Verifiable receipt cd66fb65 - zambo_universal result | Zambo

Verifiable receipt for a zambo_universal call on Zambo: {"status":"executed","primary_tool":"prompt_shield","executed":true,"executed_tools":["prompt_shield"],"

Observed result

{"status":"executed","primary_tool":"prompt_shield","executed":true,"executed_tools":["prompt_shield"],"result":{"recommendation":"block","injection_risk":90,"risk_level":"critical","jailbreak_detected":true,"policy_bypass_detected":true,"prompt_leak_detected":false,"pii_extraction_attempt":false,"flagged_patterns":[{"id":"ignore_instructions","name":"Instruction Override","severity":"critical","description":"Attempts to override system instructions"}],"pattern_count":1,"analysis":{"intent":"malicious","attack_vector":"instruction_override","reasoning":"The prompt attempts to override prior system instructions, a classic jailbreak technique, indicating a moderate to high security risk.","safe_version":"Say hello."},"scan_mode":"deep","latency_ms":892,"pass_used":false,"usage":{"plan":"free","calls_remaining":"19","daily_limit":20,"upgrade":"https://zambo.dev/#zambo-pass"},"_meta":{"tool":"PromptShield by zambo.dev","description":"Prompt injection & jailbreak detection API","pattern_library_size":18,"docs":"https://zambo.dev/api/prompt-shield"}},"verify":{"status":"complete","message":"Prompt Shield returned the live safety analysis. Treat its recommendation as the boundary before sending the prompt to another model."}}

Provenance for every timeline entry

Private agent reasoning, built-in client actions, and direct calls to unrelated MCP servers are not included unless an agent or gateway reports them.

What is this?

Zambo's receipt store reports a tool call and records its result. The SHA-256 commitment covers the exact canonical bytes. The provenance label is bound to v0.4 receipt bytes when that check passes, but no pinned signature or trusted issuer key is checked. An anchor can timestamp a fingerprint; it does not authenticate the issuer.

What is an execution receipt?

An execution receipt is a public record of a reported AI agent tool call. Its byte commitment and provenance claim can be checked independently; neither alone authenticates the issuer. Read the canonical definition of an AI agent execution receipt.

Keep the work moving

This receipt records a completed tool call. When the free allowance is not enough, choose the access path that fits the job.

UNLOCK 24H DAY PASS ($0.99) →

See all plans on the pricing page →

RUN YOUR OWN FREE CALL →

Or re-run this exact call, using the same tool and arguments.

Share this receipt

Share on X ·

Verification checks

Want a verifiable receipt for every job your bots do?

Add Zambo Receipt Bot to your team

Committed provenance claim

EXECUTED BY ZAMBO

The metadata claim is consistent with the verified receipt bytes; issuer is not authenticated.

Receipt ID
cd66fb65-3d0e-499b-8614-38ad40ba8912
SHA-256 output hash
sha256:a98a08f778b9b3d5aa9f5ebae5b5788f0c313da64ecbb94099df5384de564458
Canonical bytes
eyJjYWxsZXIiOnsiYmFzaXMiOiJpcF91YV8zMGQiLCJpZCI6InNoYTI1Njo2ODIyODQ0M2ZlOGIyYzU1NDMzOThiMWYyZDVhNjAyZTZjNDNiNjg4MmYxN2QxNWNmYjUzYjgyODBmYjZkNTkxIiwicm90YXRlc19hdCI6IjIwMjYtMTEtMDNUMDA6MDA6MDAuMDAwWiIsInR5cGUiOiJhbm9ueW1vdXMifSwiaXNzdWVyX2NsYWltcyI6eyJwcm92ZW5hbmNlX2NsYXNzIjoiRVhFQ1VURUQgQlkgWkFNQk8ifSwib3V0cHV0Ijp7ImV4ZWN1dGVkIjp0cnVlLCJleGVjdXRlZF90b29scyI6WyJwcm9tcHRfc2hpZWxkIl0sInByaW1hcnlfdG9vbCI6InByb21wdF9zaGllbGQiLCJyZXN1bHQiOnsiX21ldGEiOnsiZGVzY3JpcHRpb24iOiJQcm9tcHQgaW5qZWN0aW9uICYgamFpbGJyZWFrIGRldGVjdGlvbiBBUEkiLCJkb2NzIjoiaHR0cHM6Ly96YW1iby5kZXYvYXBpL3Byb21wdC1zaGllbGQiLCJwYXR0ZXJuX2xpYnJhcnlfc2l6ZSI6MTgsInRvb2wiOiJQcm9tcHRTaGllbGQgYnkgemFtYm8uZGV2In0sImFuYWx5c2lzIjp7ImF0dGFja192ZWN0b3IiOiJpbnN0cnVjdGlvbl9vdmVycmlkZSIsImludGVudCI6Im1hbGljaW91cyIsInJlYXNvbmluZyI6IlRoZSBwcm9tcHQgYXR0ZW1wdHMgdG8gb3ZlcnJpZGUgcHJpb3Igc3lzdGVtIGluc3RydWN0aW9ucywgYSBjbGFzc2ljIGphaWxicmVhayB0ZWNobmlxdWUsIGluZGljYXRpbmcgYSBtb2RlcmF0ZSB0byBoaWdoIHNlY3VyaXR5IHJpc2suIiwic2FmZV92ZXJzaW9uIjoiU2F5IGhlbGxvLiJ9LCJmbGFnZ2VkX3BhdHRlcm5zIjpbeyJkZXNjcmlwdGlvbiI6IkF0dGVtcHRzIHRvIG92ZXJyaWRlIHN5c3RlbSBpbnN0cnVjdGlvbnMiLCJpZCI6Imlnbm9yZV9pbnN0cnVjdGlvbnMiLCJuYW1lIjoiSW5zdHJ1Y3Rpb24gT3ZlcnJpZGUiLCJzZXZlcml0eSI6ImNyaXRpY2FsIn1dLCJpbmplY3Rpb25fcmlzayI6OTAsImphaWxicmVha19kZXRlY3RlZCI6dHJ1ZSwibGF0ZW5jeV9tcyI6ODkyLCJwYXNzX3VzZWQiOmZhbHNlLCJwYXR0ZXJuX2NvdW50IjoxLCJwaWlfZXh0cmFjdGlvbl9hdHRlbXB0IjpmYWxzZSwicG9saWN5X2J5cGFzc19kZXRlY3RlZCI6dHJ1ZSwicHJvbXB0X2xlYWtfZGV0ZWN0ZWQiOmZhbHNlLCJyZWNvbW1lbmRhdGlvbiI6ImJsb2NrIiwicmlza19sZXZlbCI6ImNyaXRpY2FsIiwic2Nhbl9tb2RlIjoiZGVlcCIsInVzYWdlIjp7ImNhbGxzX3JlbWFpbmluZyI6IjE5IiwiZGFpbHlfbGltaXQiOjIwLCJwbGFuIjoiZnJlZSIsInVwZ3JhZGUiOiJodHRwczovL3phbWJvLmRldi8jemFtYm8tcGFzcyJ9fSwic3RhdHVzIjoiZXhlY3V0ZWQiLCJ2ZXJpZnkiOnsibWVzc2FnZSI6IlByb21wdCBTaGllbGQgcmV0dXJuZWQgdGhlIGxpdmUgc2FmZXR5IGFuYWx5c2lzLiBUcmVhdCBpdHMgcmVjb21tZW5kYXRpb24gYXMgdGhlIGJvdW5kYXJ5IGJlZm9yZSBzZW5kaW5nIHRoZSBwcm9tcHQgdG8gYW5vdGhlciBtb2RlbC4iLCJzdGF0dXMiOiJjb21wbGV0ZSJ9fSwicmVjZWlwdF9zY2hlbWFfdmVyc2lvbiI6IjAuNCIsInNpZGVfZWZmZWN0cyI6eyJkZWNsYXJhdGlvbl9oYXNoIjoic2hhMjU2OmRmYjQ0MTJhYTQyOWQzYWM2MzdhMDU2NjhjNDM1YmNjOTBhMjUxMzYzZmNkZDQ5ZjdiODVhZTRhYjU1YjViYzkiLCJkZWNsYXJlZCI6WyJzdGF0ZV93cml0ZSJdLCJzY2hlbWFfdmVyc2lvbiI6InphbWJvLXNpZGUtZWZmZWN0cy8xIn0sInRvb2wiOnsibmFtZSI6InphbWJvX3VuaXZlcnNhbCIsInNjb3BlIjoicHVibGljIiwidmVyc2lvbiI6IjQuMC4wIn19
Timestamp

Bound call context

Receipt schema
0.4
Tool name
zambo_universal
Tool version
4.0.0
Permission scope
public
Caller type
anonymous
Caller ID
sha256:68228443fe8b2c5543398b1f2d5a602e6c43b6882f17d15cfb53b8280fb6d591
Caller basis
ip_ua_30d
Caller rotates at
2026-11-03T00:00:00.000Z
Declared side effects
state_write
Side-effects schema
zambo-side-effects/1
Declaration hash
sha256:dfb4412aa429d3ac637a05668c435bcc90a251363fcdd49f7b85ae4ab55b5bc9

This records what the server-side tool contract declared at call time. It does not independently verify that a downstream side effect happened.

Bound upstream evidence

Status
captured
Evidence SHA-256
sha256:53f7bf734efe5fe00bc0e326bccc64e2b65bc1ffdcf57f4c8fa19fa0745510f8
Byte length
948

Fetch exact evidence bytes

Neutral Nostr anchor

Event ID
5a86320cc64ca1b918d7f31f0c58307f86db0f405d2a1f717ae965d2372430d4
Anchor status
partial
Public key
e13475107d30c918ec664adf2ab1141024a22fb35190f82c9e933704fa49af41

Relay hints: wss://relay.damus.io · wss://nos.lol · wss://relay.primal.net

Schema: zambo-receipt-anchor/1

Anchor envelope bytes:

{"anchored_at":"2026-10-10T11:09:30.144Z","evidence_byte_length":948,"evidence_sha256":"sha256:53f7bf734efe5fe00bc0e326bccc64e2b65bc1ffdcf57f4c8fa19fa0745510f8","evidence_url":"https://zambo.dev/api/evidence/53f7bf734efe5fe00bc0e326bccc64e2b65bc1ffdcf57f4c8fa19fa0745510f8","output_sha256":"sha256:a98a08f778b9b3d5aa9f5ebae5b5788f0c313da64ecbb94099df5384de564458","receipt_uuid":"cd66fb65-3d0e-499b-8614-38ad40ba8912","schema_version":"zambo-receipt-anchor/1"}

Anchor status "partial": Published to some configured relay targets; publication was not confirmed by every configured relay.

Check this hash yourself

Recompute the SHA-256 commitment in your browser. Open the API v2 JSON response to inspect the machine-readable checks. Signature and chain remain NOT CHECKED unless a real signature verifier or chain proof is supplied. There is no combined “verified” verdict. See the Nostr anchor event on a public viewer. The fingerprint is timestamped outside Zambo too.

Embed this receipt

Markdown

[![Verifiable Zambo receipt](https://zambo.dev/api/receipt/cd66fb65-3d0e-499b-8614-38ad40ba8912/badge.svg)](https://zambo.dev/run/cd66fb65-3d0e-499b-8614-38ad40ba8912)

HTML

<a href="https://zambo.dev/run/cd66fb65-3d0e-499b-8614-38ad40ba8912"><img src="https://zambo.dev/api/receipt/cd66fb65-3d0e-499b-8614-38ad40ba8912/badge.svg" alt="Verifiable Zambo receipt"></a>

Open badge SVG

Recent receipts

41,712 verifiable receipts minted

RUN YOUR OWN FREE CALL →

Run your own calls. Free, 20 free calls per metered tool each day, no account.

Open the interactive receipt view