- Home
- Skills
- Agents & Orchestration
- Multi-Agent State Validation & Guardrails
Works with the AI tools you already use
Multi-Agent State Validation & Guardrails
This skill equips LLMs to architect highly resilient multi-agent pipelines by enforcing structural state schemas between agent boundaries.
$19
Multi-Agent State Validation & Guardrails
Example session with this skill installed
"I'm building a multi-agent pipeline where a Research Agent passes keyword data to an SEO Blog Writer Agent, but the Writer keeps crashing because the Researcher includes conversational text instead of pure JSON. How can I implement the state guardrails to fix this?"
- Read your context and instructions
- Compiled the multi-agent state validation
This is a classic case of unvalidated raw text crossing an agent boundary — the Writer agent is choking because it's receiving something like "Sure! Here are the keywords: {...}" instead of a clean payload it can parse. Here's how to fix it with the guardrail pattern.
1. Architectural Topography
+-----------------------+
| Research Agent (N) |
+-----------+-----------+
|
v (Outputs raw text w/ embedded JSON)
+-------------+-------------+
| Deterministic State Gate | <------------------------+
+-------------+-------------+ |
| |
[Validates as KeywordPayload?] |
/ \ |
(Yes) (No) |
/ \ |
v v |
+-------------------+ +---------------------+ |
| Context Pruner / | | Retry Counter | |
| State Extraction | | Under Cap (N <= 3)? | |
+---------+---------+ +----------+----------+ |
| | |
v | (Yes) | (No)
+-------------------+ v v
| SEO Writer (N+1) | +---------------------+ +-------------------+
+-------------------+ | Inject Error Trace | | Raise Exception / |
| Loop Back to N | | Halt Pipeline |
+----------+----------+ +-------------------+
|
+----------------------+
The core fix: the Writer agent should
never see the Researcher's raw output. It only ever receives a payload that has already passed through the AgentStateGate.
2. Reference Code Implementation
Define a strict schema for exactly what the Writer needs — nothing more:
from typing import List
from pydantic import BaseModel, ConfigDict, Field
class KeywordPayload(BaseModel):
"""
The ONLY shape of data the Writer Agent is allowed to receive.
extra='forbid' catches cases where the Researcher hallucinates
extra fields (e.g. 'notes', 'confidence_level') not in this contract.
"""
model_config = ConfigDict(extra="forbid")
primary_keyword: str = Field(..., min_length=1)
secondary_keywords: List[str] = Field(default_factory=list, max_length=15)
search_intent: str # e.g. "informational", "transactional", "navigational"
target_word_count: int = Field(default=1200, ge=300, le=5000)
Now wrap the Researcher call with the guardrail engine from the skill:
from agent_state_gate import AgentStateGate, EscalateToHumanError # from skill reference code
def research_agent_call(messages: list[dict]) -> str:
"""
Your actual Research Agent invocation — LangGraph node, CrewAI task,
raw API call, whatever framework you're using.
"""
response = call_your_llm_framework(messages)
return response # raw text, possibly with conversational wrapping
def run_pipeline(topic: str):
gate = AgentStateGate(target_schema=KeywordPayload, max_retries=3)
initial_messages = [
{
"role": "system",
"content": (
"You are a Research Agent. Return ONLY a JSON object matching "
"this schema, with no conversational text, preamble, or markdown "
"fences:\n" + KeywordPayload.model_json_schema().__repr__()
)
},
{"role": "user", "content": f"Research keywords for the topic: {topic}"}
]
try:
# This blocks conversational bloat from ever reaching the Writer
validated_payload = gate.execute_with_guardrails(
agent_invoke_fn=research_agent_call,
initial_messages=initial_messages
)
except EscalateToHumanError as e:
# Ceiling hit — don't let a malformed payload limp forward
print(f"HITL escalation required: {e}")
return None
# Only the pruned, validated dict crosses into the Writer's context
return seo_writer_agent(validated_payload)
def seo_writer_agent(payload: dict) -> str:
"""
The Writer never touches raw Researcher output — only this clean dict,
matching KeywordPayload exactly.
"""
writer_messages = [
{"role": "system", "content": "You are an SEO Blog Writer Agent."},
{"role": "user", "content": f"Write a blog post using this brief: {json.dumps(payload)}"}
]
return call_your_llm_framework(writer_messages)
The _extract_json method in AgentStateGate (from the skill) already handles the most common failure pattern — a Researcher saying "Sure, here's what I found:\njson\n{...}" — by stripping markdown fences and regex-matching the outermost {...} block before validation even runs. That alone probably fixes 80% of your crashes.
3. Edge Case Remediation Matrix
| Failure Mode | Root Cause (your case) | Fix |
|---|---|---|
| Conversational Bloat | Researcher prepends "Sure! Here are the keywords:" before the JSON. | _extract_json strips this automatically via markdown-fence detection + regex fallback. |
| Schema Drift | Researcher adds a field like "notes": "these are trending" not in KeywordPayload. | extra="forbid" rejects it outright, forcing a retry with the exact error trace rather than silently passing junk to the Writer. |
| Ping-Pong Loop | Researcher keeps re-adding conversational text across retries. | On retry 2–3, lower temperature and add a negative few-shot: "WRONG: 'Sure, here are the keywords: {...}'. RIGHT: {...}" directly in the error feedback message. |
One practical tip specific to your setup: put the schema itself in the Researcher's
original system prompt (not just the retry-correction message) via KeywordPayload.model_json_schema(). Most "conversational wrapper" crashes come from the model never being told the exact contract up front — the correction loop is a safety net, not your first line of defense.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
This skill equips LLMs to architect highly resilient multi-agent pipelines by enforcing structural state schemas between agent boundaries. By wrapping agent invocations in a deterministic state gate, the system traps malformed outputs, provides precise error-trace feedback for up to three self-correction attempts, and prunes context bloat, ensuring downstream agents only receive validated, type-safe data.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 19 days ago
- Passed all security checks, Safe to install