Datumline Agent Guard

io.github.datumlinev0.2.0更新於 Oct 11, 2026

Checks an AI agent's 'done' against the files and URLs it claims. Missing = FALSE_DONE.

已驗證STDIO僅桌面開發者工具AI 與機器學習

概覽

AI 產生的概覽

透過檢查 AI 代理聲稱產出的檔案與 URL 是否確實存在並通過驗證,來核實其完成聲明。

功能
提供一個 MCP 工具 verify_completion_claim,接收描述任務聲明狀態及其產物的清單(物件或路徑)。它會檢查本機檔案是否存在、最小位元組數、必須包含的內容、必要的 JSON 鍵與 SHA-256 雜湊,並抓取 URL 檢查狀態碼與內容。回傳帶有判定結果的收據:VERIFIED、FAILED、FALSE_DONE 或 UNVERIFIABLE。
適用情境
當代理回報任務已完成、而你想在接受該聲明前做獨立查核時使用;也適合用非零結束碼來擋住 CI 流程或代理迴圈。適用於代理給出具體輸出檔案或 URL 的工作流程。
執行需求
以 PyPI 套件形式透過 stdio 在本機執行,可用 uvx datumline-agent-guard 啟動,或先 pip install。核心套件需要 Python 3.9 以上,LangChain 擴充需要 3.10 以上。未宣告任何帳號、API 金鑰或環境變數。它會讀取清單中指定的檔案並抓取其中的 URL,因此需要能存取這些路徑,URL 產物還需要網路存取。
安裝前請注意
它會讀取清單中列出的本機檔案並抓取其中的 URL,因此清單可能把它指向敏感路徑或外部端點,執行前應檢查清單。它只讀取並回報,但非 VERIFIED 的判定會以非零碼結束,可能導致 CI 失敗或中斷代理迴圈。相對路徑依目前工作目錄解析。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Datumline Agent Guard,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

datumline-agent-guard

An independent verifier for AI agent work. An agent says a job is COMPLETED; agent-guard checks the artifacts it claims to have produced and returns a verdict. A completion claim with a missing artifact is reported as FALSE_DONE, not as a pass.

Standard library only, no dependencies. It imports nothing from the runtime it audits, so it can contradict that runtime.

Install

bash
pip install datumline-agent-guard

CLI

bash
agent-guard manifest.json          # human-readable receiptagent-guard manifest.json --json   # machine-readable receipt

Exit code is 0 only on VERIFIED; every other verdict exits 1 (bad input exits 2), so it can gate CI or an agent loop.

Manifest

json
{  "job": "WO-123",  "claimed_status": "COMPLETED",  "artifacts": [    {"type": "file", "path": "out/report.md", "min_bytes": 200, "must_contain": ["## Findings"]},    {"type": "json", "path": "out/feed.json", "required_keys": ["last_marked", "entries"]},    {"type": "url",  "url": "https://example.com/feed.json", "status": 200, "must_contain": ["last_marked"]},    {"type": "file", "path": "out/data.parquet", "sha256": "<hex>"}  ]}

Relative paths resolve against the current working directory.

Verdicts

VerdictMeaning
VERIFIEDevery artifact is present and passes every check
FAILEDan artifact is present but fails a check, or is absent without a completion claim
FALSE_DONEclaimed_status is COMPLETED / COMPLETE / DONE / VERIFIED and at least one artifact is absent
UNVERIFIABLEthe manifest asserts no artifacts; fail-closed, never green

Library

python
from datumline_agent_guard import verify, verify_file
receipt = verify({"claimed_status": "COMPLETED", "artifacts": [{"type": "file", "path": "out/report.md"}]})if receipt["verdict"] != "VERIFIED":    raise SystemExit(receipt["verdict"])

GitHub Action

Fail a workflow when an agent's "done" doesn't check out:

yaml
- uses: datumline/[email protected]  with:    manifest: agent-output/manifest.json   # what the agent claims it produced    # fail-on: false-done                  # only fail on FALSE_DONE (default: anything but VERIFIED)

The step installs this package from the action's own source (no network fetch), writes the receipt to the job summary, sets the verdict and receipt outputs, and exits non-zero unless the verdict is VERIFIED. It needs python3 3.9+ on the runner, which GitHub-hosted runners have.

MCP server

The same verifier as an MCP tool, verify_completion_claim, for Claude, ChatGPT, Copilot, Cursor or any MCP client. Standard library only, stdio transport.

json
{  "mcpServers": {    "agent-guard": { "command": "uvx", "args": ["datumline-agent-guard"] }  }}

Or pip install datumline-agent-guard and run datumline-agent-guard (alias agent-guard-mcp). The tool takes manifest (object) or manifest_path (string) and returns the receipt; anything other than "verdict": "VERIFIED" means not done. It reads the files and fetches the URLs the manifest names, and sends nothing anywhere else.

LangChain

bash
pip install "datumline-agent-guard[langchain]"
python
from datumline_agent_guard.langchain_tool import AgentGuardTool
tool = AgentGuardTool()  # name: agent_guard_verifytool.invoke({"manifest": {"claimed_status": "COMPLETED", "artifacts": [{"type": "file", "path": "out/report.md"}]}})# -> JSON receipt; anything other than "verdict": "VERIFIED" means not done

Give it to an agent as a tool, or call it yourself before accepting the agent's "done". It also takes manifest_path instead of manifest. It passes LangChain's standard tool tests (langchain-tests). Requires Python 3.10+; the core package needs only 3.9 and has no dependencies.

Related

The same verifier ships inside the free, MIT-licensed Receipted Operator Claude Code plugin, which adds a receipt ledger, truthful statuses and a hook that refuses unreceipted "done". Datumline also publishes paid method kits at datumlinehq.gumroad.com.

License

MIT

來源:README.md,提交 3715ce1

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.2.0最新Oct 11, 2026