current scope:
sandbox-exec), Linux bubblewrap (bwrap), and Windows AppContainer + Job Objects.flutter_secure_storage utilizing Android Keystore / iOS Keychain where supported by OS and hardware capabilities).system.execute) remains part of the host application's trusted computing base.Install the main façade package in your project:
npm install @rtq/security
Or install the RTQ CLI globally:
npm install -g @rtq/cli
import { createRTQ } from "@rtq/security";
// Initialize runtime with signing key from environment
const rtq = createRTQ({
signingKey: process.env.RTQ_SIGNING_KEY!,
});
// Step 1: Explicitly register capabilities (no ambient execution)
rtq.registerCapability({
name: "files.read",
version: 1,
description: "Read a file inside the workspace",
inputSchema: {
type: "object",
properties: { path: { type: "string" } },
required: ["path"],
additionalProperties: false,
},
risk: { base: "low" },
execute: async (ctx, input) => ({ ok: true, data: { path: input.path } }),
});
// Step 2: Register policy (default-deny: unlisted capabilities are denied)
rtq.registerPolicy({
kind: "allow",
capability: "files.read",
reason: "Allow workspace file reads",
});
// Step 3: Authorize operation (receives cryptographically signed ticket)
const auth = await rtq.authorize({
capability: "files.read",
version: 1,
input: { path: "/workspace/report.md" },
});
if (auth.decision === "allowed") {
// Step 4: Execute inside OS sandbox with single-use ticket
const outcome = await rtq.execute(auth.ticketId);
console.log("Result:", outcome.result);
} else if (auth.decision === "approval_required") {
console.log(
"Human/Mobile approval required. Challenge ID:",
auth.challengeId,
);
}
The @rtq/cli package provides actionable security inspection and testing commands:
# Inspect registered capabilities
RTQ_SIGNING_KEY=secret npx rtq capabilities --config settings/config.js
# Test policy enforcement against a candidate command
RTQ_SIGNING_KEY=secret npx rtq policy check command.json --config settings/config.js --origin remote
# Run real OS-level sandbox enforcement checks
npx rtq sandbox test
# Verify an authorization ticket signature
RTQ_SIGNING_KEY=secret npx rtq verify signature --ticket ticket.json
# Run environment and platform security diagnostics
npx rtq diagnostics
Protect MCP servers with RTQ's security gateway:
import { createMCPGateway } from "@rtq/mcp";
const gateway = createMCPGateway({
signingKey: process.env.RTQ_SIGNING_KEY!,
enforceSandboxing: true,
});
// Register MCP tool mapping to capability
// Note: RTQ enforces authorization & sandboxing, but handler safety remains part of host TCB
gateway.registerToolCapability({
toolName: "execute_script",
capabilityName: "system.execute",
version: 1,
});
For high-risk operations requiring user verification:
approval_required, it renders a single-use QR challenge.flutter_secure_storage utilizing Android Keystore / iOS Keychain where supported).npm run typecheck # Whole-repo TypeScript validation
npm run format:check # Code formatting validation
npm run build # Build all 12 packages
npm test # Run 430+ unit, contract & security tests
Apache-2.0. See LICENSE and NOTICE. RTQ is an original implementation created by Latestinssan.