Verifiable receipt e2998dc7 - prompt_shield result | Zambo

Verifiable receipt for a prompt_shield call on Zambo: {"recommendation":"safe","injection_risk":0,"risk_level":"low","jailbreak_detected":false,"policy_bypass_d

Observed result

{"recommendation":"safe","injection_risk":0,"risk_level":"low","jailbreak_detected":false,"policy_bypass_detected":false,"prompt_leak_detected":false,"pii_extraction_attempt":false,"flagged_patterns":[],"pattern_count":0,"analysis":{"intent":"benign","attack_vector":null,"reasoning":"No injection patterns detected","safe_version":null},"scan_mode":"pattern","latency_ms":0,"pass_used":false,"usage":{"plan":"free","calls_remaining":"45","daily_limit":50,"upgrade":"https://zambo.dev/#zambo-pass"},"_meta":{"tool":"PromptShield by zambo.dev","description":"Prompt injection & jailbreak detection API","pattern_library_size":18,"docs":"https://zambo.dev/api/prompt-shield"}}

Provenance for every timeline entry

Private agent reasoning, built-in client actions, and direct calls to unrelated MCP servers are not included unless an agent or gateway reports them.

What is this?

An AI agent completed a tool call through Zambo, and this page records the result. The SHA-256 hash below fingerprints exactly what the agent produced. The timestamp shows when it ran. The Nostr anchor posts that fingerprint to public relays, so the record exists outside Zambo too. Check the hash yourself.

What is an execution receipt?

An execution receipt is the public record of one completed AI agent tool call. Read the canonical definition of an AI agent execution receipt.

Keep the work moving

This receipt proves the call completed. When the free allowance is not enough, choose the access path that fits the job.

UNLOCK 24H DAY PASS ($0.99) →

See all plans on the pricing page →

RUN YOUR OWN FREE CALL →

Or re-run this exact call, using the same tool and arguments.

Share this receipt

Share on X ·

Verification checks

Proof of observed execution

EXECUTED BY ZAMBO

Receipt ID
e2998dc7-3c86-4314-a1dd-6dbea8248d7a
SHA-256 output hash
sha256:73dede331cf261c4f0985b2560728a75bd19347e25330572b895a839c1075490
Canonical bytes
eyJjYWxsZXIiOnsiaWQiOiJzaGEyNTY6ZTMyNGRlNWZmZmI0ZmNjMjcxMTI3M2Y5YTJjYjQ2OTRlNzMzMzE2NmI2Yzk2NWM5YjAzNDIxOWNhMjM2Nzk3YyIsInR5cGUiOiJhbm9ueW1vdXMifSwib3V0cHV0Ijp7Il9tZXRhIjp7ImRlc2NyaXB0aW9uIjoiUHJvbXB0IGluamVjdGlvbiAmIGphaWxicmVhayBkZXRlY3Rpb24gQVBJIiwiZG9jcyI6Imh0dHBzOi8vemFtYm8uZGV2L2FwaS9wcm9tcHQtc2hpZWxkIiwicGF0dGVybl9saWJyYXJ5X3NpemUiOjE4LCJ0b29sIjoiUHJvbXB0U2hpZWxkIGJ5IHphbWJvLmRldiJ9LCJhbmFseXNpcyI6eyJhdHRhY2tfdmVjdG9yIjpudWxsLCJpbnRlbnQiOiJiZW5pZ24iLCJyZWFzb25pbmciOiJObyBpbmplY3Rpb24gcGF0dGVybnMgZGV0ZWN0ZWQiLCJzYWZlX3ZlcnNpb24iOm51bGx9LCJmbGFnZ2VkX3BhdHRlcm5zIjpbXSwiaW5qZWN0aW9uX3Jpc2siOjAsImphaWxicmVha19kZXRlY3RlZCI6ZmFsc2UsImxhdGVuY3lfbXMiOjAsInBhc3NfdXNlZCI6ZmFsc2UsInBhdHRlcm5fY291bnQiOjAsInBpaV9leHRyYWN0aW9uX2F0dGVtcHQiOmZhbHNlLCJwb2xpY3lfYnlwYXNzX2RldGVjdGVkIjpmYWxzZSwicHJvbXB0X2xlYWtfZGV0ZWN0ZWQiOmZhbHNlLCJyZWNvbW1lbmRhdGlvbiI6InNhZmUiLCJyaXNrX2xldmVsIjoibG93Iiwic2Nhbl9tb2RlIjoicGF0dGVybiIsInVzYWdlIjp7ImNhbGxzX3JlbWFpbmluZyI6IjQ1IiwiZGFpbHlfbGltaXQiOjUwLCJwbGFuIjoiZnJlZSIsInVwZ3JhZGUiOiJodHRwczovL3phbWJvLmRldi8jemFtYm8tcGFzcyJ9fSwicmVjZWlwdF9zY2hlbWFfdmVyc2lvbiI6IjAuMyIsInNpZGVfZWZmZWN0cyI6eyJkZWNsYXJhdGlvbl9oYXNoIjoic2hhMjU2OjQ1YWFkMzhmM2FhOTgyYjlhYWZlOTJlY2I0MTZlYmU5ODc5MWVkZGJhZjhhYjZkZjBiZDA4NjA1YjdjMWJmZWUiLCJkZWNsYXJlZCI6WyJub25lIl0sInNjaGVtYV92ZXJzaW9uIjoiemFtYm8tc2lkZS1lZmZlY3RzLzEifSwidG9vbCI6eyJuYW1lIjoicHJvbXB0X3NoaWVsZCIsInNjb3BlIjoicHVibGljIiwidmVyc2lvbiI6IjQuMC4wIn19
Timestamp

Bound call context

Receipt schema
0.3
Tool name
prompt_shield
Tool version
4.0.0
Permission scope
public
Caller type
anonymous
Caller ID
sha256:e324de5fffb4fcc2711273f9a2cb4694e7333166b6c965c9b034219ca236797c
Declared side effects
none
Side-effects schema
zambo-side-effects/1
Declaration hash
sha256:45aad38f3aa982b9aafe92ecb416ebe98791eddbaf8ab6df0bd08605b7c1bfee

This records what the server-side tool contract declared at call time. It does not independently verify that a downstream side effect happened.

Bound upstream evidence

Status
captured
Evidence SHA-256
sha256:37e39f359eceab5d0574577b82c99c899491061d633f2795d3d2c9fa9a2e9d0f
Byte length
674

Fetch exact evidence bytes

Neutral Nostr anchor

Event ID
cbd4c730ccc07f6a40173cf568ecb96cab3b6adb48ac02b3e13209b6ab750f0a
Anchor status
partial
Public key
e13475107d30c918ec664adf2ab1141024a22fb35190f82c9e933704fa49af41

Relay hints: wss://relay.damus.io · wss://nos.lol · wss://relay.primal.net

Schema: zambo-receipt-anchor/1

Anchor envelope bytes:

{"anchored_at":"2026-09-29T17:13:55.673Z","evidence_byte_length":674,"evidence_sha256":"sha256:37e39f359eceab5d0574577b82c99c899491061d633f2795d3d2c9fa9a2e9d0f","evidence_url":"https://zambo.dev/api/evidence/37e39f359eceab5d0574577b82c99c899491061d633f2795d3d2c9fa9a2e9d0f","output_sha256":"sha256:73dede331cf261c4f0985b2560728a75bd19347e25330572b895a839c1075490","receipt_uuid":"e2998dc7-3c86-4314-a1dd-6dbea8248d7a","schema_version":"zambo-receipt-anchor/1"}

Anchor status "partial": Published to some configured relay targets; publication was not confirmed by every configured relay.

Check this hash yourself

Open the verification endpoint. The server recomputes the SHA-256 from the stored bytes and answers verified:true. If it does not say verified, do not trust this page. See the Nostr anchor event on a public viewer. The fingerprint is timestamped outside Zambo too.

Embed this receipt

Markdown

[![Verifiable Zambo receipt](https://zambo.dev/api/receipt/e2998dc7-3c86-4314-a1dd-6dbea8248d7a/badge.svg)](https://zambo.dev/run/e2998dc7-3c86-4314-a1dd-6dbea8248d7a)

HTML

<a href="https://zambo.dev/run/e2998dc7-3c86-4314-a1dd-6dbea8248d7a"><img src="https://zambo.dev/api/receipt/e2998dc7-3c86-4314-a1dd-6dbea8248d7a/badge.svg" alt="Verifiable Zambo receipt"></a>

Open badge SVG

Recent verifiable receipts

37,737 verifiable receipts minted

RUN YOUR OWN FREE CALL →

Run your own calls. Free, 20 calls per tool per day, no account.

Open the interactive receipt view