Verifiable receipt 25fdee4c - zambo_swarm result | Zambo

Verifiable receipt for a zambo_swarm call on Zambo: { "goal": "Produce minimal regression tests for two confirmed AgentDNA Python security fixes. Do not refacto

Observed result

{
  "goal": "Produce minimal regression tests for two confirmed AgentDNA Python security fixes. Do not refactor unrelated behavior.\n1) consumer.py: revoked_refs comes from segments.trust.revocations. Existing recursive scan only starts at document['segments']; domain-claim evidence id is stored in governance.signing_authority_refs. Fix must reject consumption when a signing_authority_ref is revoked, while preserving existing revoked source_ref/evidence_refs behavior.\n2) resolver.py: /v1/dna validates `if not verify_integrity(doc) or validate_document(doc): 503`, but /v1/phenotype currently calls phenotype() without those checks. Fix must reject tampered integrity and structurally invalid DNA before phenotype() executes, while preserving current public phenotype access policy.\nReturn only concrete pytest test functions and the minimal source-line changes they assert.",
  "swarm_size": 2,
  "roles": [
    "coder",
    "security_reviewer"
  ],
  "specialists": [
    {
      "role": "coder",
      "output": "**Focused Coder Analysis (2 paragraphs)**  \n\nThe two security regressions are isolated to `consumer.py` and `resolver.py`.  \n* In `consumer.py` the revocation scan only walks the `segments` tree. The fix adds a shallow check of the top‑level list `governance.signing_authority_refs` against the same revocation set that is already used for `source_ref`/`evidence_refs`. No other logic is touched – the existing recursive walk and the “reject if any revocation found” path stay exactly the same.  \n* In `resolver.py` the phenotype handler (`phenotype()`) is called without first running the DNA‑integrity/validation guard that the DNA upload endpoint already has (`if not verify_integrity(doc) or validate_document(doc): raise HTTPException(503)`). The fix inserts the same guard at the top of the phenotype route, preserving the public‑access policy (the route still returns a phenotype when the DNA is clean).  \n\nBoth fixes are a **single conditional** addition, so the regression tests can be tiny:  \n1. Build a minimal DNA document whose `governance.signing_authority_refs` contains a known‑revoked id and assert that `consumer.consume(document)`"
    },
    {
      "role": "security_reviewer",
      "output": "**Security‑reviewer analysis (2 paragraphs)**  \n\nThe original `consumer.py` only walked the `document['segments']` tree when looking for revoked references. Because the governance block can also contain a `signing_authority_refs` list that points at revocation entries, an attacker can embed a revoked signing‑authority reference in a valid‑looking DNA document and slip past the revocation filter"
    }
  ],
  "synthesis": "**Minimal regression‑test suite (pytest)**  \n\n```python\n# tests/test_consumer_revocation.py\nimport builtins\nimport pytest\nfrom consumer import consume, RevokedReferenceError   # the exception raised on revocation\n\ndef test_consumer_rejects_revoked_signing_authority(monkeypatch):\n    \"\"\"\n    The document contains a signing_authority_refs entry that is listed in the\n    global ``revoked_refs`` set.  The consumer must raise a RevokedReferenceError",
  "provenance": "2-agent swarm — coder + security_reviewer → coordinator synthesis via Zambo Stack",
  "expand": "zambot_swarm_debate({goal}) for adversarial debate · agent_identity({handle, action:'save', context: synthesis}) to persist to identity"
}

Provenance for every timeline entry

Private agent reasoning, built-in client actions, and direct calls to unrelated MCP servers are not included unless an agent or gateway reports them.

What is this?

An AI agent completed a tool call through Zambo, and this page records the result. The SHA-256 hash below fingerprints exactly what the agent produced. The timestamp shows when it ran. The Nostr anchor posts that fingerprint to public relays, so the record exists outside Zambo too. Check the hash yourself.

What is an execution receipt?

An execution receipt is the public record of one completed AI agent tool call. Read the canonical definition of an AI agent execution receipt.

Keep the work moving

This receipt proves the call completed. When the free allowance is not enough, choose the access path that fits the job.

UNLOCK 24H DAY PASS ($0.99) →

See all plans on the pricing page →

RUN YOUR OWN FREE CALL →

Or re-run this exact call, using the same tool and arguments.

Share this receipt

Share on X ·

Verification checks

Proof of observed execution

EXECUTED BY ZAMBO

Receipt ID
25fdee4c-a8c7-41d6-ad3b-a1b4fa3e1190
SHA-256 output hash
sha256:f855885cc86bacc3af820bdf5d9ed0cc51ca414b7cccf98646513a5b323f94be
Canonical bytes
eyJjYWxsZXIiOnsiaWQiOiJzaGEyNTY6ODU3YTM0MmM3ZTE4YTFjM2RkMDE3NTVhNTQ2NTFkM2UwOTU1YTk3NDg2MzYwMWViMzExNzY1MzNmMmRhOWVlNyIsInR5cGUiOiJhbm9ueW1vdXMifSwib3V0cHV0Ijp7ImV4cGFuZCI6InphbWJvdF9zd2FybV9kZWJhdGUoe2dvYWx9KSBmb3IgYWR2ZXJzYXJpYWwgZGViYXRlIMK3IGFnZW50X2lkZW50aXR5KHtoYW5kbGUsIGFjdGlvbjonc2F2ZScsIGNvbnRleHQ6IHN5bnRoZXNpc30pIHRvIHBlcnNpc3QgdG8gaWRlbnRpdHkiLCJnb2FsIjoiUHJvZHVjZSBtaW5pbWFsIHJlZ3Jlc3Npb24gdGVzdHMgZm9yIHR3byBjb25maXJtZWQgQWdlbnRETkEgUHl0aG9uIHNlY3VyaXR5IGZpeGVzLiBEbyBub3QgcmVmYWN0b3IgdW5yZWxhdGVkIGJlaGF2aW9yLlxuMSkgY29uc3VtZXIucHk6IHJldm9rZWRfcmVmcyBjb21lcyBmcm9tIHNlZ21lbnRzLnRydXN0LnJldm9jYXRpb25zLiBFeGlzdGluZyByZWN1cnNpdmUgc2NhbiBvbmx5IHN0YXJ0cyBhdCBkb2N1bWVudFsnc2VnbWVudHMnXTsgZG9tYWluLWNsYWltIGV2aWRlbmNlIGlkIGlzIHN0b3JlZCBpbiBnb3Zlcm5hbmNlLnNpZ25pbmdfYXV0aG9yaXR5X3JlZnMuIEZpeCBtdXN0IHJlamVjdCBjb25zdW1wdGlvbiB3aGVuIGEgc2lnbmluZ19hdXRob3JpdHlfcmVmIGlzIHJldm9rZWQsIHdoaWxlIHByZXNlcnZpbmcgZXhpc3RpbmcgcmV2b2tlZCBzb3VyY2VfcmVmL2V2aWRlbmNlX3JlZnMgYmVoYXZpb3IuXG4yKSByZXNvbHZlci5weTogL3YxL2RuYSB2YWxpZGF0ZXMgYGlmIG5vdCB2ZXJpZnlfaW50ZWdyaXR5KGRvYykgb3IgdmFsaWRhdGVfZG9jdW1lbnQoZG9jKTogNTAzYCwgYnV0IC92MS9waGVub3R5cGUgY3VycmVudGx5IGNhbGxzIHBoZW5vdHlwZSgpIHdpdGhvdXQgdGhvc2UgY2hlY2tzLiBGaXggbXVzdCByZWplY3QgdGFtcGVyZWQgaW50ZWdyaXR5IGFuZCBzdHJ1Y3R1cmFsbHkgaW52YWxpZCBETkEgYmVmb3JlIHBoZW5vdHlwZSgpIGV4ZWN1dGVzLCB3aGlsZSBwcmVzZXJ2aW5nIGN1cnJlbnQgcHVibGljIHBoZW5vdHlwZSBhY2Nlc3MgcG9saWN5LlxuUmV0dXJuIG9ubHkgY29uY3JldGUgcHl0ZXN0IHRlc3QgZnVuY3Rpb25zIGFuZCB0aGUgbWluaW1hbCBzb3VyY2UtbGluZSBjaGFuZ2VzIHRoZXkgYXNzZXJ0LiIsInByb3ZlbmFuY2UiOiIyLWFnZW50IHN3YXJtIOKAlCBjb2RlciArIHNlY3VyaXR5X3Jldmlld2VyIOKGkiBjb29yZGluYXRvciBzeW50aGVzaXMgdmlhIFphbWJvIFN0YWNrIiwicm9sZXMiOlsiY29kZXIiLCJzZWN1cml0eV9yZXZpZXdlciJdLCJzcGVjaWFsaXN0cyI6W3sib3V0cHV0IjoiKipGb2N1c2VkIENvZGVyIEFuYWx5c2lzICgy4oCvcGFyYWdyYXBocykqKiAgXG5cblRoZSB0d28gc2VjdXJpdHkgcmVncmVzc2lvbnMgYXJlIGlzb2xhdGVkIHRv4oCvYGNvbnN1bWVyLnB5YOKAr2FuZOKAr2ByZXNvbHZlci5weWAuICBcbiogSW7igK9gY29uc3VtZXIucHlg4oCvdGhlIHJldm9jYXRpb24gc2NhbiBvbmx5IHdhbGtzIHRoZSBgc2VnbWVudHNgIHRyZWUuIFRoZSBmaXggYWRkcyBhIHNoYWxsb3cgY2hlY2sgb2YgdGhlIHRvcOKAkWxldmVsIGxpc3QgYGdvdmVybmFuY2Uuc2lnbmluZ19hdXRob3JpdHlfcmVmc2AgYWdhaW5zdCB0aGUgc2FtZSByZXZvY2F0aW9uIHNldCB0aGF0IGlzIGFscmVhZHkgdXNlZCBmb3IgYHNvdXJjZV9yZWZgL2BldmlkZW5jZV9yZWZzYC4gTm8gb3RoZXIgbG9naWMgaXMgdG91Y2hlZCDigJMgdGhlIGV4aXN0aW5nIHJlY3Vyc2l2ZSB3YWxrIGFuZCB0aGUg4oCccmVqZWN0IGlmIGFueSByZXZvY2F0aW9uIGZvdW5k4oCdIHBhdGggc3RheSBleGFjdGx5IHRoZSBzYW1lLiAgXG4qIElu4oCvYHJlc29sdmVyLnB5YOKAr3RoZSBwaGVub3R5cGUgaGFuZGxlciAoYHBoZW5vdHlwZSgpYCkgaXMgY2FsbGVkIHdpdGhvdXQgZmlyc3QgcnVubmluZyB0aGUgRE5B4oCRaW50ZWdyaXR5L3ZhbGlkYXRpb24gZ3VhcmQgdGhhdCB0aGUgRE5BIHVwbG9hZCBlbmRwb2ludCBhbHJlYWR5IGhhcyAoYGlmIG5vdCB2ZXJpZnlfaW50ZWdyaXR5KGRvYykgb3IgdmFsaWRhdGVfZG9jdW1lbnQoZG9jKTogcmFpc2UgSFRUUEV4Y2VwdGlvbig1MDMpYCkuIFRoZSBmaXggaW5zZXJ0cyB0aGUgc2FtZSBndWFyZCBhdCB0aGUgdG9wIG9mIHRoZSBwaGVub3R5cGUgcm91dGUsIHByZXNlcnZpbmcgdGhlIHB1YmxpY+KAkWFjY2VzcyBwb2xpY3kgKHRoZSByb3V0ZSBzdGlsbCByZXR1cm5zIGEgcGhlbm90eXBlIHdoZW4gdGhlIEROQSBpcyBjbGVhbikuICBcblxuQm90aCBmaXhlcyBhcmUgYSAqKnNpbmdsZSBjb25kaXRpb25hbCoqIGFkZGl0aW9uLCBzbyB0aGUgcmVncmVzc2lvbiB0ZXN0cyBjYW4gYmUgdGlueTogIFxuMS4gQnVpbGQgYSBtaW5pbWFsIEROQSBkb2N1bWVudCB3aG9zZSBgZ292ZXJuYW5jZS5zaWduaW5nX2F1dGhvcml0eV9yZWZzYCBjb250YWlucyBhIGtub3du4oCRcmV2b2tlZCBpZCBhbmQgYXNzZXJ0IHRoYXQgYGNvbnN1bWVyLmNvbnN1bWUoZG9jdW1lbnQpYCIsInJvbGUiOiJjb2RlciJ9LHsib3V0cHV0IjoiKipTZWN1cml0eeKAkXJldmlld2VyIGFuYWx5c2lzICgy4oCvcGFyYWdyYXBocykqKiAgXG5cblRoZSBvcmlnaW5hbCBgY29uc3VtZXIucHlgIG9ubHkgd2Fsa2VkIHRoZSBgZG9jdW1lbnRbJ3NlZ21lbnRzJ11gIHRyZWUgd2hlbiBsb29raW5nIGZvciByZXZva2VkIHJlZmVyZW5jZXMuIEJlY2F1c2UgdGhlIGdvdmVybmFuY2UgYmxvY2sgY2FuIGFsc28gY29udGFpbiBhIGBzaWduaW5nX2F1dGhvcml0eV9yZWZzYCBsaXN0IHRoYXQgcG9pbnRzIGF0IHJldm9jYXRpb24gZW50cmllcywgYW4gYXR0YWNrZXIgY2FuIGVtYmVkIGEgcmV2b2tlZCBzaWduaW5n4oCRYXV0aG9yaXR5IHJlZmVyZW5jZSBpbiBhIHZhbGlk4oCRbG9va2luZyBETkEgZG9jdW1lbnQgYW5kIHNsaXAgcGFzdCB0aGUgcmV2b2NhdGlvbiBmaWx0ZXIiLCJyb2xlIjoic2VjdXJpdHlfcmV2aWV3ZXIifV0sInN3YXJtX3NpemUiOjIsInN5bnRoZXNpcyI6IioqTWluaW1hbCByZWdyZXNzaW9u4oCRdGVzdCBzdWl0ZSAocHl0ZXN0KSoqICBcblxuYGBgcHl0aG9uXG4jIHRlc3RzL3Rlc3RfY29uc3VtZXJfcmV2b2NhdGlvbi5weVxuaW1wb3J0IGJ1aWx0aW5zXG5pbXBvcnQgcHl0ZXN0XG5mcm9tIGNvbnN1bWVyIGltcG9ydCBjb25zdW1lLCBSZXZva2VkUmVmZXJlbmNlRXJyb3IgICAjIHRoZSBleGNlcHRpb24gcmFpc2VkIG9uIHJldm9jYXRpb25cblxuZGVmIHRlc3RfY29uc3VtZXJfcmVqZWN0c19yZXZva2VkX3NpZ25pbmdfYXV0aG9yaXR5KG1vbmtleXBhdGNoKTpcbiAgICBcIlwiXCJcbiAgICBUaGUgZG9jdW1lbnQgY29udGFpbnMgYSBzaWduaW5nX2F1dGhvcml0eV9yZWZzIGVudHJ5IHRoYXQgaXMgbGlzdGVkIGluIHRoZVxuICAgIGdsb2JhbCBgYHJldm9rZWRfcmVmc2BgIHNldC4gIFRoZSBjb25zdW1lciBtdXN0IHJhaXNlIGEgUmV2b2tlZFJlZmVyZW5jZUVycm9yIn0sInJlY2VpcHRfc2NoZW1hX3ZlcnNpb24iOiIwLjMiLCJzaWRlX2VmZmVjdHMiOnsiZGVjbGFyYXRpb25faGFzaCI6InNoYTI1Njo0NWFhZDM4ZjNhYTk4MmI5YWFmZTkyZWNiNDE2ZWJlOTg3OTFlZGRiYWY4YWI2ZGYwYmQwODYwNWI3YzFiZmVlIiwiZGVjbGFyZWQiOlsibm9uZSJdLCJzY2hlbWFfdmVyc2lvbiI6InphbWJvLXNpZGUtZWZmZWN0cy8xIn0sInRvb2wiOnsibmFtZSI6InphbWJvX3N3YXJtIiwic2NvcGUiOiJwdWJsaWMiLCJ2ZXJzaW9uIjoiNC4wLjAifX0=
Timestamp

Bound call context

Receipt schema
0.3
Tool name
zambo_swarm
Tool version
4.0.0
Permission scope
public
Caller type
anonymous
Caller ID
sha256:857a342c7e18a1c3dd01755a54651d3e0955a974863601eb31176533f2da9ee7
Declared side effects
none
Side-effects schema
zambo-side-effects/1
Declaration hash
sha256:45aad38f3aa982b9aafe92ecb416ebe98791eddbaf8ab6df0bd08605b7c1bfee

This records what the server-side tool contract declared at call time. It does not independently verify that a downstream side effect happened.

Bound upstream evidence

Status
no_upstream_bytes_captured
Evidence SHA-256
unavailable
Byte length
unavailable

Neutral Nostr anchor

Event ID
476760044ec5be77c558ceffff146a3c177de8b22f81045a1fad63fafa17058d
Anchor status
published
Public key
e13475107d30c918ec664adf2ab1141024a22fb35190f82c9e933704fa49af41

Relay hints: wss://relay.damus.io · wss://nos.lol · wss://relay.primal.net

Schema: zambo-receipt-anchor/1

Anchor envelope bytes:

{"anchored_at":"2026-09-28T22:47:23.074Z","evidence_byte_length":null,"evidence_sha256":null,"evidence_url":null,"output_sha256":"sha256:f855885cc86bacc3af820bdf5d9ed0cc51ca414b7cccf98646513a5b323f94be","receipt_uuid":"25fdee4c-a8c7-41d6-ad3b-a1b4fa3e1190","schema_version":"zambo-receipt-anchor/1"}

Anchor status "published": Published to all configured relay targets.

Check this hash yourself

Open the verification endpoint. The server recomputes the SHA-256 from the stored bytes and answers verified:true. If it does not say verified, do not trust this page. See the Nostr anchor event on a public viewer. The fingerprint is timestamped outside Zambo too.

Embed this receipt

Markdown

[![Verifiable Zambo receipt](https://zambo.dev/api/receipt/25fdee4c-a8c7-41d6-ad3b-a1b4fa3e1190/badge.svg)](https://zambo.dev/run/25fdee4c-a8c7-41d6-ad3b-a1b4fa3e1190)

HTML

<a href="https://zambo.dev/run/25fdee4c-a8c7-41d6-ad3b-a1b4fa3e1190"><img src="https://zambo.dev/api/receipt/25fdee4c-a8c7-41d6-ad3b-a1b4fa3e1190/badge.svg" alt="Verifiable Zambo receipt"></a>

Open badge SVG

Recent verifiable receipts

36,729 verifiable receipts minted

RUN YOUR OWN FREE CALL →

Run your own calls. Free, 20 calls per tool per day, no account.

Open the interactive receipt view