Skip to main content

agent-receipt

Offline claim-to-evidence receipts for agent handoffs. A receipt records what was observed; it is not proof that an agent's claim is true.

Install

uv tool install agent-receipt

Or with pipx:

pipx install agent-receipt

For contributors working from this repository:

uv tool install ./packages/agent-receipt

Safety model

  • Evidence paths are POSIX paths relative to a caller-supplied, trusted workspace root. Absolute paths, . / .., NULs, and symlink escapes are rejected.
  • Rechecks require a verifier-supplied --recheck-root; the receipt never chooses a filesystem root or command working directory.
  • Text evidence is literal substring matching only; v1 has no regex mode.
  • File reads, receipt strings, claim/evidence counts, command arguments, captured command output, and command timeouts are bounded. A command that exceeds the output limit is terminated and recorded as failed.
  • The optional context is either null or exactly binds packet_digest, input_commit, and output_manifest_digest. There is no arbitrary metadata.

content_digest detects inconsistent or non-rehashed changes to the unsigned receipt body. Because it is unkeyed, an active attacker can replace both the body and digest. An Ed25519 signature authenticates signer attribution against a verifier-provided public key; it still does not establish claim truth.

Build and verify

agent-receipt build \
  --workspace-root . \
  --agent worker --task "write report" --claim report="report exists" \
  --file-exists report=./report.md \
  --text-contains 'report=./report.md::PASS' \
  --out receipt.json

agent-receipt verify receipt.json --recheck --recheck-root .

Rechecks compare a current file hash to the hash observed while building the receipt. They therefore catch later file changes.

Command evidence

Commands run without a shell, with a constrained environment and bounded output. They always run from the trusted build root; no cwd is stored in the receipt. They can still execute repository code, so they are an explicit execution decision.

Command rechecks require both a verifier-selected root and an exact tuple allowlist:

agent-receipt verify receipt.json --recheck-commands --recheck-root . \
  --allow-command '/absolute/path/to/python -m pytest -q'

Inspect the executable, every argument, and the repository state before adding an allowlist entry. The executable path must be absolute, so PATH cannot silently select a different program. An unlisted receipt command fails closed. The verifier, not the worker receipt, defines success as exit code 0, uses a fixed 20-second timeout, and ignores worker-selected output expectations. At most five distinct commands may occur in one receipt.

Verification reports assurance and coverage. reported means no evidence was rerun, partially_rechecked means only some evidence was independently rerun, and fully_rechecked means every stored evidence item was rerun. Blocked command evidence is counted separately and never presented as rechecked. By default, verification exits successfully only for fully_rechecked. A lower threshold requires an explicit decision such as --minimum-assurance reported; that mode validates structure and internal consistency, not claim truth.

Canonical output manifests

The controller can inventory a completed output directory without executing any of its contents:

agent-receipt manifest create --workspace-root ./worker-output --json
agent-receipt manifest verify --workspace-root ./worker-output \
  --expected-digest '<independently trusted digest>' --json

Creation writes OUTPUT_MANIFEST.json under the selected root by default. The manifest uses the strict agent-output-manifest/v1 schema: relative POSIX paths are unique and sorted, and every regular file has a SHA-256 and byte count. Its digest is SHA-256 over canonical UTF-8 JSON with sorted object keys and compact separators, excluding the storage newline. Verification rebuilds the inventory and requires the exact file set, sizes, and hashes—not just the files named in the manifest. JSON with duplicate object keys is rejected.

Traversal is descriptor-relative and bounded by file count, entry count, depth, per-file size, total bytes, path length, and manifest size. Symbolic links, hard links, special files, path traversal, duplicate paths, and detectable path/content changes during scanning fail closed. receipt.json and OUTPUT_MANIFEST.json at the root are control files and are excluded by default; a custom CLI manifest path inside the root is also excluded exactly. No broad ignore patterns are applied. Creation and verification each require two complete, identical scans. This catches late changes missed by an earlier per-entry check, but it is not a transactional filesystem snapshot and cannot prevent a write after the final system call. Stop the worker before scanning and keep the output root quiescent until acceptance.

To bind a receipt to a handoff, supply all three strict context values at build and verify time: --packet-digest, --input-commit, and --output-manifest-digest. Verification compares the receipt context exactly to the verifier-provided values. Use the digest printed by manifest create, transfer it through a trusted channel, and independently run manifest verify before accepting the receipt. The digest is unkeyed; use the receipt's Ed25519 signature when signer attribution is needed.

Signatures

agent-receipt build ... --sign-private-key worker.pem --key-id worker-2026
agent-receipt verify receipt.json --trusted-key worker-2026=worker.pub \
  --minimum-assurance reported

Keep private keys out of receipts, repositories, command lines, and logs. Key IDs are labels; the verifier's supplied public key is the trust anchor. The explicit reported threshold above checks attribution and internal consistency only. Add the appropriate independent rechecks before accepting any claim.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

agent_receipt-0.1.0.tar.gz (29.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

agent_receipt-0.1.0-py3-none-any.whl (24.3 kB view details)

Uploaded Python 3

File details

Details for the file agent_receipt-0.1.0.tar.gz.

File metadata

  • Download URL: agent_receipt-0.1.0.tar.gz
  • Upload date:
  • Size: 29.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for agent_receipt-0.1.0.tar.gz
Algorithm Hash digest
SHA256 579cf413d0b69d43a8a88ee572fc4b981efd42cfe9be295c2bb479772954c1ce
MD5 906db3ddc7489a61891082699503ab3f
BLAKE2b-256 08a4c5c6b73de49ab73fcf3fbe9a5d0dff3cf4ce7c10c5c9d0fb945d28ae4e16

See more details on using hashes here.

Provenance

The following attestation bundles were made for agent_receipt-0.1.0.tar.gz:

Publisher: ci.yml on mauricemohr88-debug/agent-trust-kit

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file agent_receipt-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: agent_receipt-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 24.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for agent_receipt-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 208741779070fa16d8fb2635be5fa9eabd3ad53efd4855a6f27974334261a901
MD5 77e35e434a0c8684e197ad21674aa556
BLAKE2b-256 d78cd89691612e333ce590aa7b74bf315c585c721ded3a6f2502ae1efdb0b39a

See more details on using hashes here.

Provenance

The following attestation bundles were made for agent_receipt-0.1.0-py3-none-any.whl:

Publisher: ci.yml on mauricemohr88-debug/agent-trust-kit

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 files

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page