semantic-kernel-mycelium-ref-verify
Semantic Kernel plugin for action_ref and decision_binding_ref — the
content-addressed identifiers from the argentum-core
spec family. action_ref identifies an agent action instance; decision_binding_ref
binds it to the authorization decision that permitted it. Both are
SHA-256(JCS(preimage)) — deterministic, independently recomputable by any
third party, no trust in the emitting system required.
Same underlying logic as mycelium-ref-verify
(Agent Skill) and crewai-decision-binding-ref
(CrewAI Tool) — action_ref.py and decision_binding_ref.py here are the
same stdlib-only modules, wrapped as @kernel_function-decorated methods
instead of a BaseTool.
Specs: action-ref.md · decision-binding-ref-v1.0.md
Install
pip install semantic-kernel-mycelium-ref-verify
Usage
from semantic_kernel import Kernel
from semantic_kernel_mycelium_ref_verify import MyceliumRefPlugin
kernel = Kernel()
kernel.add_plugin(MyceliumRefPlugin(), plugin_name="mycelium_ref")
fn = kernel.get_function("mycelium_ref", "compute_decision_binding_ref")
result = await kernel.invoke(
fn,
action_ref="sha256:...",
decision_id="approval:...",
decision_at_ms=1748736000000,
)
Four kernel functions are exposed:
| Function | Purpose |
|---|---|
compute_action_ref |
Derive action_ref from agent_id/action_type/scope/timestamp. |
verify_action_ref |
Recompute and, if presented_ref given, compare. |
compute_decision_binding_ref |
Derive decision_binding_ref from its preimage. |
verify_decision_binding_ref |
Recompute and, if presented_ref given, compare. |
The four verify states
Both verify_* functions report one of four states, deliberately kept
separate from the trail_status ladder (COMMITTED/PENDING/FAILED)
used elsewhere in Mycelium for execution-outcome tracking. That ladder
answers a temporal question — did the post-execution receipt arrive? This
plugin answers a cryptographic one — does this hash match? verify_* never
returns FAILED.
| State | Meaning |
|---|---|
COMMITTED |
Recompute succeeded and matches the presented ref. |
MISMATCH |
Recompute succeeded but does not match the presented ref. Fail-closed — same pattern as CONTEXT_SET_MISMATCH in the decision_binding_ref spec's context_digest extension. Never silent. |
PENDING_NON_NULL |
Preimage complete, ref computed, no presented ref given yet (compute-only mode). |
PENDING_NULL |
Preimage incomplete — recompute cannot be attempted. |
Tests
Conformance tests reuse the byte-verified fixtures already published in
argentum-core, no new vectors invented:
- Fixtures A–D from
decision-binding-ref-v1.0.md - Vectors
cd-001..cd-004fromexamples/conformance/decision-binding-context-digest-v1/
pip install -e .
pytest
License
Apache-2.0
Metadata
Release files for semantic-kernel-mycelium-ref-verify 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| semantic_kernel_mycelium_ref_verify-0.1.0.tar.gz | 14.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| semantic_kernel_mycelium_ref_verify-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 28.4 kB
Release files / semantic_kernel_mycelium_ref_verify-0.1.0.tar.gz
| Download URL | semantic_kernel_mycelium_ref_verify-0.1.0.tar.gz |
|---|---|
| Size | 14.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
2c84f083c2a9539f92209d24d15a19b00998a172af2ff5930264c718aa27392d
|
|
BLAKE2b-256 checksum How to use checksums |
3eb1317f60de23fb1d880c542cf66bc1f078a5e1d56df163213c6cb352557ad4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.3
|
Release files / semantic_kernel_mycelium_ref_verify-0.1.0-py3-none-any.whl
| Download URL | semantic_kernel_mycelium_ref_verify-0.1.0-py3-none-any.whl |
|---|---|
| Size | 14.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
b9b42e16a1d85233269988dbd3a5346c0d9188f0a17d6c24d928499a58314309
|
|
BLAKE2b-256 checksum How to use checksums |
76a2d7d2599990dc172832c0bd6cec39dc30cab0d5588e4e09d5554bd96e663a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.12.3
|