aer1-smolagents
AER-1 verifiable workflow receipts for HuggingFace SmolAgents.
Attach one collector to your agent and every run emits a hash-chained, offline-verifiable verifiable workflow receipt (AER-1, Section 8): what the agent did, in what order, with per-step hashes and a Merkle root over the whole run. No network calls, no behavior changes, the collector only observes.
Install
pip install aer1-smolagents
Use it (two lines)
from aer1_smolagents import AER1ReceiptCollector
from smolagents import ToolCallingAgent, TaskStep, ActionStep
collector = AER1ReceiptCollector(goal="Summarize the quarterly report")
agent = ToolCallingAgent(
tools=[...],
model=...,
step_callbacks={TaskStep: collector, ActionStep: collector}, # line 1
)
answer = agent.run("Summarize the quarterly report")
receipt = collector.finalize(final_answer=answer) # line 2
assert collector.verify(receipt) == [] # VALID
collector.save("receipt.json", workflow=receipt)
That is the whole integration. The receipt is a plain JSON object you can store, ship to an auditor, or render in a UI.
What the receipt contains
Workflow level (AER-1 Section 8, Table 2):
type,version,workflow_id,receipt_id,session_idgoal,statussteps: one record per agent step, seq 1..n in ordermerkle_root: Section 8.1 root over the ordered step receipt idsoutput_hash: SHA-256 of the final answerverify_url: where the verification procedure is documented
Step level (AER-1 Section 8, Table 3):
seq,receipt_id,tool,receipt_hash,started_at,ended_at,status
Each step receipt_hash is SHA-256 over the canonical JSON of what the
step actually did: tool name, arguments, observations, action output, and
error if any. The hash commits to the content; the receipt stays compact.
Verification
collector.verify(receipt) runs the full offline check and returns a
list of failure reasons, empty when valid:
- all Table 2 / Table 3 members present and well-formed
seqvalues exactly 1..n in order, no gaps- no two steps share a
receipt_id(MM-1) merkle_rootmatches the recomputed Section 8.1 root- strict RFC 3339 timestamps, lowercase UUIDs, 64-char hex digests
Tamper with any field and verification fails. Try it:
receipt["steps"][0]["tool"] = ""
assert collector.verify(receipt) != [] # fails, as it should
Notes
- Works with
ToolCallingAgentandCodeAgent. Planning steps are recorded astool: "plan"when the agent emits them. - Pass
goal=to the collector; SmolAgents does not forward the task text through step callbacks in current versions, so the constructor is the reliable place for it. session_iddefaults to a fresh UUID per collector; pass your own to correlate receipts across runs.verify_urldefaults to the AER-1 specification page; point it at your own verifier in production.
Spec
AER-1: Agent Execution Receipts, draft-zambo-aer1,
https://datatracker.ietf.org/doc/draft-zambo-aer1/
License
Apache-2.0
Metadata
Release files for aer1-smolagents 0.1.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| aer1_smolagents-0.1.2.tar.gz | 8.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| aer1_smolagents-0.1.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 16.3 kB
Release files / aer1_smolagents-0.1.2.tar.gz
| Download URL | aer1_smolagents-0.1.2.tar.gz |
|---|---|
| Size | 8.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
7aee6c916958507bfa42e3fe94eae6f044a81a90c270395b0a16c8d8051395ab
|
|
BLAKE2b-256 checksum How to use checksums |
71edb95a9a10658dc4b8f63a737710ce75292a5653ee44860bb68c0d86b41270
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
rambo-pypi-grab/0.1.0
|
Release files / aer1_smolagents-0.1.2-py3-none-any.whl
| Download URL | aer1_smolagents-0.1.2-py3-none-any.whl |
|---|---|
| Size | 7.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
cb9de59ad0e9f461b04d4771c22c1077392cca3a7a5dfe4c30dd6887bd51d2cb
|
|
BLAKE2b-256 checksum How to use checksums |
f983b4cba5cc8cea7d8c6d8beb2384cd951c9e19238a73a9893e5247a2acdc10
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
rambo-pypi-grab/0.1.0
|