Datumline Agent Guard

io.github.datumlinev0.2.0更新于 Oct 11, 2026

Checks an AI agent's 'done' against the files and URLs it claims. Missing = FALSE_DONE.

已验证STDIO仅桌面开发者工具AI 与机器学习

概览

AI 生成的概览

通过检查 AI 智能体声称产出的文件和 URL 是否真实存在并通过校验,来核实其完成声明。

功能
提供一个 MCP 工具 verify_completion_claim,接收描述任务声明状态及其产物的清单(对象或路径)。它会检查本地文件是否存在、最小字节数、必须包含的内容、必需的 JSON 键和 SHA-256 哈希,并抓取 URL 检查状态码和内容。返回带有判定结果的回执:VERIFIED、FAILED、FALSE_DONE 或 UNVERIFIABLE。
适用场景
当智能体报告任务已完成、而你想在接受该声明前做独立核实时使用;也适合用非零退出码来卡住 CI 流水线或智能体循环。适用于智能体给出具体输出文件或 URL 的工作流。
运行要求
以 PyPI 包形式通过 stdio 在本地运行,可用 uvx datumline-agent-guard 启动或先 pip install。核心包需要 Python 3.9 及以上,LangChain 扩展需要 3.10 及以上。未声明任何账号、API 密钥或环境变量。它会读取清单中指定的文件并抓取其中的 URL,因此需要能访问这些路径,URL 产物还需要网络访问。
安装前请注意
它会读取清单中列出的本地文件并抓取其中的 URL,因此清单可能把它指向敏感路径或外部端点,运行前应检查清单。它只读取并报告,但非 VERIFIED 的判定会以非零码退出,可能导致 CI 失败或中断智能体循环。相对路径按当前工作目录解析。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Datumline Agent Guard,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

datumline-agent-guard

An independent verifier for AI agent work. An agent says a job is COMPLETED; agent-guard checks the artifacts it claims to have produced and returns a verdict. A completion claim with a missing artifact is reported as FALSE_DONE, not as a pass.

Standard library only, no dependencies. It imports nothing from the runtime it audits, so it can contradict that runtime.

Install

bash
pip install datumline-agent-guard

CLI

bash
agent-guard manifest.json          # human-readable receiptagent-guard manifest.json --json   # machine-readable receipt

Exit code is 0 only on VERIFIED; every other verdict exits 1 (bad input exits 2), so it can gate CI or an agent loop.

Manifest

json
{  "job": "WO-123",  "claimed_status": "COMPLETED",  "artifacts": [    {"type": "file", "path": "out/report.md", "min_bytes": 200, "must_contain": ["## Findings"]},    {"type": "json", "path": "out/feed.json", "required_keys": ["last_marked", "entries"]},    {"type": "url",  "url": "https://example.com/feed.json", "status": 200, "must_contain": ["last_marked"]},    {"type": "file", "path": "out/data.parquet", "sha256": "<hex>"}  ]}

Relative paths resolve against the current working directory.

Verdicts

VerdictMeaning
VERIFIEDevery artifact is present and passes every check
FAILEDan artifact is present but fails a check, or is absent without a completion claim
FALSE_DONEclaimed_status is COMPLETED / COMPLETE / DONE / VERIFIED and at least one artifact is absent
UNVERIFIABLEthe manifest asserts no artifacts; fail-closed, never green

Library

python
from datumline_agent_guard import verify, verify_file
receipt = verify({"claimed_status": "COMPLETED", "artifacts": [{"type": "file", "path": "out/report.md"}]})if receipt["verdict"] != "VERIFIED":    raise SystemExit(receipt["verdict"])

GitHub Action

Fail a workflow when an agent's "done" doesn't check out:

yaml
- uses: datumline/[email protected]  with:    manifest: agent-output/manifest.json   # what the agent claims it produced    # fail-on: false-done                  # only fail on FALSE_DONE (default: anything but VERIFIED)

The step installs this package from the action's own source (no network fetch), writes the receipt to the job summary, sets the verdict and receipt outputs, and exits non-zero unless the verdict is VERIFIED. It needs python3 3.9+ on the runner, which GitHub-hosted runners have.

MCP server

The same verifier as an MCP tool, verify_completion_claim, for Claude, ChatGPT, Copilot, Cursor or any MCP client. Standard library only, stdio transport.

json
{  "mcpServers": {    "agent-guard": { "command": "uvx", "args": ["datumline-agent-guard"] }  }}

Or pip install datumline-agent-guard and run datumline-agent-guard (alias agent-guard-mcp). The tool takes manifest (object) or manifest_path (string) and returns the receipt; anything other than "verdict": "VERIFIED" means not done. It reads the files and fetches the URLs the manifest names, and sends nothing anywhere else.

LangChain

bash
pip install "datumline-agent-guard[langchain]"
python
from datumline_agent_guard.langchain_tool import AgentGuardTool
tool = AgentGuardTool()  # name: agent_guard_verifytool.invoke({"manifest": {"claimed_status": "COMPLETED", "artifacts": [{"type": "file", "path": "out/report.md"}]}})# -> JSON receipt; anything other than "verdict": "VERIFIED" means not done

Give it to an agent as a tool, or call it yourself before accepting the agent's "done". It also takes manifest_path instead of manifest. It passes LangChain's standard tool tests (langchain-tests). Requires Python 3.10+; the core package needs only 3.9 and has no dependencies.

Related

The same verifier ships inside the free, MIT-licensed Receipted Operator Claude Code plugin, which adds a receipt ledger, truthful statuses and a hook that refuses unreceipted "done". Datumline also publishes paid method kits at datumlinehq.gumroad.com.

License

MIT

来源:README.md,提交 3715ce1

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.2.0最新Oct 11, 2026