Verifiable receipt f0ef620b — prompt_shield result | Zambo

Verifiable receipt for a prompt_shield call on Zambo: {"recommendation":"safe","injection_risk":0,"risk_level":"low","jailbreak_detected":false,"policy_bypass_d

What is this?

An AI agent did real work through Zambo, and this page is the proof. The SHA-256 hash below is a fingerprint of exactly what the agent produced — change one character of the output and the fingerprint changes. The timestamp shows when it ran. The Nostr anchor posts that fingerprint to public relays, so the record exists outside Zambo too — anyone can look it up by the event ID below. You don't have to take the agent's word for it. Check the hash yourself.

What is an execution receipt?

An execution receipt is the public record of one completed AI agent tool call. Read the canonical definition of an AI agent execution receipt.

Observed result

{"recommendation":"safe","injection_risk":0,"risk_level":"low","jailbreak_detected":false,"policy_bypass_detected":false,"prompt_leak_detected":false,"pii_extraction_attempt":false,"flagged_patterns":[],"pattern_count":0,"analysis":{"intent":"benign","attack_vector":null,"reasoning":"No injection patterns detected","safe_version":null},"scan_mode":"pattern","latency_ms":3,"pass_used":false,"usage":{"plan":"free","calls_remaining":"49","daily_limit":50,"upgrade":"https://zambo.dev/#zambo-pass"},"_meta":{"tool":"PromptShield by zambo.dev","description":"Prompt injection & jailbreak detection API","pattern_library_size":18,"docs":"https://zambo.dev/api/prompt-shield"}}

Keep the work moving

This receipt proves the call completed. When the free allowance is not enough, choose the access path that fits the job.

UNLOCK 24H DAY PASS ($1.49) → ZAMBO PASS $49 →

RUN YOUR OWN FREE CALL →

Or re-run this exact call — same tool, same arguments.

Share this receipt

Share on X ·

Verification checks

Proof of observed execution

Receipt ID
f0ef620b-7567-4f78-b44e-63abb80b8bbf
SHA-256 output hash
sha256:5be67e8dbe82a1e3935ae138f7076251efae6f08ac7648fde8f4eb783586011b
Canonical bytes
eyJjYWxsZXIiOnsiaWQiOiJzaGEyNTY6ZWZjN2MzMjEyMWRmYzFiM2M3NzRjZjUwYTUyZjY2YjdhNjg0ZWUzOTE2NDgyODAwMjFlNjAyZjMyZmE0OTgxZCIsInR5cGUiOiJhbm9ueW1vdXMifSwib3V0cHV0Ijp7Il9tZXRhIjp7ImRlc2NyaXB0aW9uIjoiUHJvbXB0IGluamVjdGlvbiAmIGphaWxicmVhayBkZXRlY3Rpb24gQVBJIiwiZG9jcyI6Imh0dHBzOi8vemFtYm8uZGV2L2FwaS9wcm9tcHQtc2hpZWxkIiwicGF0dGVybl9saWJyYXJ5X3NpemUiOjE4LCJ0b29sIjoiUHJvbXB0U2hpZWxkIGJ5IHphbWJvLmRldiJ9LCJhbmFseXNpcyI6eyJhdHRhY2tfdmVjdG9yIjpudWxsLCJpbnRlbnQiOiJiZW5pZ24iLCJyZWFzb25pbmciOiJObyBpbmplY3Rpb24gcGF0dGVybnMgZGV0ZWN0ZWQiLCJzYWZlX3ZlcnNpb24iOm51bGx9LCJmbGFnZ2VkX3BhdHRlcm5zIjpbXSwiaW5qZWN0aW9uX3Jpc2siOjAsImphaWxicmVha19kZXRlY3RlZCI6ZmFsc2UsImxhdGVuY3lfbXMiOjMsInBhc3NfdXNlZCI6ZmFsc2UsInBhdHRlcm5fY291bnQiOjAsInBpaV9leHRyYWN0aW9uX2F0dGVtcHQiOmZhbHNlLCJwb2xpY3lfYnlwYXNzX2RldGVjdGVkIjpmYWxzZSwicHJvbXB0X2xlYWtfZGV0ZWN0ZWQiOmZhbHNlLCJyZWNvbW1lbmRhdGlvbiI6InNhZmUiLCJyaXNrX2xldmVsIjoibG93Iiwic2Nhbl9tb2RlIjoicGF0dGVybiIsInVzYWdlIjp7ImNhbGxzX3JlbWFpbmluZyI6IjQ5IiwiZGFpbHlfbGltaXQiOjUwLCJwbGFuIjoiZnJlZSIsInVwZ3JhZGUiOiJodHRwczovL3phbWJvLmRldi8jemFtYm8tcGFzcyJ9fSwicmVjZWlwdF9zY2hlbWFfdmVyc2lvbiI6IjAuMyIsInNpZGVfZWZmZWN0cyI6eyJkZWNsYXJhdGlvbl9oYXNoIjoic2hhMjU2OjQ1YWFkMzhmM2FhOTgyYjlhYWZlOTJlY2I0MTZlYmU5ODc5MWVkZGJhZjhhYjZkZjBiZDA4NjA1YjdjMWJmZWUiLCJkZWNsYXJlZCI6WyJub25lIl0sInNjaGVtYV92ZXJzaW9uIjoiemFtYm8tc2lkZS1lZmZlY3RzLzEifSwidG9vbCI6eyJuYW1lIjoicHJvbXB0X3NoaWVsZCIsInNjb3BlIjoicHVibGljIiwidmVyc2lvbiI6IjQuMC4wIn19
Timestamp

Bound call context

Receipt schema
0.3
Tool name
prompt_shield
Tool version
4.0.0
Permission scope
public
Caller type
anonymous
Caller ID
sha256:efc7c32121dfc1b3c774cf50a52f66b7a684ee391648280021e602f32fa4981d
Declared side effects
none
Side-effects schema
zambo-side-effects/1
Declaration hash
sha256:45aad38f3aa982b9aafe92ecb416ebe98791eddbaf8ab6df0bd08605b7c1bfee

This records what the server-side tool contract declared at call time. It does not independently verify that a downstream side effect happened.

Bound upstream evidence

Status
captured
Evidence SHA-256
sha256:f5c7839e33890692c7348c1d3fccb2fbeba36a66318813f106852a367e9cec3f
Byte length
674

Fetch exact evidence bytes

Neutral Nostr anchor

Event ID
ebe4c0bf35d90c352b8a9a037e269e110e590ba868d18b78718726bd1d84c025
Anchor status
published
Public key
e13475107d30c918ec664adf2ab1141024a22fb35190f82c9e933704fa49af41

Relay hints: wss://relay.damus.io · wss://nos.lol · wss://relay.primal.net

Schema: zambo-receipt-anchor/1

Anchor envelope bytes:

{"anchored_at":"2026-09-21T16:42:35.685Z","evidence_byte_length":674,"evidence_sha256":"sha256:f5c7839e33890692c7348c1d3fccb2fbeba36a66318813f106852a367e9cec3f","evidence_url":"https://zambo.dev/api/evidence/f5c7839e33890692c7348c1d3fccb2fbeba36a66318813f106852a367e9cec3f","output_sha256":"sha256:5be67e8dbe82a1e3935ae138f7076251efae6f08ac7648fde8f4eb783586011b","receipt_uuid":"f0ef620b-7567-4f78-b44e-63abb80b8bbf","schema_version":"zambo-receipt-anchor/1"}

Anchor status "published": Published to all configured relay targets.

Check this hash yourself

Open the verification endpoint — the server recomputes the SHA-256 from the stored bytes and answers verified:true. If it doesn't say verified, don't trust this page. See the Nostr anchor event on a public viewer — the fingerprint is timestamped outside Zambo too.

Embed this receipt

Markdown

[![Verifiable Zambo receipt](https://zambo.dev/api/receipt/f0ef620b-7567-4f78-b44e-63abb80b8bbf/badge.svg)](https://zambo.dev/run/f0ef620b-7567-4f78-b44e-63abb80b8bbf)

HTML

<a href="https://zambo.dev/run/f0ef620b-7567-4f78-b44e-63abb80b8bbf"><img src="https://zambo.dev/api/receipt/f0ef620b-7567-4f78-b44e-63abb80b8bbf/badge.svg" alt="Verifiable Zambo receipt"></a>

Open badge SVG

Recent verifiable receipts

32,890 verifiable receipts minted

RUN YOUR OWN FREE CALL →

Open the interactive receipt view