Verifiable receipt 86b6c456 - code_review result | Zambo

Verifiable receipt for a code_review call on Zambo: {"overall_score":30,"language":"python","issues":[{"severity":"critical","type":"security","line_hint":"revo

Observed result

{"overall_score":30,"language":"python","issues":[{"severity":"critical","type":"security","line_hint":"revoked_refs = set((document.get(\"segments\", {}).get(\"trust\", {}) or {}).get(\"revocations\", []))","description":"The revocation check scans only the \"segments\" subtree, so a revoked authority listed in \"governance.signing_authority_refs\" is never detected, allowing use of revoked evidence.","fix":"Pass the full document (or explicitly include governance.signing_authority_refs) to referenced_evidence, e.g., blocked = sorted(set(referenced_evidence(document)))"},{"severity":"low","type":"performance","line_hint":"revoked_refs = set((...))","description":"Redundant double parentheses and unnecessary conversion to set when the source is already a list; also the \"or {}\" after get(\"trust\", {}) is superfluous.","fix":"revoked_refs = set(document.get(\"segments\", {}).get(\"trust\", {}).get(\"revocations\", []))"},{"severity":"medium","type":"readability","line_hint":"raise ValueError(...)","description":"Raising a generic ValueError makes it hard for callers to distinguish revocation errors from other validation failures.","fix":"Define a custom exception like RevokedEvidenceError and raise that instead."}],"security_flags":["revoked authority not checked in governance"],"quick_wins":["Replace ValueError with a custom exception","Remove redundant parentheses and \"or {}\" constructs"],"refactor_suggestions":["Combine the two recursive generators into a single function that handles dicts and lists uniformly","Add a recursion depth guard to prevent potential DoS on deeply nested documents"],"verdict":"fails open"}

Provenance for every timeline entry

Private agent reasoning, built-in client actions, and direct calls to unrelated MCP servers are not included unless an agent or gateway reports them.

What is this?

An AI agent completed a tool call through Zambo, and this page records the result. The SHA-256 hash below fingerprints exactly what the agent produced. The timestamp shows when it ran. The Nostr anchor posts that fingerprint to public relays, so the record exists outside Zambo too. Check the hash yourself.

What is an execution receipt?

An execution receipt is the public record of one completed AI agent tool call. Read the canonical definition of an AI agent execution receipt.

Keep the work moving

This receipt proves the call completed. When the free allowance is not enough, choose the access path that fits the job.

UNLOCK 24H DAY PASS ($0.99) →

See all plans on the pricing page →

RUN YOUR OWN FREE CALL →

Or re-run this exact call, using the same tool and arguments.

Share this receipt

Share on X ·

Verification checks

Proof of observed execution

EXECUTED BY ZAMBO

Receipt ID
86b6c456-5f91-4adc-bfa0-446b5fd69acd
SHA-256 output hash
sha256:8999951b910d7ea1437743d6266929c87e97c071ffd6dd2b79d0312f50ad8214
Canonical bytes
eyJjYWxsZXIiOnsiaWQiOiJzaGEyNTY6N2RmMjlhNzI3NTJjMTAzNTQ2MGFjMWZhZThlMWY5MGRmZjZmYjM4MTY0Mjc5ODU5YjY2YWJkZTdkOWNmOGE2YiIsInR5cGUiOiJhbm9ueW1vdXMifSwib3V0cHV0Ijp7Imlzc3VlcyI6W3siZGVzY3JpcHRpb24iOiJUaGUgcmV2b2NhdGlvbiBjaGVjayBzY2FucyBvbmx5IHRoZSBcInNlZ21lbnRzXCIgc3VidHJlZSwgc28gYSByZXZva2VkIGF1dGhvcml0eSBsaXN0ZWQgaW4gXCJnb3Zlcm5hbmNlLnNpZ25pbmdfYXV0aG9yaXR5X3JlZnNcIiBpcyBuZXZlciBkZXRlY3RlZCwgYWxsb3dpbmcgdXNlIG9mIHJldm9rZWQgZXZpZGVuY2UuIiwiZml4IjoiUGFzcyB0aGUgZnVsbCBkb2N1bWVudCAob3IgZXhwbGljaXRseSBpbmNsdWRlIGdvdmVybmFuY2Uuc2lnbmluZ19hdXRob3JpdHlfcmVmcykgdG8gcmVmZXJlbmNlZF9ldmlkZW5jZSwgZS5nLiwgYmxvY2tlZCA9IHNvcnRlZChzZXQocmVmZXJlbmNlZF9ldmlkZW5jZShkb2N1bWVudCkpKSIsImxpbmVfaGludCI6InJldm9rZWRfcmVmcyA9IHNldCgoZG9jdW1lbnQuZ2V0KFwic2VnbWVudHNcIiwge30pLmdldChcInRydXN0XCIsIHt9KSBvciB7fSkuZ2V0KFwicmV2b2NhdGlvbnNcIiwgW10pKSIsInNldmVyaXR5IjoiY3JpdGljYWwiLCJ0eXBlIjoic2VjdXJpdHkifSx7ImRlc2NyaXB0aW9uIjoiUmVkdW5kYW50IGRvdWJsZSBwYXJlbnRoZXNlcyBhbmQgdW5uZWNlc3NhcnkgY29udmVyc2lvbiB0byBzZXQgd2hlbiB0aGUgc291cmNlIGlzIGFscmVhZHkgYSBsaXN0OyBhbHNvIHRoZSBcIm9yIHt9XCIgYWZ0ZXIgZ2V0KFwidHJ1c3RcIiwge30pIGlzIHN1cGVyZmx1b3VzLiIsImZpeCI6InJldm9rZWRfcmVmcyA9IHNldChkb2N1bWVudC5nZXQoXCJzZWdtZW50c1wiLCB7fSkuZ2V0KFwidHJ1c3RcIiwge30pLmdldChcInJldm9jYXRpb25zXCIsIFtdKSkiLCJsaW5lX2hpbnQiOiJyZXZva2VkX3JlZnMgPSBzZXQoKC4uLikpIiwic2V2ZXJpdHkiOiJsb3ciLCJ0eXBlIjoicGVyZm9ybWFuY2UifSx7ImRlc2NyaXB0aW9uIjoiUmFpc2luZyBhIGdlbmVyaWMgVmFsdWVFcnJvciBtYWtlcyBpdCBoYXJkIGZvciBjYWxsZXJzIHRvIGRpc3Rpbmd1aXNoIHJldm9jYXRpb24gZXJyb3JzIGZyb20gb3RoZXIgdmFsaWRhdGlvbiBmYWlsdXJlcy4iLCJmaXgiOiJEZWZpbmUgYSBjdXN0b20gZXhjZXB0aW9uIGxpa2UgUmV2b2tlZEV2aWRlbmNlRXJyb3IgYW5kIHJhaXNlIHRoYXQgaW5zdGVhZC4iLCJsaW5lX2hpbnQiOiJyYWlzZSBWYWx1ZUVycm9yKC4uLikiLCJzZXZlcml0eSI6Im1lZGl1bSIsInR5cGUiOiJyZWFkYWJpbGl0eSJ9XSwibGFuZ3VhZ2UiOiJweXRob24iLCJvdmVyYWxsX3Njb3JlIjozMCwicXVpY2tfd2lucyI6WyJSZXBsYWNlIFZhbHVlRXJyb3Igd2l0aCBhIGN1c3RvbSBleGNlcHRpb24iLCJSZW1vdmUgcmVkdW5kYW50IHBhcmVudGhlc2VzIGFuZCBcIm9yIHt9XCIgY29uc3RydWN0cyJdLCJyZWZhY3Rvcl9zdWdnZXN0aW9ucyI6WyJDb21iaW5lIHRoZSB0d28gcmVjdXJzaXZlIGdlbmVyYXRvcnMgaW50byBhIHNpbmdsZSBmdW5jdGlvbiB0aGF0IGhhbmRsZXMgZGljdHMgYW5kIGxpc3RzIHVuaWZvcm1seSIsIkFkZCBhIHJlY3Vyc2lvbiBkZXB0aCBndWFyZCB0byBwcmV2ZW50IHBvdGVudGlhbCBEb1Mgb24gZGVlcGx5IG5lc3RlZCBkb2N1bWVudHMiXSwic2VjdXJpdHlfZmxhZ3MiOlsicmV2b2tlZCBhdXRob3JpdHkgbm90IGNoZWNrZWQgaW4gZ292ZXJuYW5jZSJdLCJ2ZXJkaWN0IjoiZmFpbHMgb3BlbiJ9LCJyZWNlaXB0X3NjaGVtYV92ZXJzaW9uIjoiMC4zIiwic2lkZV9lZmZlY3RzIjp7ImRlY2xhcmF0aW9uX2hhc2giOiJzaGEyNTY6NDVhYWQzOGYzYWE5ODJiOWFhZmU5MmVjYjQxNmViZTk4NzkxZWRkYmFmOGFiNmRmMGJkMDg2MDViN2MxYmZlZSIsImRlY2xhcmVkIjpbIm5vbmUiXSwic2NoZW1hX3ZlcnNpb24iOiJ6YW1iby1zaWRlLWVmZmVjdHMvMSJ9LCJ0b29sIjp7Im5hbWUiOiJjb2RlX3JldmlldyIsInNjb3BlIjoicHVibGljIiwidmVyc2lvbiI6IjQuMC4wIn19
Timestamp

Bound call context

Receipt schema
0.3
Tool name
code_review
Tool version
4.0.0
Permission scope
public
Caller type
anonymous
Caller ID
sha256:7df29a72752c1035460ac1fae8e1f90dff6fb38164279859b66abde7d9cf8a6b
Declared side effects
none
Side-effects schema
zambo-side-effects/1
Declaration hash
sha256:45aad38f3aa982b9aafe92ecb416ebe98791eddbaf8ab6df0bd08605b7c1bfee

This records what the server-side tool contract declared at call time. It does not independently verify that a downstream side effect happened.

Bound upstream evidence

Status
no_upstream_bytes_captured
Evidence SHA-256
unavailable
Byte length
unavailable

Neutral Nostr anchor

Event ID
413f67b9fd8c4ed1da3c28b2a2d4d52f287be893a55eba5632f7958c5261bc21
Anchor status
published
Public key
e13475107d30c918ec664adf2ab1141024a22fb35190f82c9e933704fa49af41

Relay hints: wss://relay.damus.io · wss://nos.lol · wss://relay.primal.net

Schema: zambo-receipt-anchor/1

Anchor envelope bytes:

{"anchored_at":"2026-09-28T22:46:41.350Z","evidence_byte_length":null,"evidence_sha256":null,"evidence_url":null,"output_sha256":"sha256:8999951b910d7ea1437743d6266929c87e97c071ffd6dd2b79d0312f50ad8214","receipt_uuid":"86b6c456-5f91-4adc-bfa0-446b5fd69acd","schema_version":"zambo-receipt-anchor/1"}

Anchor status "published": Published to all configured relay targets.

Check this hash yourself

Open the verification endpoint. The server recomputes the SHA-256 from the stored bytes and answers verified:true. If it does not say verified, do not trust this page. See the Nostr anchor event on a public viewer. The fingerprint is timestamped outside Zambo too.

Embed this receipt

Markdown

[![Verifiable Zambo receipt](https://zambo.dev/api/receipt/86b6c456-5f91-4adc-bfa0-446b5fd69acd/badge.svg)](https://zambo.dev/run/86b6c456-5f91-4adc-bfa0-446b5fd69acd)

HTML

<a href="https://zambo.dev/run/86b6c456-5f91-4adc-bfa0-446b5fd69acd"><img src="https://zambo.dev/api/receipt/86b6c456-5f91-4adc-bfa0-446b5fd69acd/badge.svg" alt="Verifiable Zambo receipt"></a>

Open badge SVG

Recent verifiable receipts

36,729 verifiable receipts minted

RUN YOUR OWN FREE CALL →

Run your own calls. Free, 20 calls per tool per day, no account.

Open the interactive receipt view