aer1-smolagents
AER-1 verifiable workflow receipts for HuggingFace SmolAgents.
Attach one collector to your agent and every run emits a hash-chained, offline-verifiable verifiable workflow receipt (AER-1, Section 8): what the agent did, in what order, with per-step hashes and a Merkle root over the whole run. No network calls, no behavior changes, the collector only observes.
Install
pip install aer1-smolagents
Use it (two lines)
from aer1_smolagents import AER1ReceiptCollector
from smolagents import ToolCallingAgent, TaskStep, ActionStep
collector = AER1ReceiptCollector(goal="Summarize the quarterly report")
agent = ToolCallingAgent(
tools=[...],
model=...,
step_callbacks={TaskStep: collector, ActionStep: collector}, # line 1
)
answer = agent.run("Summarize the quarterly report")
receipt = collector.finalize(final_answer=answer) # line 2
assert collector.verify(receipt) == [] # VALID
collector.save("receipt.json", workflow=receipt)
That is the whole integration. The receipt is a plain JSON object you can store, ship to an auditor, or render in a UI.
What the receipt contains
Workflow level (AER-1 Section 8, Table 2):
type,version,workflow_id,receipt_id,session_idgoal,statussteps: one record per agent step, seq 1..n in ordermerkle_root: Section 8.1 root over the ordered step receipt idsoutput_hash: SHA-256 of the final answerverify_url: where the verification procedure is documented
Step level (AER-1 Section 8, Table 3):
seq,receipt_id,tool,receipt_hash,started_at,ended_at,status
Each step receipt_hash is SHA-256 over the canonical JSON of what the
step actually did: tool name, arguments, observations, action output, and
error if any. The hash commits to the content; the receipt stays compact.
Verification
collector.verify(receipt) runs the full offline check and returns a
list of failure reasons, empty when valid:
- all Table 2 / Table 3 members present and well-formed
seqvalues exactly 1..n in order, no gaps- no two steps share a
receipt_id(MM-1) merkle_rootmatches the recomputed Section 8.1 root- strict RFC 3339 timestamps, lowercase UUIDs, 64-char hex digests
Tamper with any field and verification fails. Try it:
receipt["steps"][0]["tool"] = ""
assert collector.verify(receipt) != [] # fails, as it should
Notes
- Works with
ToolCallingAgentandCodeAgent. Planning steps are recorded astool: "plan"when the agent emits them. - Pass
goal=to the collector; SmolAgents does not forward the task text through step callbacks in current versions, so the constructor is the reliable place for it. session_iddefaults to a fresh UUID per collector; pass your own to correlate receipts across runs.verify_urldefaults to the AER-1 specification page; point it at your own verifier in production.
Spec
AER-1: Agent Execution Receipts, draft-zambo-aer1,
https://datatracker.ietf.org/doc/draft-zambo-aer1/
License
Apache-2.0
Metadata
Release files for aer1-smolagents 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| aer1_smolagents-0.1.1.tar.gz | 8.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| aer1_smolagents-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 16.3 kB
Release files / aer1_smolagents-0.1.1.tar.gz
| Download URL | aer1_smolagents-0.1.1.tar.gz |
|---|---|
| Size | 8.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
5e7d276086c4230cc8b9433e971907faf6e5da02bf0d2e8e5d045e58e4c13843
|
|
BLAKE2b-256 checksum How to use checksums |
238a430adcf32abecabf895f433e748488ba99cf0bd7e92701db231260b6380a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
rambo-pypi-grab/0.1.0
|
Release files / aer1_smolagents-0.1.1-py3-none-any.whl
| Download URL | aer1_smolagents-0.1.1-py3-none-any.whl |
|---|---|
| Size | 7.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
046221c9290973712cc6ff5c6992aa159d152189266efbd0e8d960d3ff9db1f0
|
|
BLAKE2b-256 checksum How to use checksums |
1cd2d2c6392345c05274c72b75e6239d5af8adbd9bf5a13d3d33223252e8736d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
rambo-pypi-grab/0.1.0
|