Datumline Agent Guard

io.github.datumlinev0.2.0Updated Oct 11, 2026

Checks an AI agent's 'done' against the files and URLs it claims. Missing = FALSE_DONE.

VerifiedSTDIODesktop onlyDeveloper ToolsAI & ML

Overview

AI-generated overview

Verifies an AI agent's completion claim by checking that the files and URLs it says it produced actually exist and pass the stated checks.

What it does
Exposes one MCP tool, verify_completion_claim, which takes a manifest (object or path) describing a job's claimed status and its artifacts. It checks local files for presence, minimum size, required content, required JSON keys and SHA-256 hashes, and fetches URLs to check status codes and content. It returns a receipt with a verdict: VERIFIED, FAILED, FALSE_DONE or UNVERIFIABLE.
When to use it
Use it when an agent reports a job as done and you want an independent check before accepting that claim, or when you want a non-zero exit to gate a CI pipeline or an agent loop. It is aimed at workflows where the agent names concrete output files or URLs.
Requirements
Runs locally over stdio as a PyPI package, started with uvx datumline-agent-guard or after pip install. Python 3.9 or newer for the core package; the LangChain extra needs 3.10+. No accounts, API keys or environment variables are declared. It reads the files and fetches the URLs named in the manifest, so it needs access to those paths and network access for URL artifacts.
Before you install
It reads the local files and fetches the URLs listed in the manifest, so a manifest can point it at sensitive paths or external endpoints; review manifests before running. It only reads and reports, but a non-VERIFIED verdict exits non-zero, which can fail CI or stop an agent loop. Relative paths resolve against the current working directory.

Installation

In SourceWeft

  1. Open Datumline Agent Guard in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

datumline-agent-guard

An independent verifier for AI agent work. An agent says a job is COMPLETED; agent-guard checks the artifacts it claims to have produced and returns a verdict. A completion claim with a missing artifact is reported as FALSE_DONE, not as a pass.

Standard library only, no dependencies. It imports nothing from the runtime it audits, so it can contradict that runtime.

Install

bash
pip install datumline-agent-guard

CLI

bash
agent-guard manifest.json          # human-readable receiptagent-guard manifest.json --json   # machine-readable receipt

Exit code is 0 only on VERIFIED; every other verdict exits 1 (bad input exits 2), so it can gate CI or an agent loop.

Manifest

json
{  "job": "WO-123",  "claimed_status": "COMPLETED",  "artifacts": [    {"type": "file", "path": "out/report.md", "min_bytes": 200, "must_contain": ["## Findings"]},    {"type": "json", "path": "out/feed.json", "required_keys": ["last_marked", "entries"]},    {"type": "url",  "url": "https://example.com/feed.json", "status": 200, "must_contain": ["last_marked"]},    {"type": "file", "path": "out/data.parquet", "sha256": "<hex>"}  ]}

Relative paths resolve against the current working directory.

Verdicts

VerdictMeaning
VERIFIEDevery artifact is present and passes every check
FAILEDan artifact is present but fails a check, or is absent without a completion claim
FALSE_DONEclaimed_status is COMPLETED / COMPLETE / DONE / VERIFIED and at least one artifact is absent
UNVERIFIABLEthe manifest asserts no artifacts; fail-closed, never green

Library

python
from datumline_agent_guard import verify, verify_file
receipt = verify({"claimed_status": "COMPLETED", "artifacts": [{"type": "file", "path": "out/report.md"}]})if receipt["verdict"] != "VERIFIED":    raise SystemExit(receipt["verdict"])

GitHub Action

Fail a workflow when an agent's "done" doesn't check out:

yaml
- uses: datumline/[email protected]  with:    manifest: agent-output/manifest.json   # what the agent claims it produced    # fail-on: false-done                  # only fail on FALSE_DONE (default: anything but VERIFIED)

The step installs this package from the action's own source (no network fetch), writes the receipt to the job summary, sets the verdict and receipt outputs, and exits non-zero unless the verdict is VERIFIED. It needs python3 3.9+ on the runner, which GitHub-hosted runners have.

MCP server

The same verifier as an MCP tool, verify_completion_claim, for Claude, ChatGPT, Copilot, Cursor or any MCP client. Standard library only, stdio transport.

json
{  "mcpServers": {    "agent-guard": { "command": "uvx", "args": ["datumline-agent-guard"] }  }}

Or pip install datumline-agent-guard and run datumline-agent-guard (alias agent-guard-mcp). The tool takes manifest (object) or manifest_path (string) and returns the receipt; anything other than "verdict": "VERIFIED" means not done. It reads the files and fetches the URLs the manifest names, and sends nothing anywhere else.

LangChain

bash
pip install "datumline-agent-guard[langchain]"
python
from datumline_agent_guard.langchain_tool import AgentGuardTool
tool = AgentGuardTool()  # name: agent_guard_verifytool.invoke({"manifest": {"claimed_status": "COMPLETED", "artifacts": [{"type": "file", "path": "out/report.md"}]}})# -> JSON receipt; anything other than "verdict": "VERIFIED" means not done

Give it to an agent as a tool, or call it yourself before accepting the agent's "done". It also takes manifest_path instead of manifest. It passes LangChain's standard tool tests (langchain-tests). Requires Python 3.10+; the core package needs only 3.9 and has no dependencies.

Related

The same verifier ships inside the free, MIT-licensed Receipted Operator Claude Code plugin, which adds a receipt ledger, truthful statuses and a hook that refuses unreceipted "done". Datumline also publishes paid method kits at datumlinehq.gumroad.com.

License

MIT

Source: README.md at commit 3715ce1

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.2.0LatestOct 11, 2026