Verifiable receipt e946d309 - prompt_shield result | Zambo

Verifiable receipt for a prompt_shield call on Zambo: {"recommendation":"safe","injection_risk":0,"risk_level":"low","jailbreak_detected":false,"policy_bypass_d

Observed result

{"recommendation":"safe","injection_risk":0,"risk_level":"low","jailbreak_detected":false,"policy_bypass_detected":false,"prompt_leak_detected":false,"pii_extraction_attempt":false,"flagged_patterns":[],"pattern_count":0,"analysis":{"intent":"benign","attack_vector":null,"reasoning":"No injection patterns detected","safe_version":null},"scan_mode":"pattern","latency_ms":0,"pass_used":false,"usage":{"plan":"free","calls_remaining":"19","daily_limit":20,"upgrade":"https://zambo.dev/#zambo-pass"},"_meta":{"tool":"PromptShield by zambo.dev","description":"Prompt injection & jailbreak detection API","pattern_library_size":18,"docs":"https://zambo.dev/api/prompt-shield"}}

Provenance for every timeline entry

Private agent reasoning, built-in client actions, and direct calls to unrelated MCP servers are not included unless an agent or gateway reports them.

What is this?

An AI agent completed a tool call through Zambo, and this page records the result. The SHA-256 hash below fingerprints exactly what the agent produced. The timestamp shows when it ran. The Nostr anchor posts that fingerprint to public relays, so the record exists outside Zambo too. Check the hash yourself.

What is an execution receipt?

An execution receipt is the public record of one completed AI agent tool call. Read the canonical definition of an AI agent execution receipt.

Keep the work moving

This receipt proves the call completed. When the free allowance is not enough, choose the access path that fits the job.

UNLOCK 24H DAY PASS ($0.99) →

See all plans on the pricing page →

RUN YOUR OWN FREE CALL →

Or re-run this exact call, using the same tool and arguments.

Share this receipt

Share on X ·

Verification checks

Proof of observed execution

EXECUTED BY ZAMBO

Receipt ID
e946d309-aaf4-4df5-bead-b818006df1a4
SHA-256 output hash
sha256:2adc69de67c7e7f585a0a8019660f44bbd8a3b724f2484a232bdf2929be49e2d
Canonical bytes
eyJjYWxsZXIiOnsiaWQiOiJzaGEyNTY6ZjkzYjk2ODRjZDdiZTNkZDI3MGQ5OWRhYmFmY2Y5MTZlZDY4NzZhYzhmMTQxN2RhMmU5MzI0OGE3MWU2NmFlOCIsInR5cGUiOiJhbm9ueW1vdXMifSwib3V0cHV0Ijp7Il9tZXRhIjp7ImRlc2NyaXB0aW9uIjoiUHJvbXB0IGluamVjdGlvbiAmIGphaWxicmVhayBkZXRlY3Rpb24gQVBJIiwiZG9jcyI6Imh0dHBzOi8vemFtYm8uZGV2L2FwaS9wcm9tcHQtc2hpZWxkIiwicGF0dGVybl9saWJyYXJ5X3NpemUiOjE4LCJ0b29sIjoiUHJvbXB0U2hpZWxkIGJ5IHphbWJvLmRldiJ9LCJhbmFseXNpcyI6eyJhdHRhY2tfdmVjdG9yIjpudWxsLCJpbnRlbnQiOiJiZW5pZ24iLCJyZWFzb25pbmciOiJObyBpbmplY3Rpb24gcGF0dGVybnMgZGV0ZWN0ZWQiLCJzYWZlX3ZlcnNpb24iOm51bGx9LCJmbGFnZ2VkX3BhdHRlcm5zIjpbXSwiaW5qZWN0aW9uX3Jpc2siOjAsImphaWxicmVha19kZXRlY3RlZCI6ZmFsc2UsImxhdGVuY3lfbXMiOjAsInBhc3NfdXNlZCI6ZmFsc2UsInBhdHRlcm5fY291bnQiOjAsInBpaV9leHRyYWN0aW9uX2F0dGVtcHQiOmZhbHNlLCJwb2xpY3lfYnlwYXNzX2RldGVjdGVkIjpmYWxzZSwicHJvbXB0X2xlYWtfZGV0ZWN0ZWQiOmZhbHNlLCJyZWNvbW1lbmRhdGlvbiI6InNhZmUiLCJyaXNrX2xldmVsIjoibG93Iiwic2Nhbl9tb2RlIjoicGF0dGVybiIsInVzYWdlIjp7ImNhbGxzX3JlbWFpbmluZyI6IjE5IiwiZGFpbHlfbGltaXQiOjIwLCJwbGFuIjoiZnJlZSIsInVwZ3JhZGUiOiJodHRwczovL3phbWJvLmRldi8jemFtYm8tcGFzcyJ9fSwicmVjZWlwdF9zY2hlbWFfdmVyc2lvbiI6IjAuMyIsInNpZGVfZWZmZWN0cyI6eyJkZWNsYXJhdGlvbl9oYXNoIjoic2hhMjU2OjQ1YWFkMzhmM2FhOTgyYjlhYWZlOTJlY2I0MTZlYmU5ODc5MWVkZGJhZjhhYjZkZjBiZDA4NjA1YjdjMWJmZWUiLCJkZWNsYXJlZCI6WyJub25lIl0sInNjaGVtYV92ZXJzaW9uIjoiemFtYm8tc2lkZS1lZmZlY3RzLzEifSwidG9vbCI6eyJuYW1lIjoicHJvbXB0X3NoaWVsZCIsInNjb3BlIjoicHVibGljIiwidmVyc2lvbiI6IjQuMC4wIn19
Timestamp

Bound call context

Receipt schema
0.3
Tool name
prompt_shield
Tool version
4.0.0
Permission scope
public
Caller type
anonymous
Caller ID
sha256:f93b9684cd7be3dd270d99dabafcf916ed6876ac8f1417da2e93248a71e66ae8
Declared side effects
none
Side-effects schema
zambo-side-effects/1
Declaration hash
sha256:45aad38f3aa982b9aafe92ecb416ebe98791eddbaf8ab6df0bd08605b7c1bfee

This records what the server-side tool contract declared at call time. It does not independently verify that a downstream side effect happened.

Bound upstream evidence

Status
captured
Evidence SHA-256
sha256:750f94019fc5c2e41ec6948b9a9eb034c3a02e7ffed00edf3b2813f8775841a0
Byte length
674

Fetch exact evidence bytes

Neutral Nostr anchor

Event ID
39c70a0588008d99420063d36827cce6121517451ce1e257d081985e8d0797b7
Anchor status
published
Public key
e13475107d30c918ec664adf2ab1141024a22fb35190f82c9e933704fa49af41

Relay hints: wss://relay.damus.io · wss://nos.lol · wss://relay.primal.net

Schema: zambo-receipt-anchor/1

Anchor envelope bytes:

{"anchored_at":"2026-10-04T11:03:03.881Z","evidence_byte_length":674,"evidence_sha256":"sha256:750f94019fc5c2e41ec6948b9a9eb034c3a02e7ffed00edf3b2813f8775841a0","evidence_url":"https://zambo.dev/api/evidence/750f94019fc5c2e41ec6948b9a9eb034c3a02e7ffed00edf3b2813f8775841a0","output_sha256":"sha256:2adc69de67c7e7f585a0a8019660f44bbd8a3b724f2484a232bdf2929be49e2d","receipt_uuid":"e946d309-aaf4-4df5-bead-b818006df1a4","schema_version":"zambo-receipt-anchor/1"}

Anchor status "published": Published to all configured relay targets.

Check this hash yourself

Open the verification endpoint. The server recomputes the SHA-256 from the stored bytes and answers verified:true. If it does not say verified, do not trust this page. See the Nostr anchor event on a public viewer. The fingerprint is timestamped outside Zambo too.

Embed this receipt

Markdown

[![Verifiable Zambo receipt](https://zambo.dev/api/receipt/e946d309-aaf4-4df5-bead-b818006df1a4/badge.svg)](https://zambo.dev/run/e946d309-aaf4-4df5-bead-b818006df1a4)

HTML

<a href="https://zambo.dev/run/e946d309-aaf4-4df5-bead-b818006df1a4"><img src="https://zambo.dev/api/receipt/e946d309-aaf4-4df5-bead-b818006df1a4/badge.svg" alt="Verifiable Zambo receipt"></a>

Open badge SVG

Recent verifiable receipts

39,329 verifiable receipts minted

RUN YOUR OWN FREE CALL →

Run your own calls. Free, 20 calls per tool per day, no account.

Open the interactive receipt view