Verifiable receipt def354db - prompt_shield result | Zambo

Verifiable receipt for a prompt_shield call on Zambo: {"recommendation":"safe","injection_risk":0,"risk_level":"low","jailbreak_detected":false,"policy_bypass_d

Observed result

{"recommendation":"safe","injection_risk":0,"risk_level":"low","jailbreak_detected":false,"policy_bypass_detected":false,"prompt_leak_detected":false,"pii_extraction_attempt":false,"flagged_patterns":[],"pattern_count":0,"analysis":{"intent":"benign","attack_vector":null,"reasoning":"No injection patterns detected","safe_version":null},"scan_mode":"pattern","latency_ms":0,"pass_used":false,"usage":{"plan":"free","calls_remaining":"46","daily_limit":50,"upgrade":"https://zambo.dev/#zambo-pass"},"_meta":{"tool":"PromptShield by zambo.dev","description":"Prompt injection & jailbreak detection API","pattern_library_size":18,"docs":"https://zambo.dev/api/prompt-shield"}}

Provenance for every timeline entry

Private agent reasoning, built-in client actions, and direct calls to unrelated MCP servers are not included unless an agent or gateway reports them.

What is this?

An AI agent completed a tool call through Zambo, and this page records the result. The SHA-256 hash below fingerprints exactly what the agent produced. The timestamp shows when it ran. The Nostr anchor posts that fingerprint to public relays, so the record exists outside Zambo too. Check the hash yourself.

What is an execution receipt?

An execution receipt is the public record of one completed AI agent tool call. Read the canonical definition of an AI agent execution receipt.

Keep the work moving

This receipt proves the call completed. When the free allowance is not enough, choose the access path that fits the job.

UNLOCK 24H DAY PASS ($0.99) →

See all plans on the pricing page →

RUN YOUR OWN FREE CALL →

Or re-run this exact call, using the same tool and arguments.

Share this receipt

Share on X ·

Verification checks

Proof of observed execution

EXECUTED BY ZAMBO

Receipt ID
def354db-ab74-4374-8af5-21cae660660b
SHA-256 output hash
sha256:544af440e3326e37b95943861c595fc46586489b673725622064456d2fab6ef0
Canonical bytes
eyJjYWxsZXIiOnsiaWQiOiJzaGEyNTY6ZmI4NzUwNzc2ZjgyM2JjMDUwOGVlM2Y5MzFkYjM5ZDFjZTNhOGVhNmNlOWNmNDk3YjIwODBkYjk4NTE3ODE4ZSIsInR5cGUiOiJhbm9ueW1vdXMifSwib3V0cHV0Ijp7Il9tZXRhIjp7ImRlc2NyaXB0aW9uIjoiUHJvbXB0IGluamVjdGlvbiAmIGphaWxicmVhayBkZXRlY3Rpb24gQVBJIiwiZG9jcyI6Imh0dHBzOi8vemFtYm8uZGV2L2FwaS9wcm9tcHQtc2hpZWxkIiwicGF0dGVybl9saWJyYXJ5X3NpemUiOjE4LCJ0b29sIjoiUHJvbXB0U2hpZWxkIGJ5IHphbWJvLmRldiJ9LCJhbmFseXNpcyI6eyJhdHRhY2tfdmVjdG9yIjpudWxsLCJpbnRlbnQiOiJiZW5pZ24iLCJyZWFzb25pbmciOiJObyBpbmplY3Rpb24gcGF0dGVybnMgZGV0ZWN0ZWQiLCJzYWZlX3ZlcnNpb24iOm51bGx9LCJmbGFnZ2VkX3BhdHRlcm5zIjpbXSwiaW5qZWN0aW9uX3Jpc2siOjAsImphaWxicmVha19kZXRlY3RlZCI6ZmFsc2UsImxhdGVuY3lfbXMiOjAsInBhc3NfdXNlZCI6ZmFsc2UsInBhdHRlcm5fY291bnQiOjAsInBpaV9leHRyYWN0aW9uX2F0dGVtcHQiOmZhbHNlLCJwb2xpY3lfYnlwYXNzX2RldGVjdGVkIjpmYWxzZSwicHJvbXB0X2xlYWtfZGV0ZWN0ZWQiOmZhbHNlLCJyZWNvbW1lbmRhdGlvbiI6InNhZmUiLCJyaXNrX2xldmVsIjoibG93Iiwic2Nhbl9tb2RlIjoicGF0dGVybiIsInVzYWdlIjp7ImNhbGxzX3JlbWFpbmluZyI6IjQ2IiwiZGFpbHlfbGltaXQiOjUwLCJwbGFuIjoiZnJlZSIsInVwZ3JhZGUiOiJodHRwczovL3phbWJvLmRldi8jemFtYm8tcGFzcyJ9fSwicmVjZWlwdF9zY2hlbWFfdmVyc2lvbiI6IjAuMyIsInNpZGVfZWZmZWN0cyI6eyJkZWNsYXJhdGlvbl9oYXNoIjoic2hhMjU2OjQ1YWFkMzhmM2FhOTgyYjlhYWZlOTJlY2I0MTZlYmU5ODc5MWVkZGJhZjhhYjZkZjBiZDA4NjA1YjdjMWJmZWUiLCJkZWNsYXJlZCI6WyJub25lIl0sInNjaGVtYV92ZXJzaW9uIjoiemFtYm8tc2lkZS1lZmZlY3RzLzEifSwidG9vbCI6eyJuYW1lIjoicHJvbXB0X3NoaWVsZCIsInNjb3BlIjoicHVibGljIiwidmVyc2lvbiI6IjQuMC4wIn19
Timestamp

Bound call context

Receipt schema
0.3
Tool name
prompt_shield
Tool version
4.0.0
Permission scope
public
Caller type
anonymous
Caller ID
sha256:fb8750776f823bc0508ee3f931db39d1ce3a8ea6ce9cf497b2080db98517818e
Declared side effects
none
Side-effects schema
zambo-side-effects/1
Declaration hash
sha256:45aad38f3aa982b9aafe92ecb416ebe98791eddbaf8ab6df0bd08605b7c1bfee

This records what the server-side tool contract declared at call time. It does not independently verify that a downstream side effect happened.

Bound upstream evidence

Status
captured
Evidence SHA-256
sha256:37deabc816512c5389f81791eb7da18c62f531af26f0481164c8b3d20ff9cdcf
Byte length
674

Fetch exact evidence bytes

Neutral Nostr anchor

Event ID
66f72ae38a5227926064ca5925da415e10e07448fb656e0ce5b123c08a2be134
Anchor status
partial
Public key
e13475107d30c918ec664adf2ab1141024a22fb35190f82c9e933704fa49af41

Relay hints: wss://relay.damus.io · wss://nos.lol · wss://relay.primal.net

Schema: zambo-receipt-anchor/1

Anchor envelope bytes:

{"anchored_at":"2026-09-29T17:13:58.226Z","evidence_byte_length":674,"evidence_sha256":"sha256:37deabc816512c5389f81791eb7da18c62f531af26f0481164c8b3d20ff9cdcf","evidence_url":"https://zambo.dev/api/evidence/37deabc816512c5389f81791eb7da18c62f531af26f0481164c8b3d20ff9cdcf","output_sha256":"sha256:544af440e3326e37b95943861c595fc46586489b673725622064456d2fab6ef0","receipt_uuid":"def354db-ab74-4374-8af5-21cae660660b","schema_version":"zambo-receipt-anchor/1"}

Anchor status "partial": Published to some configured relay targets; publication was not confirmed by every configured relay.

Check this hash yourself

Open the verification endpoint. The server recomputes the SHA-256 from the stored bytes and answers verified:true. If it does not say verified, do not trust this page. See the Nostr anchor event on a public viewer. The fingerprint is timestamped outside Zambo too.

Embed this receipt

Markdown

[![Verifiable Zambo receipt](https://zambo.dev/api/receipt/def354db-ab74-4374-8af5-21cae660660b/badge.svg)](https://zambo.dev/run/def354db-ab74-4374-8af5-21cae660660b)

HTML

<a href="https://zambo.dev/run/def354db-ab74-4374-8af5-21cae660660b"><img src="https://zambo.dev/api/receipt/def354db-ab74-4374-8af5-21cae660660b/badge.svg" alt="Verifiable Zambo receipt"></a>

Open badge SVG

Recent verifiable receipts

37,737 verifiable receipts minted

RUN YOUR OWN FREE CALL →

Run your own calls. Free, 20 calls per tool per day, no account.

Open the interactive receipt view