crewai-alex-evidence
Verify signed ALEX Evidence Packages as a CrewAI tool. This is a thin adapter around the same
independent verifier that langchain-alex exposes as
a LangChain tool and alex-evidence-verify-mcp
exposes as an MCP tool — no second verification algorithm is maintained here.
The tool returns one of three verdicts, never a bare true/false:
VERIFIED— signature, schema, and declared outcome all passed. This means the bundle matches the formal contract, not that the underlying work is correct.FAILED— a real integrity or structure problem: wrong trust anchor, tampered signature, unsupported schema, missing required attestation.INCONCLUSIVE— the bundle is authentically signed and structurally valid, but it honestly declares a non-success outcome (e.g. the underlying task was never completed or had no CI). This is deliberately not folded intoFAILED: a correctly-signed admission of "inconclusive" is not the same failure mode as a broken signature.
Requirements
- Python 3.10 or newer
- OpenSSL available as
opensslonPATH
Install
pip install crewai-alex-evidence
For development, install from source inside this repository instead:
pip install -e packages/crewai-alex-evidence
See all three verdicts without writing any code
crewai-alex-evidence-demo
Runs the tool against three bundled example evidence packages (shipped with the package, no
network access, no access to this repository needed) and prints the real VERIFIED, FAILED,
and INCONCLUSIVE verdicts. The keys under src/crewai_alex_evidence/examples/keys/*.TEST-KEY.pem
are public test keys for this demo only — never a real ALEX production trust anchor. Source for
the demo: src/crewai_alex_evidence/examples/run_verdicts.py.
Use in a crew
from crewai import Agent, Task
from crewai_alex_evidence import AlexEvidenceVerifyTool
verify_tool = AlexEvidenceVerifyTool()
agent = Agent(
role="Evidence Auditor",
goal="Verify evidence packages before any decision relies on them",
tools=[verify_tool],
)
The agent calls the tool with a path to the evidence bundle and a path to the trust anchor public key — both supplied by the caller, never read from an environment variable or taken from inside the bundle under test. A public key embedded only in the bundle itself is never trusted.
Development
python -m pip install -e ".[dev]"
python -m pytest
ruff check .
python -m build
The verifier implementation lives in langchain-alex (langchain_alex._verifier). This package
adds a crewai.tools.BaseTool wrapper only.
Metadata
Release files for crewai-alex-evidence 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| crewai_alex_evidence-0.1.0.tar.gz | 17.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| crewai_alex_evidence-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 48.6 kB
Release files / crewai_alex_evidence-0.1.0.tar.gz
| Download URL | crewai_alex_evidence-0.1.0.tar.gz |
|---|---|
| Size | 17.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
446b9c8aa5e1331f33ce72f66f7978d64ce2d74de47d719c92a729b347b8a91b
|
|
BLAKE2b-256 checksum How to use checksums |
b8d3148d23625f679992b9530004af641f80215f36f7b44e86a5e8e6e932e212
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.32 {"installer":{"name":"uv","version":"0.11.32","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":null,"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|
Release files / crewai_alex_evidence-0.1.0-py3-none-any.whl
| Download URL | crewai_alex_evidence-0.1.0-py3-none-any.whl |
|---|---|
| Size | 31.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
f9bdb49b8026347f92cb4ab04ad87b84d37bdf9fe79900e26ea6c7fc61132f61
|
|
BLAKE2b-256 checksum How to use checksums |
06b37b28699982164311504bd5342e261b3c9f9d3ebbb2d50eca8e6ad000964b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.32 {"installer":{"name":"uv","version":"0.11.32","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":null,"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|