Verifiable receipt a5be3691 - code_review result | Zambo
Verifiable receipt for a code_review call on Zambo: {"overall_score":45,"language":"python","issues":[{"severity":"high","type":"security","line_hint":"revoked_
Observed result
{"overall_score":45,"language":"python","issues":[{"severity":"high","type":"security","line_hint":"revoked_refs = set((document.get('segments', {}).get('trust', {}) or {}).get('revocations', []))","description":"Revocation check only inspects segments.trust.revocations and does not consider governance.signing_authority_refs, allowing revoked domain‑claim evidence to remain effective.","fix":"Include governance.signing_authority_refs in the revocation traversal or ensure revocations are propagated to that list before validation."},{"severity":"medium","type":"security","line_hint":"raise ValueError('invalid AgentDNA: ' + '; '.join(errors))","description":"Error messages expose internal validation details, which could aid an attacker in crafting malicious documents.","fix":"Raise a generic exception or sanitize messages before returning them to callers."},{"severity":"low","type":"readability","line_hint":"def referenced_evidence(value): ...","description":"Recursive traversal may encounter cyclic references leading to RecursionError.","fix":"Add cycle detection or limit recursion depth when walking the document structure."}],"security_flags":["revoked evidence in governance.signing_authority_refs not checked","information leakage via exception messages"],"quick_wins":["Add governance.signing_authority_refs to revocation set","Sanitize exception messages"],"refactor_suggestions":["Extract revocation checking into a separate utility function","Use typed data structures for document schema validation"],"verdict":"The current revocation logic is incomplete and may allow consumption of AgentDNA with revoked domain‑claim evidence, representing a security risk."}
Verify this receipt
This is a verifiable receipt: the result above is hashed and timestamped at a permanent URL.
Provenance for every timeline entry
- EXECUTED BY ZAMBOZambo ran the tool call itself.
- OBSERVED VIA GATEWAYA Zambo gateway observed request and response bytes from the named external executor. Zambo did not run that external action.
- LOGGED BY AGENTAn agent or local hook reported the action. Zambo attests that the record is unchanged since logging, not that the action happened as described.
Private agent reasoning, built-in client actions, and direct calls to unrelated MCP servers are not included unless an agent or gateway reports them.
What is this?
An AI agent completed a tool call through Zambo, and this page records the result. The SHA-256 hash below fingerprints exactly what the agent produced. The timestamp shows when it ran. The Nostr anchor posts that fingerprint to public relays, so the record exists outside Zambo too. Check the hash yourself.
What is an execution receipt?
An execution receipt is the public record of one completed AI agent tool call. Read the canonical definition of an AI agent execution receipt.
Keep the work moving
This receipt proves the call completed. When the free allowance is not enough, choose the access path that fits the job.
Or re-run this exact call, using the same tool and arguments.
Share this receipt
Verification checks
- Integrity check: Recomputable from canonical bytes
- Issued by zambo.dev: Served from the zambo.dev receipt store
- Chain valid: Receipt hash chain is internally consistent
- Recorded in the immutable log: 2026-09-28T22:46:24.119Z
Proof of observed execution
EXECUTED BY ZAMBO
- Receipt ID
a5be3691-b208-4118-a132-bbf95cd2db23- SHA-256 output hash
sha256:30912449dfcf20415c7f00c1c3f7ca0d5cd5cf6b1fc707b8f5f33c58c6b5e0ea- Canonical bytes
eyJjYWxsZXIiOnsiaWQiOiJzaGEyNTY6NGYwMWE3NWE5MTNjMDIxZGY3ODY3NTdjZTJjZjVkZWY1ZDRkMjU1NzE1NzM3MDcwNmQ3YzBjZWExNGJlY2MyMyIsInR5cGUiOiJhbm9ueW1vdXMifSwib3V0cHV0Ijp7Imlzc3VlcyI6W3siZGVzY3JpcHRpb24iOiJSZXZvY2F0aW9uIGNoZWNrIG9ubHkgaW5zcGVjdHMgc2VnbWVudHMudHJ1c3QucmV2b2NhdGlvbnMgYW5kIGRvZXMgbm90IGNvbnNpZGVyIGdvdmVybmFuY2Uuc2lnbmluZ19hdXRob3JpdHlfcmVmcywgYWxsb3dpbmcgcmV2b2tlZCBkb21haW7igJFjbGFpbSBldmlkZW5jZSB0byByZW1haW4gZWZmZWN0aXZlLiIsImZpeCI6IkluY2x1ZGUgZ292ZXJuYW5jZS5zaWduaW5nX2F1dGhvcml0eV9yZWZzIGluIHRoZSByZXZvY2F0aW9uIHRyYXZlcnNhbCBvciBlbnN1cmUgcmV2b2NhdGlvbnMgYXJlIHByb3BhZ2F0ZWQgdG8gdGhhdCBsaXN0IGJlZm9yZSB2YWxpZGF0aW9uLiIsImxpbmVfaGludCI6InJldm9rZWRfcmVmcyA9IHNldCgoZG9jdW1lbnQuZ2V0KCdzZWdtZW50cycsIHt9KS5nZXQoJ3RydXN0Jywge30pIG9yIHt9KS5nZXQoJ3Jldm9jYXRpb25zJywgW10pKSIsInNldmVyaXR5IjoiaGlnaCIsInR5cGUiOiJzZWN1cml0eSJ9LHsiZGVzY3JpcHRpb24iOiJFcnJvciBtZXNzYWdlcyBleHBvc2UgaW50ZXJuYWwgdmFsaWRhdGlvbiBkZXRhaWxzLCB3aGljaCBjb3VsZCBhaWQgYW4gYXR0YWNrZXIgaW4gY3JhZnRpbmcgbWFsaWNpb3VzIGRvY3VtZW50cy4iLCJmaXgiOiJSYWlzZSBhIGdlbmVyaWMgZXhjZXB0aW9uIG9yIHNhbml0aXplIG1lc3NhZ2VzIGJlZm9yZSByZXR1cm5pbmcgdGhlbSB0byBjYWxsZXJzLiIsImxpbmVfaGludCI6InJhaXNlIFZhbHVlRXJyb3IoJ2ludmFsaWQgQWdlbnRETkE6ICcgKyAnOyAnLmpvaW4oZXJyb3JzKSkiLCJzZXZlcml0eSI6Im1lZGl1bSIsInR5cGUiOiJzZWN1cml0eSJ9LHsiZGVzY3JpcHRpb24iOiJSZWN1cnNpdmUgdHJhdmVyc2FsIG1heSBlbmNvdW50ZXIgY3ljbGljIHJlZmVyZW5jZXMgbGVhZGluZyB0byBSZWN1cnNpb25FcnJvci4iLCJmaXgiOiJBZGQgY3ljbGUgZGV0ZWN0aW9uIG9yIGxpbWl0IHJlY3Vyc2lvbiBkZXB0aCB3aGVuIHdhbGtpbmcgdGhlIGRvY3VtZW50IHN0cnVjdHVyZS4iLCJsaW5lX2hpbnQiOiJkZWYgcmVmZXJlbmNlZF9ldmlkZW5jZSh2YWx1ZSk6IC4uLiIsInNldmVyaXR5IjoibG93IiwidHlwZSI6InJlYWRhYmlsaXR5In1dLCJsYW5ndWFnZSI6InB5dGhvbiIsIm92ZXJhbGxfc2NvcmUiOjQ1LCJxdWlja193aW5zIjpbIkFkZCBnb3Zlcm5hbmNlLnNpZ25pbmdfYXV0aG9yaXR5X3JlZnMgdG8gcmV2b2NhdGlvbiBzZXQiLCJTYW5pdGl6ZSBleGNlcHRpb24gbWVzc2FnZXMiXSwicmVmYWN0b3Jfc3VnZ2VzdGlvbnMiOlsiRXh0cmFjdCByZXZvY2F0aW9uIGNoZWNraW5nIGludG8gYSBzZXBhcmF0ZSB1dGlsaXR5IGZ1bmN0aW9uIiwiVXNlIHR5cGVkIGRhdGEgc3RydWN0dXJlcyBmb3IgZG9jdW1lbnQgc2NoZW1hIHZhbGlkYXRpb24iXSwic2VjdXJpdHlfZmxhZ3MiOlsicmV2b2tlZCBldmlkZW5jZSBpbiBnb3Zlcm5hbmNlLnNpZ25pbmdfYXV0aG9yaXR5X3JlZnMgbm90IGNoZWNrZWQiLCJpbmZvcm1hdGlvbiBsZWFrYWdlIHZpYSBleGNlcHRpb24gbWVzc2FnZXMiXSwidmVyZGljdCI6IlRoZSBjdXJyZW50IHJldm9jYXRpb24gbG9naWMgaXMgaW5jb21wbGV0ZSBhbmQgbWF5IGFsbG93IGNvbnN1bXB0aW9uIG9mIEFnZW50RE5BIHdpdGggcmV2b2tlZCBkb21haW7igJFjbGFpbSBldmlkZW5jZSwgcmVwcmVzZW50aW5nIGEgc2VjdXJpdHkgcmlzay4ifSwicmVjZWlwdF9zY2hlbWFfdmVyc2lvbiI6IjAuMyIsInNpZGVfZWZmZWN0cyI6eyJkZWNsYXJhdGlvbl9oYXNoIjoic2hhMjU2OjQ1YWFkMzhmM2FhOTgyYjlhYWZlOTJlY2I0MTZlYmU5ODc5MWVkZGJhZjhhYjZkZjBiZDA4NjA1YjdjMWJmZWUiLCJkZWNsYXJlZCI6WyJub25lIl0sInNjaGVtYV92ZXJzaW9uIjoiemFtYm8tc2lkZS1lZmZlY3RzLzEifSwidG9vbCI6eyJuYW1lIjoiY29kZV9yZXZpZXciLCJzY29wZSI6InB1YmxpYyIsInZlcnNpb24iOiI0LjAuMCJ9fQ==- Timestamp
Bound call context
- Receipt schema
0.3- Tool name
code_review- Tool version
4.0.0- Permission scope
public- Caller type
anonymous- Caller ID
sha256:4f01a75a913c021df786757ce2cf5def5d4d2557157370706d7c0cea14becc23- Declared side effects
none- Side-effects schema
zambo-side-effects/1- Declaration hash
sha256:45aad38f3aa982b9aafe92ecb416ebe98791eddbaf8ab6df0bd08605b7c1bfee
This records what the server-side tool contract declared at call time. It does not independently verify that a downstream side effect happened.
Bound upstream evidence
- Status
- no_upstream_bytes_captured
- Evidence SHA-256
unavailable- Byte length
- unavailable
Neutral Nostr anchor
- Event ID
3e6fb51d0ba781b43b27567a8d73ae75963719e20bb99ca3291031866714d530- Anchor status
- published
- Public key
e13475107d30c918ec664adf2ab1141024a22fb35190f82c9e933704fa49af41
Relay hints: wss://relay.damus.io · wss://nos.lol · wss://relay.primal.net
Schema: zambo-receipt-anchor/1
Anchor envelope bytes:
{"anchored_at":"2026-09-28T22:46:24.104Z","evidence_byte_length":null,"evidence_sha256":null,"evidence_url":null,"output_sha256":"sha256:30912449dfcf20415c7f00c1c3f7ca0d5cd5cf6b1fc707b8f5f33c58c6b5e0ea","receipt_uuid":"a5be3691-b208-4118-a132-bbf95cd2db23","schema_version":"zambo-receipt-anchor/1"}
Anchor status "published": Published to all configured relay targets.
Check this hash yourself
Open the verification endpoint. The server recomputes the SHA-256 from the stored bytes and answers verified:true. If it does not say verified, do not trust this page.
See the Nostr anchor event on a public viewer. The fingerprint is timestamped outside Zambo too.
Embed this receipt
Markdown
[](https://zambo.dev/run/a5be3691-b208-4118-a132-bbf95cd2db23)
HTML
<a href="https://zambo.dev/run/a5be3691-b208-4118-a132-bbf95cd2db23"><img src="https://zambo.dev/api/receipt/a5be3691-b208-4118-a132-bbf95cd2db23/badge.svg" alt="Verifiable Zambo receipt"></a>
Recent verifiable receipts
36,729 verifiable receipts minted
Run your own calls. Free, 20 calls per tool per day, no account.