Domain-independent source-citation verification for legal RAG: verbatim quote snapping, citation existence checks, and text-hash verification
Project description
juricode-verifier
Domain-independent source-citation verification for legal RAG systems. 法令 RAG のための、ドメイン非依存の「出典検証」ライブラリ。
Part of JuriCode-JP. MIT licensed. Zero third-party dependencies (stdlib only, Python 3.11+).
What it verifies / 何を検証するか
| API | Verifies |
|---|---|
snap_quote(anchor, body) |
Locates an LLM-provided anchor in the source body and cuts the quote from the original bytes. The LLM never emits the quote itself, so the quote is verbatim by construction. Returns None when the anchor is not locatable (paraphrase / hallucination). |
check_citations_exist(citations, allowed_chunk_ids) |
G1: every cited chunk_id is a member of the set of chunks actually provided to the LLM (no fabricated sources). |
check_quotes_verbatim(citations, chunk_texts) |
G2: every quote is a verbatim byte substring of its source body. With server-side snapping this is an invariant check; a mismatch is reported as an implementation bug (fail-loud). |
valid_citations_only(citations, allowed_chunk_ids, chunk_texts) |
Filters citations down to those passing G1+G2 (for safe fallback responses). |
verify_text_hash(canonical_text, expected_sha256) |
The sha256 of a canonical text matches the value locked in a source manifest (proof that the corpus text is unaltered from its primary source). Canonicalization itself is the caller's responsibility. |
All checks are pure functions returning structured Violation(code, detail) values. The caller decides what to do on violation (drop the citation, regenerate, fall back).
snap_quoteは LLM の anchor(引用したい箇所の目印)を原文中に位置特定し、原文のバイト列を引用として切り出します。引用文を LLM に打たせないため、引用は構造上必ず逐語一致になります。check_citations_exist(G1)は「LLM に渡していない出典の捏造」を、check_quotes_verbatim(G2)は「引用の改変」を機械的に検出します。verify_text_hashは「corpus 本文が一次ソースから改変されていないこと」を manifest のロック値との照合で証明します(canonicalize は呼び出し側の責務)。
What it does NOT verify / 検証しないもの
- Answer correctness. This package proves that citations are faithful to their sources; it does not prove the answer built on them is right.
- Application policy. Assertion bans, numeric-output bans, tense disclaimers, professional-practice notices and similar rules are application policy, not source verification. Keep them in your application layer.
(回答の正しさ・アプリ固有のポリシーは検証対象外です。本パッケージは「出典の忠実性」だけを検証します。)
Install
Not on PyPI yet. Install from the monorepo subdirectory:
pip install "juricode-verifier @ git+https://github.com/JuriCode-JP/JuriCode-JP.git#subdirectory=packages/juricode-verifier"
Usage
from juricode_verifier import (
Violation,
check_citations_exist,
check_quotes_verbatim,
snap_quote,
verify_text_hash,
)
# 1. Server-side quote snapping: LLM emits only {chunk_id, anchor}
quote = snap_quote(anchor="急迫不正の侵害に対して", body=chunk_body) # verbatim or None
# 2. Verify citations (pure functions -> list[Violation])
violations = []
violations += check_citations_exist(citations, allowed_chunk_ids=set(chunk_texts))
violations += check_quotes_verbatim(citations, chunk_texts)
# 3. Prove the source text is unaltered from its manifest-locked hash
v = verify_text_hash(canonical_text, expected_sha256=manifest_entry["ja_text_sha256"])
if v is not None:
violations.append(v)
Versioning
Semver. 0.x may change APIs between minor versions; pin the version (or commit) you depend on.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file juricode_verifier-0.1.0.tar.gz.
File metadata
- Download URL: juricode_verifier-0.1.0.tar.gz
- Upload date:
- Size: 11.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
cd356cfcf4a79e71515a0808a65f249bd006fb447848b10eef5bb3a2115bc6eb
|
|
| MD5 |
d6991a6ccea90a72cb0ec78bee6eca30
|
|
| BLAKE2b-256 |
ebde1ab55cd44e758b590324db50513ce07fb77907e13d7595a946ca794e1db3
|
Provenance
The following attestation bundles were made for juricode_verifier-0.1.0.tar.gz:
Publisher:
publish-juricode-verifier.yml on JuriCode-JP/JuriCode-JP
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
juricode_verifier-0.1.0.tar.gz -
Subject digest:
cd356cfcf4a79e71515a0808a65f249bd006fb447848b10eef5bb3a2115bc6eb - Sigstore transparency entry: 2194856607
- Sigstore integration time:
-
Permalink:
JuriCode-JP/JuriCode-JP@8114f90ff1b172b36aeb31f2269911d1d2619820 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/JuriCode-JP
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-juricode-verifier.yml@8114f90ff1b172b36aeb31f2269911d1d2619820 -
Trigger Event:
workflow_dispatch
-
Statement type:
File details
Details for the file juricode_verifier-0.1.0-py3-none-any.whl.
File metadata
- Download URL: juricode_verifier-0.1.0-py3-none-any.whl
- Upload date:
- Size: 9.7 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
0e9d367148856f7b61be7043b6abdddeaf1dd3d8588c8d6afd9c5108dc614c9c
|
|
| MD5 |
3e76783815bec7df13e61595f132ea24
|
|
| BLAKE2b-256 |
6010e09c43dd1c88bea7c42b9b27aeb08feda5749d22d3623769a8cb43dbe640
|
Provenance
The following attestation bundles were made for juricode_verifier-0.1.0-py3-none-any.whl:
Publisher:
publish-juricode-verifier.yml on JuriCode-JP/JuriCode-JP
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
juricode_verifier-0.1.0-py3-none-any.whl -
Subject digest:
0e9d367148856f7b61be7043b6abdddeaf1dd3d8588c8d6afd9c5108dc614c9c - Sigstore transparency entry: 2194856614
- Sigstore integration time:
-
Permalink:
JuriCode-JP/JuriCode-JP@8114f90ff1b172b36aeb31f2269911d1d2619820 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/JuriCode-JP
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-juricode-verifier.yml@8114f90ff1b172b36aeb31f2269911d1d2619820 -
Trigger Event:
workflow_dispatch
-
Statement type: