Skip to main content

ResultSeal

CI PyPI License: MIT Python

HTTP 200 is not an observation. Empty is not not-found. A tool call is not an effect.

ResultSeal is a small, framework-neutral Python toolkit that prevents AI-agent workflows from promoting empty, partial, stale, source-mismatched, or unverified tool results into factual claims. Shipped adapters cover raw JSON, HTTP responses, MCP-style tool results (structuredContent / isError / outputSchema), and stdio process output — each establishing structural facts only (see docs/specs/ADAPTERS.md).

Why ResultSeal

AI agents frequently suffer from false-success hallucinations: treating empty search responses as proof of absence, or transport-level HTTP 200s as verified effects. Standard schema validators only verify payload shape—ResultSeal enforces observation integrity:

Tool Output Scenario Naive Agent Behavior ResultSeal Guard
Query returns {} or [] Hallucinates: "Item does not exist" BLOCKED (EMPTY_WITHOUT_NOT_FOUND_SENTINEL)
Explicit absence ({"status": "NOT_FOUND"}) May confuse with unexpected error SEALED (not_found via contract sentinel)
HTTP 204 DELETE (empty body) Assumes mutation succeeded without proof BLOCKED (UNVERIFIED_EFFECT)
MCP returns isError: true with text Reads error message as answer BLOCKED (PROTOCOL_CONFLICT)
Cache returns outdated revision Acts on stale state BLOCKED (STALE_OBSERVATION)
Missing required fields Promotes partial payload BLOCKED (MISSING_REQUIRED_FIELD)

What it does

ResultSeal normalizes a tool result, applies a declarative contract, and produces a deterministic decision. Unknown and incomplete evidence is blocked by default.

Install

pip install resultseal

Requires Python 3.11+.

From source instead:

git clone https://github.com/sx4im/resultseal.git
cd resultseal
pip install .

Try it

CLI

# Replay a self-contained fixture bundle against its recorded expectation
resultseal replay fixtures/empty-result.yaml         # empty response -> blocked/empty
resultseal replay fixtures/explicit-not-found.yaml   # approved sentinel -> sealed/not_found

# Evaluate a shipped example against a shipped contract (exit 0 = sealed, 1 = blocked)
resultseal check examples/mcp_result.json --contract examples/customer_contract.json
resultseal check examples/http_empty.json --contract examples/customer_contract.json

The last two are the toolkit's thesis side by side: a complete MCP result seals, while an HTTP 200 carrying an empty body blocks as empty — it can never be promoted to not_found. All four commands print the decision record with a verifiable deterministic_fingerprint.

Python API

import json
from datetime import datetime, UTC
from pathlib import Path
from resultseal.contracts import load_contract_file
from resultseal.limits import Limits
from resultseal.models import Decision
from resultseal.normalize import normalize
from resultseal.rules import ReferenceClock, evaluate

# 1. Load a declarative contract
contract = load_contract_file(Path("examples/customer_contract.json"), Limits())

# 2. Normalize raw tool observation (MCP, HTTP, stdio, or JSON)
raw_tool_result = json.loads(Path("examples/mcp_result.json").read_text())
clock = ReferenceClock(now=datetime.now(UTC))
norm = normalize(raw_tool_result, clock)

# 3. Evaluate observation against contract
evaluation = evaluate(norm.envelope, norm.payload, contract, clock)

if evaluation.decision is Decision.SEALED:
    print(f"Observation verified! Truth state: {evaluation.truth_state.value}")
else:
    print(f"Blocked! Reason codes: {evaluation.reason_codes}")

Scope

ResultSeal is not an agent framework, proxy, dashboard, policy engine, retry middleware, signed receipt system, or LLM judge. It is an executable semantic boundary for tool observations.

Development

make install   # editable install with dev tools
make all       # test, lint, typecheck, build

Contributing

Contributions are warmly welcome! Whether you are:

  • Adding a new protocol adapter (e.g. SQL query results, GraphQL)
  • Submitting an edge-case negative test fixture in fixtures/
  • Contributing an integration example for an agent framework (LangChain, LangGraph, Pydantic-AI, CrewAI)
  • Improving documentation or adding production contract recipes

Check out CONTRIBUTING.md to get set up in under two minutes.

Metadata

Release files for resultseal 0.1.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for resultseal 0.1.2
File Size Uploaded
resultseal-0.1.2.tar.gz 58.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for resultseal 0.1.2
File Interpreter ABI Platform
resultseal-0.1.2-py3-none-any.whl Python 3 none any Details

Total release size: 87.5 kB

Release files / resultseal-0.1.2.tar.gz

Download URL resultseal-0.1.2.tar.gz
Size 58.3 kB
Tags Source
SHA-256 checksum
How to use checksums
b26b765c9d267e175012e410da5e53925ac766a1af72c747d00c16170c6f2bd2
BLAKE2b-256 checksum
How to use checksums
d68810dce1a81a92d4e9a0e33bd8a27d8ddd8e922ec20438f1d59fbc27abb532
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 3, 2026.

Transparency log

Release files / resultseal-0.1.2-py3-none-any.whl

Download URL resultseal-0.1.2-py3-none-any.whl
Size 29.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
889f9a2ff6a6af0fac0ecaf842f83f914132d6c3a7c86a68f66f6fa5481e2d7c
BLAKE2b-256 checksum
How to use checksums
6844fb75cbdc5f4641945046db78a85cfe5c74d5b8cabcba83189b798cb866a8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 3, 2026.

Transparency log

Release history Release notifications | RSS feed

0.1.3

2 release files

This release

0.1.2 This release

2 release files

0.1.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page