DCL Trust Oracle — AI/LLM Output Audit (x402 MCP)
AI/LLM agent output audit MCP: policy eval, tamper-evident chain, AI safety, x402 USDC on Base.
使うべきか
品質と安全性
検出事項(3)
- HIGHdcl_evaluate_fast 内
- HIGHdcl_evaluate_jailbreak 内
- HIGH
ツール定義とプロトコルへの準拠に関する自動分析に基づいています。
コンテキストコスト
これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。
インストール
ワンクリックインストール
これを `claude_desktop_config.json` ファイルに追加してください:
{
"mcpServers": {
"dcl-trust-oracle": {
"url": "https://mcp.fronesislabs.com/mcp"
}
}
}リモートエンドポイント
https://mcp.fronesislabs.com/mcpstreamable-httpできること
ツール一覧
ツール(18)
🟢dcl_evaluate_fast(response, agent_id)
FAST Pre-Action Audit ($0.01). Runs the response through the server's "default" policy: a substring check against 3 forbidden phrases ("ignore previous instructions", "jailbreak", "bypass safety") with a 0.7 minimum-confidence threshold. Each forbidden match found costs 0.4 confidence; if confidence falls below 0.7, or any match is found, the verdict is NO_COMMIT and `reason` lists which phrase triggered it. Otherwise COMMIT. Use this as the default low-cost first-pass gate before a risky agent action; switch to dcl_evaluate_strict for a broader, higher-bar check, or to dcl_evaluate_jailbreak / dcl_evaluate_safety / dcl_evaluate_quality for a narrower, single-topic check instead of the general-purpose default policy.
入力スキーマ
{
"type": "object",
"properties": {
"response": {
"description": "The agent or LLM response text to audit.",
"title": "Response",
"type": "string"
},
"agent_id": {
"description": "Identifier of the agent that produced the response.",
"title": "Agent Id",
"type": "string"
}
},
"required": [
"response",
"agent_id"
],
"title": "dcl_evaluate_fastArguments"
}出力スキーマ
{
"type": "object",
"properties": {
"verdict": {
"description": "COMMIT if the response passed policy checks, otherwise NO_COMMIT.",
"title": "Verdict",
"type": "string"
},
"confidence": {
"description": "Confidence score of the verdict, from 0.0 to 1.0.",
"title": "Confidence",
"type": "number"
},
"reason": {
"description": "Human-readable explanation of why the verdict was reached.",
"title": "Reason",
"type": "string"
},
"tx_hash": {
"description": "Hash of this record in the tamper-evident audit chain.",
"title": "Tx Hash",
"type": "string"
},
"chain_index": {
"description": "Sequential index of this record in the audit chain.",
"title": "Chain Index",
"type": "integer"
},
"input_hash": {
"description": "Hash of the evaluated response (raw content is never stored).",
"title": "Input Hash",
"type": "string"
},
"policy_version": {
"description": "Version of the policy that was applied.",
"title": "Policy Version",
"type": "string"
},
"drift_mode": {
"description": "Current drift status: NORMAL, WARNING, ESCALATION, or BLOCK.",
"title": "Drift Mode",
"type": "string"
},
"drift_score": {
"description": "Z-score measuring deviation of the recent commit rate from baseline.",
"title": "Drift Score",
"type": "number"
},
"timestamp": {
"description": "Unix timestamp when this record was sealed.",
"title": "Timestamp",
"type": "number"
},
"seal_text": {
"description": "Human-readable Leibniz Layer verification seal.",
"title": "Seal Text",
"type": "string"
},
"verify_url": {
"description": "Public URL to independently verify this seal.",
"title": "Verify Url",
"type": "string"
}
},
"required": [
"verdict",
"confidence",
"reason",
"tx_hash",
"chain_index",
"input_hash",
"policy_version",
"drift_mode",
"drift_score",
"timestamp",
"seal_text",
"verify_url"
],
"title": "EvaluateResult"
}⚪dcl_evaluate_strict(response, agent_id)
STRICT Pre-Action Audit ($0.05). Runs the response against a broader, higher-bar "strict" policy: the union of all forbidden phrases from the default, anti-jailbreak, and safety policies (8 phrases total), with a 0.85 minimum-confidence threshold instead of the default policy's 0.7. Each matched phrase costs 0.4 confidence; if confidence falls below 0.85, or any phrase matches, the verdict is NO_COMMIT with `reason` listing every match found. Use this instead of dcl_evaluate_fast when the cost of a false COMMIT is high — e.g. before an irreversible or high-stakes agent action — since it catches jailbreak- and safety-adjacent phrasing that the plain default policy would miss.
入力スキーマ
{
"type": "object",
"properties": {
"response": {
"description": "The agent or LLM response text to audit.",
"title": "Response",
"type": "string"
},
"agent_id": {
"description": "Identifier of the agent that produced the response.",
"title": "Agent Id",
"type": "string"
}
},
"required": [
"response",
"agent_id"
],
"title": "dcl_evaluate_strictArguments"
}出力スキーマ
{
"type": "object",
"properties": {
"verdict": {
"description": "COMMIT if the response passed policy checks, otherwise NO_COMMIT.",
"title": "Verdict",
"type": "string"
},
"confidence": {
"description": "Confidence score of the verdict, from 0.0 to 1.0.",
"title": "Confidence",
"type": "number"
},
"reason": {
"description": "Human-readable explanation of why the verdict was reached.",
"title": "Reason",
"type": "string"
},
"tx_hash": {
"description": "Hash of this record in the tamper-evident audit chain.",
"title": "Tx Hash",
"type": "string"
},
"chain_index": {
"description": "Sequential index of this record in the audit chain.",
"title": "Chain Index",
"type": "integer"
},
"input_hash": {
"description": "Hash of the evaluated response (raw content is never stored).",
"title": "Input Hash",
"type": "string"
},
"policy_version": {
"description": "Version of the policy that was applied.",
"title": "Policy Version",
"type": "string"
},
"drift_mode": {
"description": "Current drift status: NORMAL, WARNING, ESCALATION, or BLOCK.",
"title": "Drift Mode",
"type": "string"
},
"drift_score": {
"description": "Z-score measuring deviation of the recent commit rate from baseline.",
"title": "Drift Score",
"type": "number"
},
"timestamp": {
"description": "Unix timestamp when this record was sealed.",
"title": "Timestamp",
"type": "number"
},
"seal_text": {
"description": "Human-readable Leibniz Layer verification seal.",
"title": "Seal Text",
"type": "string"
},
"verify_url": {
"description": "Public URL to independently verify this seal.",
"title": "Verify Url",
"type": "string"
}
},
"required": [
"verdict",
"confidence",
"reason",
"tx_hash",
"chain_index",
"input_hash",
"policy_version",
"drift_mode",
"drift_score",
"timestamp",
"seal_text",
"verify_url"
],
"title": "EvaluateResult"
}🟢dcl_evaluate_jailbreak(response, agent_id)
PRE-ACTION Instruction Adherence Check ($0.02). Runs the "anti_jailbreak" policy: a substring check against 6 forbidden phrases ("ignore previous instructions", "jailbreak", "bypass safety", "pretend you are", "act as if", "DAN") with a 0.8 minimum-confidence threshold — each match costs 0.4 confidence. Returns COMMIT if no phrase matches and confidence stays at or above 0.8, otherwise NO_COMMIT with `reason` listing the matched phrase(s). Use this as a targeted, cheaper check when the concern is specifically prompt-injection / persona-hijack risk; use dcl_evaluate_strict instead when you also want safety- and default-policy phrases covered in the same call.
入力スキーマ
{
"type": "object",
"properties": {
"response": {
"description": "The agent or LLM response text to check for jailbreak attempts.",
"title": "Response",
"type": "string"
},
"agent_id": {
"description": "Identifier of the agent that produced the response.",
"title": "Agent Id",
"type": "string"
}
},
"required": [
"response",
"agent_id"
],
"title": "dcl_evaluate_jailbreakArguments"
}出力スキーマ
{
"type": "object",
"properties": {
"verdict": {
"description": "COMMIT if the response passed policy checks, otherwise NO_COMMIT.",
"title": "Verdict",
"type": "string"
},
"confidence": {
"description": "Confidence score of the verdict, from 0.0 to 1.0.",
"title": "Confidence",
"type": "number"
},
"reason": {
"description": "Human-readable explanation of why the verdict was reached.",
"title": "Reason",
"type": "string"
},
"tx_hash": {
"description": "Hash of this record in the tamper-evident audit chain.",
"title": "Tx Hash",
"type": "string"
},
"chain_index": {
"description": "Sequential index of this record in the audit chain.",
"title": "Chain Index",
"type": "integer"
},
"input_hash": {
"description": "Hash of the evaluated response (raw content is never stored).",
"title": "Input Hash",
"type": "string"
},
"policy_version": {
"description": "Version of the policy that was applied.",
"title": "Policy Version",
"type": "string"
},
"drift_mode": {
"description": "Current drift status: NORMAL, WARNING, ESCALATION, or BLOCK.",
"title": "Drift Mode",
"type": "string"
},
"drift_score": {
"description": "Z-score measuring deviation of the recent commit rate from baseline.",
"title": "Drift Score",
"type": "number"
},
"timestamp": {
"description": "Unix timestamp when this record was sealed.",
"title": "Timestamp",
"type": "number"
},
"seal_text": {
"description": "Human-readable Leibniz Layer verification seal.",
"title": "Seal Text",
"type": "string"
},
"verify_url": {
"description": "Public URL to independently verify this seal.",
"title": "Verify Url",
"type": "string"
}
},
"required": [
"verdict",
"confidence",
"reason",
"tx_hash",
"chain_index",
"input_hash",
"policy_version",
"drift_mode",
"drift_score",
"timestamp",
"seal_text",
"verify_url"
],
"title": "EvaluateResult"
}🟢dcl_evaluate_safety(response, agent_id)
PRE-ACTION Baseline Safety Check ($0.01). Runs the "safety" policy: flags 2 forbidden disclaimers ("I cannot be held responsible", "no guarantees") and additionally REQUIRES the substring "AI" to appear somewhere in the response — missing it costs 0.2 confidence even with no forbidden phrase present. Minimum confidence is 0.75. Returns NO_COMMIT if confidence drops below 0.75, with `reason` naming the forbidden phrase found or the missing required pattern. Use this when you specifically need to confirm an AI-disclosure marker is present and the two disclaimer phrases are absent — not as a general-purpose safety net; for broader coverage use dcl_evaluate_fast or dcl_evaluate_strict instead.
入力スキーマ
{
"type": "object",
"properties": {
"response": {
"description": "The agent or LLM response text to check for safety violations.",
"title": "Response",
"type": "string"
},
"agent_id": {
"description": "Identifier of the agent that produced the response.",
"title": "Agent Id",
"type": "string"
}
},
"required": [
"response",
"agent_id"
],
"title": "dcl_evaluate_safetyArguments"
}出力スキーマ
{
"type": "object",
"properties": {
"verdict": {
"description": "COMMIT if the response passed policy checks, otherwise NO_COMMIT.",
"title": "Verdict",
"type": "string"
},
"confidence": {
"description": "Confidence score of the verdict, from 0.0 to 1.0.",
"title": "Confidence",
"type": "number"
},
"reason": {
"description": "Human-readable explanation of why the verdict was reached.",
"title": "Reason",
"type": "string"
},
"tx_hash": {
"description": "Hash of this record in the tamper-evident audit chain.",
"title": "Tx Hash",
"type": "string"
},
"chain_index": {
"description": "Sequential index of this record in the audit chain.",
"title": "Chain Index",
"type": "integer"
},
"input_hash": {
"description": "Hash of the evaluated response (raw content is never stored).",
"title": "Input Hash",
"type": "string"
},
"policy_version": {
"description": "Version of the policy that was applied.",
"title": "Policy Version",
"type": "string"
},
"drift_mode": {
"description": "Current drift status: NORMAL, WARNING, ESCALATION, or BLOCK.",
"title": "Drift Mode",
"type": "string"
},
"drift_score": {
"description": "Z-score measuring deviation of the recent commit rate from baseline.",
"title": "Drift Score",
"type": "number"
},
"timestamp": {
"description": "Unix timestamp when this record was sealed.",
"title": "Timestamp",
"type": "number"
},
"seal_text": {
"description": "Human-readable Leibniz Layer verification seal.",
"title": "Seal Text",
"type": "string"
},
"verify_url": {
"description": "Public URL to independently verify this seal.",
"title": "Verify Url",
"type": "string"
}
},
"required": [
"verdict",
"confidence",
"reason",
"tx_hash",
"chain_index",
"input_hash",
"policy_version",
"drift_mode",
"drift_score",
"timestamp",
"seal_text",
"verify_url"
],
"title": "EvaluateResult"
}🟢dcl_evaluate_quality(response, agent_id)
PRE-ACTION Content Quality & Drift Check ($0.03). Runs the "content_quality" policy: flags 12 absolutist or unverifiable-claim phrases (e.g. "guaranteed returns", "100% accurate", "studies show", "without a doubt") with a 0.85 minimum-confidence threshold — the highest bar of any single-policy tool. Returns NO_COMMIT if any phrase matches or confidence falls below 0.85, with `reason` listing the matched phrase(s). Use this to catch overconfident or unsubstantiated claims in generated content — a different concern from jailbreak or safety phrasing — e.g. before publishing agent-written copy or reports.
入力スキーマ
{
"type": "object",
"properties": {
"response": {
"description": "The agent or LLM response text to check for quality and drift.",
"title": "Response",
"type": "string"
},
"agent_id": {
"description": "Identifier of the agent that produced the response.",
"title": "Agent Id",
"type": "string"
}
},
"required": [
"response",
"agent_id"
],
"title": "dcl_evaluate_qualityArguments"
}出力スキーマ
{
"type": "object",
"properties": {
"verdict": {
"description": "COMMIT if the response passed policy checks, otherwise NO_COMMIT.",
"title": "Verdict",
"type": "string"
},
"confidence": {
"description": "Confidence score of the verdict, from 0.0 to 1.0.",
"title": "Confidence",
"type": "number"
},
"reason": {
"description": "Human-readable explanation of why the verdict was reached.",
"title": "Reason",
"type": "string"
},
"tx_hash": {
"description": "Hash of this record in the tamper-evident audit chain.",
"title": "Tx Hash",
"type": "string"
},
"chain_index": {
"description": "Sequential index of this record in the audit chain.",
"title": "Chain Index",
"type": "integer"
},
"input_hash": {
"description": "Hash of the evaluated response (raw content is never stored).",
"title": "Input Hash",
"type": "string"
},
"policy_version": {
"description": "Version of the policy that was applied.",
"title": "Policy Version",
"type": "string"
},
"drift_mode": {
"description": "Current drift status: NORMAL, WARNING, ESCALATION, or BLOCK.",
"title": "Drift Mode",
"type": "string"
},
"drift_score": {
"description": "Z-score measuring deviation of the recent commit rate from baseline.",
"title": "Drift Score",
"type": "number"
},
"timestamp": {
"description": "Unix timestamp when this record was sealed.",
"title": "Timestamp",
"type": "number"
},
"seal_text": {
"description": "Human-readable Leibniz Layer verification seal.",
"title": "Seal Text",
"type": "string"
},
"verify_url": {
"description": "Public URL to independently verify this seal.",
"title": "Verify Url",
"type": "string"
}
},
"required": [
"verdict",
"confidence",
"reason",
"tx_hash",
"chain_index",
"input_hash",
"policy_version",
"drift_mode",
"drift_score",
"timestamp",
"seal_text",
"verify_url"
],
"title": "EvaluateResult"
}🟡dcl_evaluate_secrets(response, agent_id)
POST-ACTION Secret & Credential Leak Scan ($0.02). Regex-based scan across 8 categories (API keys, cloud credentials, tokens/JWTs, private keys, DB URLs, connection strings, env assignments, webhook secrets, internal endpoints with auth). Any finding results in NO_COMMIT.
入力スキーマ
{
"type": "object",
"properties": {
"response": {
"description": "The text to scan for exposed API keys, tokens, private keys, DB URLs, and other credentials.",
"title": "Response",
"type": "string"
},
"agent_id": {
"description": "Identifier of the agent that produced the response.",
"title": "Agent Id",
"type": "string"
}
},
"required": [
"response",
"agent_id"
],
"title": "dcl_evaluate_secretsArguments"
}出力スキーマ
{
"type": "object",
"properties": {
"verdict": {
"description": "COMMIT if nothing was found, otherwise NO_COMMIT.",
"title": "Verdict",
"type": "string"
},
"risk_score": {
"description": "0.0-1.0 risk score based on number and severity of findings.",
"title": "Risk Score",
"type": "number"
},
"findings": {
"description": "All matches found. Empty list if verdict is COMMIT.",
"items": {
"$ref": "#/$defs/DetectionFinding"
},
"title": "Findings",
"type": "array"
},
"detection_count": {
"description": "Number of findings.",
"title": "Detection Count",
"type": "integer"
},
"categories_checked": {
"description": "All checklist categories that were scanned.",
"items": {
"type": "string"
},
"title": "Categories Checked",
"type": "array"
},
"categories_clear": {
"description": "Categories with no findings.",
"items": {
"type": "string"
},
"title": "Categories Clear",
"type": "array"
},
"tx_hash": {
"description": "Hash of this record in the tamper-evident audit chain.",
"title": "Tx Hash",
"type": "string"
},
"chain_index": {
"description": "Sequential index of this record in the audit chain.",
"title": "Chain Index",
"type": "integer"
},
"input_hash": {
"description": "Hash of the scanned text (raw content is never stored).",
"title": "Input Hash",
"type": "string"
},
"timestamp": {
"description": "Unix timestamp when this record was sealed.",
"title": "Timestamp",
"type": "number"
},
"seal_text": {
"description": "Human-readable Leibniz Layer verification seal.",
"title": "Seal Text",
"type": "string"
},
"verify_url": {
"description": "Public URL to independently verify this seal.",
"title": "Verify Url",
"type": "string"
}
},
"required": [
"verdict",
"risk_score",
"findings",
"detection_count",
"categories_checked",
"categories_clear",
"tx_hash",
"chain_index",
"input_hash",
"timestamp",
"seal_text",
"verify_url"
],
"$defs": {
"DetectionFinding": {
"properties": {
"type": {
"description": "The specific pattern category matched (e.g. 'api_key', 'email').",
"title": "Type",
"type": "string"
},
"position": {
"description": "Character offset of the match in the submitted text.",
"title": "Position",
"type": "integer"
},
"redacted_sample": {
"description": "Masked version of the match — first 2 and last 4 chars only.",
"title": "Redacted Sample",
"type": "string"
},
"severity": {
"description": "critical, major, or minor.",
"title": "Severity",
"type": "string"
},
"category": {
"description": "Checklist code, e.g. S1-S8 for secrets or T1-T8 for PII.",
"title": "Category",
"type": "string"
},
"provider": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Identified provider/service, if known.",
"title": "Provider"
}
},
"required": [
"type",
"position",
"redacted_sample",
"severity",
"category"
],
"title": "DetectionFinding",
"type": "object"
}
},
"title": "ScanResult"
}🟡dcl_evaluate_pii(response, agent_id)
POST-ACTION PII Detection Scan ($0.02). Regex-based scan across 8 personal-data categories, with a Luhn checksum on card numbers to reduce false positives. Any finding results in NO_COMMIT.
入力スキーマ
{
"type": "object",
"properties": {
"response": {
"description": "The text to scan for personal data: emails, phone numbers, national IDs, bank cards, IBANs, crypto addresses, IP addresses, passport numbers.",
"title": "Response",
"type": "string"
},
"agent_id": {
"description": "Identifier of the agent that produced the response.",
"title": "Agent Id",
"type": "string"
}
},
"required": [
"response",
"agent_id"
],
"title": "dcl_evaluate_piiArguments"
}出力スキーマ
{
"type": "object",
"properties": {
"verdict": {
"description": "COMMIT if nothing was found, otherwise NO_COMMIT.",
"title": "Verdict",
"type": "string"
},
"risk_score": {
"description": "0.0-1.0 risk score based on number and severity of findings.",
"title": "Risk Score",
"type": "number"
},
"findings": {
"description": "All matches found. Empty list if verdict is COMMIT.",
"items": {
"$ref": "#/$defs/DetectionFinding"
},
"title": "Findings",
"type": "array"
},
"detection_count": {
"description": "Number of findings.",
"title": "Detection Count",
"type": "integer"
},
"categories_checked": {
"description": "All checklist categories that were scanned.",
"items": {
"type": "string"
},
"title": "Categories Checked",
"type": "array"
},
"categories_clear": {
"description": "Categories with no findings.",
"items": {
"type": "string"
},
"title": "Categories Clear",
"type": "array"
},
"tx_hash": {
"description": "Hash of this record in the tamper-evident audit chain.",
"title": "Tx Hash",
"type": "string"
},
"chain_index": {
"description": "Sequential index of this record in the audit chain.",
"title": "Chain Index",
"type": "integer"
},
"input_hash": {
"description": "Hash of the scanned text (raw content is never stored).",
"title": "Input Hash",
"type": "string"
},
"timestamp": {
"description": "Unix timestamp when this record was sealed.",
"title": "Timestamp",
"type": "number"
},
"seal_text": {
"description": "Human-readable Leibniz Layer verification seal.",
"title": "Seal Text",
"type": "string"
},
"verify_url": {
"description": "Public URL to independently verify this seal.",
"title": "Verify Url",
"type": "string"
}
},
"required": [
"verdict",
"risk_score",
"findings",
"detection_count",
"categories_checked",
"categories_clear",
"tx_hash",
"chain_index",
"input_hash",
"timestamp",
"seal_text",
"verify_url"
],
"$defs": {
"DetectionFinding": {
"properties": {
"type": {
"description": "The specific pattern category matched (e.g. 'api_key', 'email').",
"title": "Type",
"type": "string"
},
"position": {
"description": "Character offset of the match in the submitted text.",
"title": "Position",
"type": "integer"
},
"redacted_sample": {
"description": "Masked version of the match — first 2 and last 4 chars only.",
"title": "Redacted Sample",
"type": "string"
},
"severity": {
"description": "critical, major, or minor.",
"title": "Severity",
"type": "string"
},
"category": {
"description": "Checklist code, e.g. S1-S8 for secrets or T1-T8 for PII.",
"title": "Category",
"type": "string"
},
"provider": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Identified provider/service, if known.",
"title": "Provider"
}
},
"required": [
"type",
"position",
"redacted_sample",
"severity",
"category"
],
"title": "DetectionFinding",
"type": "object"
}
},
"title": "ScanResult"
}🟢dcl_evaluate_batch(items, agent_id)
PRE-ACTION Bulk Processing ($0.10). Evaluates a list of items in one call; each item is a dict shaped {"response": str, "policy"?: str}, where policy defaults to "default" if omitted and may be any built-in policy name (default, strict, anti_jailbreak, safety, content_quality). Each item gets its own independent COMMIT/NO_COMMIT verdict via the same logic as the matching single-item evaluate_* tool; results are returned in input order under `results`, plus a shared `batch_id`. Capped at 200 items per call — oversized batches are rejected. Use this instead of multiple single-item evaluate_* calls when checking several responses — optionally against different policies — in one priced call rather than paying per item separately.
入力スキーマ
{
"type": "object",
"properties": {
"items": {
"description": "List of items to evaluate, each shaped like {'response': str, 'policy'?: str}.",
"items": {
"additionalProperties": true,
"type": "object"
},
"title": "Items",
"type": "array"
},
"agent_id": {
"description": "Identifier of the agent that produced the responses.",
"title": "Agent Id",
"type": "string"
}
},
"required": [
"items",
"agent_id"
],
"title": "dcl_evaluate_batchArguments"
}出力スキーマ
{
"type": "object",
"properties": {
"batch_id": {
"description": "Unique identifier for this batch run.",
"title": "Batch Id",
"type": "string"
},
"agent_id": {
"description": "Identifier of the agent whose responses were evaluated.",
"title": "Agent Id",
"type": "string"
},
"count": {
"description": "Number of items evaluated in this batch.",
"title": "Count",
"type": "integer"
},
"results": {
"description": "Per-item evaluation results, in input order.",
"items": {
"$ref": "#/$defs/EvaluateResult"
},
"title": "Results",
"type": "array"
}
},
"required": [
"batch_id",
"agent_id",
"count",
"results"
],
"$defs": {
"EvaluateResult": {
"properties": {
"verdict": {
"description": "COMMIT if the response passed policy checks, otherwise NO_COMMIT.",
"title": "Verdict",
"type": "string"
},
"confidence": {
"description": "Confidence score of the verdict, from 0.0 to 1.0.",
"title": "Confidence",
"type": "number"
},
"reason": {
"description": "Human-readable explanation of why the verdict was reached.",
"title": "Reason",
"type": "string"
},
"tx_hash": {
"description": "Hash of this record in the tamper-evident audit chain.",
"title": "Tx Hash",
"type": "string"
},
"chain_index": {
"description": "Sequential index of this record in the audit chain.",
"title": "Chain Index",
"type": "integer"
},
"input_hash": {
"description": "Hash of the evaluated response (raw content is never stored).",
"title": "Input Hash",
"type": "string"
},
"policy_version": {
"description": "Version of the policy that was applied.",
"title": "Policy Version",
"type": "string"
},
"drift_mode": {
"description": "Current drift status: NORMAL, WARNING, ESCALATION, or BLOCK.",
"title": "Drift Mode",
"type": "string"
},
"drift_score": {
"description": "Z-score measuring deviation of the recent commit rate from baseline.",
"title": "Drift Score",
"type": "number"
},
"timestamp": {
"description": "Unix timestamp when this record was sealed.",
"title": "Timestamp",
"type": "number"
},
"seal_text": {
"description": "Human-readable Leibniz Layer verification seal.",
"title": "Seal Text",
"type": "string"
},
"verify_url": {
"description": "Public URL to independently verify this seal.",
"title": "Verify Url",
"type": "string"
}
},
"required": [
"verdict",
"confidence",
"reason",
"tx_hash",
"chain_index",
"input_hash",
"policy_version",
"drift_mode",
"drift_score",
"timestamp",
"seal_text",
"verify_url"
],
"title": "EvaluateResult",
"type": "object"
}
},
"title": "BatchResult"
}⚪dcl_pipeline_start(agent_id, scope, ttl_seconds)
SESSION Management ($0.05). Generates a new `pipeline_id` and returns session metadata (scope, expiry, initial drift_mode) for organizing a series of related checks under one identifier. Note: this call does not currently link the returned pipeline_id to later evaluate_* calls — there is no server-side session state that ties subsequent audits back to it; it is an identifier/timestamp issuer, not an active tracking session. Use this to obtain a shared reference ID for your own client-side grouping of a multi-step audit sequence; do not rely on it to automatically aggregate drift across calls.
入力スキーマ
{
"type": "object",
"properties": {
"agent_id": {
"description": "Identifier of the agent that owns this session.",
"title": "Agent Id",
"type": "string"
},
"scope": {
"default": "default",
"description": "Scope label for the session.",
"title": "Scope",
"type": "string"
},
"ttl_seconds": {
"default": 3600,
"description": "Session time-to-live, in seconds.",
"title": "Ttl Seconds",
"type": "integer"
}
},
"required": [
"agent_id"
],
"title": "dcl_pipeline_startArguments"
}出力スキーマ
{
"type": "object",
"properties": {
"pipeline_id": {
"description": "Unique identifier for the newly opened pipeline session.",
"title": "Pipeline Id",
"type": "string"
},
"agent_id": {
"description": "Identifier of the agent that owns this session.",
"title": "Agent Id",
"type": "string"
},
"scope": {
"description": "Scope label for the session.",
"title": "Scope",
"type": "string"
},
"expires_at": {
"description": "Unix timestamp when the session expires.",
"title": "Expires At",
"type": "number"
},
"drift_mode": {
"description": "Drift status at session start (always NORMAL for a new session).",
"title": "Drift Mode",
"type": "string"
}
},
"required": [
"pipeline_id",
"agent_id",
"scope",
"expires_at",
"drift_mode"
],
"title": "PipelineStartResult"
}🟢dcl_audit_decode(tx_hash)
POST-ACTION Basic Audit ($0.10). Retrieves a record from the tamper-evident chain by tx_hash.
入力スキーマ
{
"type": "object",
"properties": {
"tx_hash": {
"description": "Transaction hash of the audit chain record to retrieve.",
"title": "Tx Hash",
"type": "string"
}
},
"required": [
"tx_hash"
],
"title": "dcl_audit_decodeArguments"
}出力スキーマ
{
"type": "object",
"properties": {
"error": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Set if tx_hash was not found; other fields are omitted.",
"title": "Error"
},
"tx_hash": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Hash of the audit chain record.",
"title": "Tx Hash"
},
"agent_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Identifier of the agent tied to this record.",
"title": "Agent Id"
},
"verdict": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "COMMIT or NO_COMMIT.",
"title": "Verdict"
},
"reason": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Explanation recorded for the verdict.",
"title": "Reason"
},
"confidence": {
"anyOf": [
{
"type": "number"
},
{
"type": "null"
}
],
"default": null,
"description": "Confidence score recorded for the verdict.",
"title": "Confidence"
},
"task_type": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Task type tag recorded with this entry.",
"title": "Task Type"
},
"timestamp": {
"anyOf": [
{
"type": "number"
},
{
"type": "null"
}
],
"default": null,
"description": "Unix timestamp when the record was created.",
"title": "Timestamp"
},
"chain_index": {
"anyOf": [
{
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "Sequential index of the record in the chain.",
"title": "Chain Index"
},
"prev_hash": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Hash of the preceding record in the chain.",
"title": "Prev Hash"
},
"chain_integrity": {
"anyOf": [
{
"type": "boolean"
},
{
"type": "null"
}
],
"default": null,
"description": "True if the full chain verifies as intact.",
"title": "Chain Integrity"
},
"seal_text": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Human-readable Leibniz Layer verification seal.",
"title": "Seal Text"
},
"verify_url": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Public URL to independently verify this seal.",
"title": "Verify Url"
}
},
"title": "AuditResult"
}🟢dcl_audit_decode_deep(tx_hash)
POST-ACTION Deep Forensic Audit ($0.50). Extended output with drift_context and full chain integrity verification.
入力スキーマ
{
"type": "object",
"properties": {
"tx_hash": {
"description": "Transaction hash of the audit chain record to retrieve.",
"title": "Tx Hash",
"type": "string"
}
},
"required": [
"tx_hash"
],
"title": "dcl_audit_decode_deepArguments"
}出力スキーマ
{
"type": "object",
"properties": {
"error": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Set if tx_hash was not found; other fields are omitted.",
"title": "Error"
},
"tx_hash": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Hash of the audit chain record.",
"title": "Tx Hash"
},
"agent_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Identifier of the agent tied to this record.",
"title": "Agent Id"
},
"verdict": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "COMMIT or NO_COMMIT.",
"title": "Verdict"
},
"reason": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Explanation recorded for the verdict.",
"title": "Reason"
},
"confidence": {
"anyOf": [
{
"type": "number"
},
{
"type": "null"
}
],
"default": null,
"description": "Confidence score recorded for the verdict.",
"title": "Confidence"
},
"task_type": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Task type tag recorded with this entry.",
"title": "Task Type"
},
"timestamp": {
"anyOf": [
{
"type": "number"
},
{
"type": "null"
}
],
"default": null,
"description": "Unix timestamp when the record was created.",
"title": "Timestamp"
},
"chain_index": {
"anyOf": [
{
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "Sequential index of the record in the chain.",
"title": "Chain Index"
},
"prev_hash": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Hash of the preceding record in the chain.",
"title": "Prev Hash"
},
"chain_integrity": {
"anyOf": [
{
"type": "boolean"
},
{
"type": "null"
}
],
"default": null,
"description": "True if the full chain verifies as intact.",
"title": "Chain Integrity"
},
"seal_text": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Human-readable Leibniz Layer verification seal.",
"title": "Seal Text"
},
"verify_url": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Public URL to independently verify this seal.",
"title": "Verify Url"
},
"tampered_at_index": {
"anyOf": [
{
"type": "integer"
},
{
"type": "null"
}
],
"default": null,
"description": "Index where chain integrity broke, if any tampering was detected.",
"title": "Tampered At Index"
},
"tamper_reason": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Why chain_integrity is False — a broken prev_hash link or an edited row whose stored tx_hash no longer matches its recomputed content hash.",
"title": "Tamper Reason"
},
"drift_context": {
"anyOf": [
{
"additionalProperties": true,
"type": "object"
},
{
"type": "null"
}
],
"default": null,
"description": "Extended forensic metadata captured at evaluation time.",
"title": "Drift Context"
}
},
"title": "AuditDeepResult"
}⚪dcl_evaluate_jailbreak_crypto(response, agent_id)
PRE-ACTION Crypto Jailbreak & Injection Detection ($0.02). Crypto-specialized instruction-override/jailbreak/injection screen: standard role-switch and instruction-override patterns, plus crypto-specific drain-wallet injection (e.g. "transfer all funds to...", fake "test transaction" requesting full balance) and unlimited-approval injection (e.g. type(uint256).max, "approve unlimited allowance", skip-slippage-confirmation framing). Any match returns NO_COMMIT with `reason` and `findings` naming the matched category/categories; run this FIRST in the DCL crypto pipeline, before wallet/trade/MEV checks, since it screens the input itself rather than a decision built on top of it.
入力スキーマ
{
"type": "object",
"properties": {
"response": {
"description": "The incoming prompt or agent response to screen for crypto-specialized jailbreak/injection attempts.",
"title": "Response",
"type": "string"
},
"agent_id": {
"description": "Identifier of the agent that produced or received the text.",
"title": "Agent Id",
"type": "string"
}
},
"required": [
"response",
"agent_id"
],
"title": "dcl_evaluate_jailbreak_cryptoArguments"
}出力スキーマ
{
"type": "object",
"properties": {
"verdict": {
"description": "COMMIT if no injection pattern matched, otherwise NO_COMMIT.",
"title": "Verdict",
"type": "string"
},
"confidence": {
"description": "Confidence score of the verdict, from 0.0 to 1.0.",
"title": "Confidence",
"type": "number"
},
"reason": {
"description": "Human-readable explanation of the verdict.",
"title": "Reason",
"type": "string"
},
"findings": {
"description": "All matched patterns. Empty list if verdict is COMMIT.",
"items": {
"$ref": "#/$defs/CryptoFinding"
},
"title": "Findings",
"type": "array"
},
"tx_hash": {
"description": "Hash of this record in the tamper-evident audit chain.",
"title": "Tx Hash",
"type": "string"
},
"chain_index": {
"description": "Sequential index of this record in the audit chain.",
"title": "Chain Index",
"type": "integer"
},
"input_hash": {
"description": "Hash of the screened text (raw content is never stored).",
"title": "Input Hash",
"type": "string"
},
"policy_version": {
"description": "Version of the crypto jailbreak policy that was applied.",
"title": "Policy Version",
"type": "string"
}
},
"required": [
"verdict",
"confidence",
"reason",
"findings",
"tx_hash",
"chain_index",
"input_hash",
"policy_version"
],
"$defs": {
"CryptoFinding": {
"properties": {
"type": {
"description": "The specific pattern category matched.",
"title": "Type",
"type": "string"
},
"severity": {
"description": "critical or major.",
"title": "Severity",
"type": "string"
},
"regulatory_reference": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Illustrative regulatory tag for this finding type (e.g. MiFID II, FCA), if applicable.",
"title": "Regulatory Reference"
}
},
"required": [
"type",
"severity"
],
"title": "CryptoFinding",
"type": "object"
}
},
"title": "JailbreakCryptoResult"
}🟡dcl_evaluate_wallet(response, agent_id)
POST-ACTION Wallet Secret Guardian ($0.02). Scans for BIP-39 seed phrases (12 or 24 consecutive wordlist words), raw hex or WIF-format private keys, Ethereum/Bitcoin wallet addresses, and API keys/bearer tokens appearing near wallet/custody/signing terminology. Any finding results in NO_COMMIT — wallet secrets have no safe threshold, unlike other DCL evaluators. Returns a `sanitized_output` with all matches redacted (null if nothing was found) and a masked `redacted_sample` per finding — the real value is never returned or stored server-side.
入力スキーマ
{
"type": "object",
"properties": {
"response": {
"description": "The text to scan for seed phrases, private keys, wallet addresses, and wallet-context API credentials.",
"title": "Response",
"type": "string"
},
"agent_id": {
"description": "Identifier of the agent that produced the response.",
"title": "Agent Id",
"type": "string"
}
},
"required": [
"response",
"agent_id"
],
"title": "dcl_evaluate_walletArguments"
}出力スキーマ
{
"type": "object",
"properties": {
"verdict": {
"description": "COMMIT if nothing was found, otherwise NO_COMMIT. Wallet secrets have no safe threshold.",
"title": "Verdict",
"type": "string"
},
"confidence": {
"description": "Confidence score of the verdict, from 0.0 to 1.0.",
"title": "Confidence",
"type": "number"
},
"reason": {
"description": "Human-readable explanation of the verdict.",
"title": "Reason",
"type": "string"
},
"findings": {
"description": "All matches found. Empty list if verdict is COMMIT.",
"items": {
"$ref": "#/$defs/WalletFinding"
},
"title": "Findings",
"type": "array"
},
"sanitized_output": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Input text with all matches redacted. Null if verdict is COMMIT.",
"title": "Sanitized Output"
},
"risk_score": {
"description": "0.0-1.0 risk score based on number and severity of findings.",
"title": "Risk Score",
"type": "number"
},
"tx_hash": {
"description": "Hash of this record in the tamper-evident audit chain.",
"title": "Tx Hash",
"type": "string"
},
"chain_index": {
"description": "Sequential index of this record in the audit chain.",
"title": "Chain Index",
"type": "integer"
},
"input_hash": {
"description": "Hash of the scanned text (raw content is never stored).",
"title": "Input Hash",
"type": "string"
},
"policy_version": {
"description": "Version of the wallet-guardian policy that was applied.",
"title": "Policy Version",
"type": "string"
},
"timestamp": {
"description": "Unix timestamp when this record was sealed.",
"title": "Timestamp",
"type": "number"
}
},
"required": [
"verdict",
"confidence",
"reason",
"findings",
"risk_score",
"tx_hash",
"chain_index",
"input_hash",
"policy_version",
"timestamp"
],
"$defs": {
"WalletFinding": {
"properties": {
"type": {
"description": "seed_phrase, private_key, wallet_address, or wallet_api_credential.",
"title": "Type",
"type": "string"
},
"position": {
"description": "Character offset of the match in the submitted text.",
"title": "Position",
"type": "integer"
},
"redacted_sample": {
"description": "Masked version of the match — never the real value.",
"title": "Redacted Sample",
"type": "string"
},
"severity": {
"description": "critical or major.",
"title": "Severity",
"type": "string"
}
},
"required": [
"type",
"position",
"redacted_sample",
"severity"
],
"title": "WalletFinding",
"type": "object"
}
},
"title": "WalletResult"
}⚪dcl_evaluate_trade(response, agent_id)
PRE-ACTION Trade Decision Verifier ($0.02). Screens trade-decision language for guaranteed-return claims, zero-risk/"can't lose" framing, and unqualified "buy/sell X now" directives — any match is NO_COMMIT. If no unsafe language is found, COMMIT additionally requires the word "risk" to appear anywhere in the text as a minimum disclosure marker; its absence alone triggers NO_COMMIT with `reason` noting the missing disclosure. Produces an immutable `trade_receipt` (tx_hash/chain_hash/chain_depth) distinct from the top-level audit hash, for downstream systems that specifically need a trade-shaped receipt object.
入力スキーマ
{
"type": "object",
"properties": {
"response": {
"description": "The trade decision or recommendation text to screen.",
"title": "Response",
"type": "string"
},
"agent_id": {
"description": "Identifier of the agent that produced the response.",
"title": "Agent Id",
"type": "string"
}
},
"required": [
"response",
"agent_id"
],
"title": "dcl_evaluate_tradeArguments"
}出力スキーマ
{
"type": "object",
"properties": {
"verdict": {
"description": "COMMIT if the trade decision's language passed the screen, otherwise NO_COMMIT.",
"title": "Verdict",
"type": "string"
},
"confidence": {
"description": "Confidence score of the verdict, from 0.0 to 1.0.",
"title": "Confidence",
"type": "number"
},
"reason": {
"description": "Human-readable explanation of the verdict.",
"title": "Reason",
"type": "string"
},
"findings": {
"description": "All matched patterns. Empty list if verdict is COMMIT.",
"items": {
"$ref": "#/$defs/CryptoFinding"
},
"title": "Findings",
"type": "array"
},
"trade_receipt": {
"$ref": "#/$defs/TradeReceipt",
"description": "Immutable receipt for this trade-verification record."
},
"input_hash": {
"description": "Hash of the screened text (raw content is never stored).",
"title": "Input Hash",
"type": "string"
},
"timestamp": {
"description": "Unix timestamp when this record was sealed.",
"title": "Timestamp",
"type": "number"
}
},
"required": [
"verdict",
"confidence",
"reason",
"findings",
"trade_receipt",
"input_hash",
"timestamp"
],
"$defs": {
"CryptoFinding": {
"properties": {
"type": {
"description": "The specific pattern category matched.",
"title": "Type",
"type": "string"
},
"severity": {
"description": "critical or major.",
"title": "Severity",
"type": "string"
},
"regulatory_reference": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Illustrative regulatory tag for this finding type (e.g. MiFID II, FCA), if applicable.",
"title": "Regulatory Reference"
}
},
"required": [
"type",
"severity"
],
"title": "CryptoFinding",
"type": "object"
},
"TradeReceipt": {
"properties": {
"tx_hash": {
"description": "Tamper-evident proof of this specific trade-verification record.",
"title": "Tx Hash",
"type": "string"
},
"chain_hash": {
"description": "Hash of the previous commit in the append-only chain that this one links to.",
"title": "Chain Hash",
"type": "string"
},
"chain_depth": {
"description": "This record's position (index) in the chain.",
"title": "Chain Depth",
"type": "integer"
}
},
"required": [
"tx_hash",
"chain_hash",
"chain_depth"
],
"title": "TradeReceipt",
"type": "object"
}
},
"title": "TradeResult"
}🟡dcl_evaluate_mev(response, agent_id)
POST-ACTION MEV & Market-Abuse Compliance Screen ($0.03). Text-level screen (not a mempool/transaction analyzer) for front-running/sandwich-attack language, wash trading/layering/spoofing, KYC/AML red flags (mixers, structuring, obscuring fund origin), and pump-and-dump/rug-pull language. Any critical-severity finding, or two or more major-severity findings, returns NO_COMMIT; a single major-severity finding is also returned as NO_COMMIT but with a distinctly higher `confidence` (~0.55 vs ~0.05-0.2 for harder violations) so downstream callers can tell a soft single flag apart from a hard multi-finding block. Each finding includes an illustrative `regulatory_reference` tag (MiFID II, FCA, or an EU AI Act article).
入力スキーマ
{
"type": "object",
"properties": {
"response": {
"description": "The agent or LLM response text describing or proposing an on-chain/trading action, to screen for MEV and market-abuse language.",
"title": "Response",
"type": "string"
},
"agent_id": {
"description": "Identifier of the agent that produced the response.",
"title": "Agent Id",
"type": "string"
}
},
"required": [
"response",
"agent_id"
],
"title": "dcl_evaluate_mevArguments"
}出力スキーマ
{
"type": "object",
"properties": {
"verdict": {
"description": "COMMIT if the response passed the MEV/compliance screen, otherwise NO_COMMIT.",
"title": "Verdict",
"type": "string"
},
"confidence": {
"description": "Confidence score of the verdict, from 0.0 to 1.0.",
"title": "Confidence",
"type": "number"
},
"findings": {
"description": "All matched patterns. Empty list if verdict is COMMIT.",
"items": {
"$ref": "#/$defs/CryptoFinding"
},
"title": "Findings",
"type": "array"
},
"tx_hash": {
"description": "Hash of this record in the tamper-evident audit chain.",
"title": "Tx Hash",
"type": "string"
},
"chain_index": {
"description": "Sequential index of this record in the audit chain.",
"title": "Chain Index",
"type": "integer"
},
"input_hash": {
"description": "Hash of the screened text (raw content is never stored).",
"title": "Input Hash",
"type": "string"
},
"timestamp": {
"description": "Unix timestamp when this record was sealed.",
"title": "Timestamp",
"type": "number"
}
},
"required": [
"verdict",
"confidence",
"findings",
"tx_hash",
"chain_index",
"input_hash",
"timestamp"
],
"$defs": {
"CryptoFinding": {
"properties": {
"type": {
"description": "The specific pattern category matched.",
"title": "Type",
"type": "string"
},
"severity": {
"description": "critical or major.",
"title": "Severity",
"type": "string"
},
"regulatory_reference": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Illustrative regulatory tag for this finding type (e.g. MiFID II, FCA), if applicable.",
"title": "Regulatory Reference"
}
},
"required": [
"type",
"severity"
],
"title": "CryptoFinding",
"type": "object"
}
},
"title": "MevResult"
}🟡dcl_evaluate_signal(response, agent_id)
POST-ACTION Market Signal Fabrication Screen ($0.03). Pattern-based heuristic on the output text alone (no source price feed) — flags guaranteed-price-prediction language ("will definitely hit $X"), absolute-certainty claims ("100% certain", "cannot go down"), a fabricated-price flag when a specific dollar figure co-occurs with a guaranteed-outcome claim, and an invented-token flag when a "$TICKER" cashtag doesn't match a small set of well-known symbols (false positives are possible for legitimate lesser-known tickers — this is a heuristic pre-check, not ground truth). For a full claim-by-claim check against an actual price-feed snapshot, use the local grounding workflow instead of this live tool. Verdict/confidence collapsing follows the same rule as dcl_evaluate_mev: any critical finding or 2+ major findings is a hard NO_COMMIT; exactly one major finding is a softer NO_COMMIT at ~0.55 confidence.
入力スキーマ
{
"type": "object",
"properties": {
"response": {
"description": "The market signal, analysis, or price-prediction text to screen.",
"title": "Response",
"type": "string"
},
"agent_id": {
"description": "Identifier of the agent that produced the response.",
"title": "Agent Id",
"type": "string"
}
},
"required": [
"response",
"agent_id"
],
"title": "dcl_evaluate_signalArguments"
}出力スキーマ
{
"type": "object",
"properties": {
"verdict": {
"description": "COMMIT if no fabrication/overconfidence pattern matched, otherwise NO_COMMIT.",
"title": "Verdict",
"type": "string"
},
"confidence": {
"description": "Confidence score of the verdict, from 0.0 to 1.0.",
"title": "Confidence",
"type": "number"
},
"reason": {
"description": "Human-readable explanation of the verdict.",
"title": "Reason",
"type": "string"
},
"findings": {
"description": "All matched patterns. Empty list if verdict is COMMIT.",
"items": {
"$ref": "#/$defs/CryptoFinding"
},
"title": "Findings",
"type": "array"
},
"tx_hash": {
"description": "Hash of this record in the tamper-evident audit chain.",
"title": "Tx Hash",
"type": "string"
},
"chain_index": {
"description": "Sequential index of this record in the audit chain.",
"title": "Chain Index",
"type": "integer"
},
"input_hash": {
"description": "Hash of the screened text (raw content is never stored).",
"title": "Input Hash",
"type": "string"
},
"timestamp": {
"description": "Unix timestamp when this record was sealed.",
"title": "Timestamp",
"type": "number"
}
},
"required": [
"verdict",
"confidence",
"reason",
"findings",
"tx_hash",
"chain_index",
"input_hash",
"timestamp"
],
"$defs": {
"CryptoFinding": {
"properties": {
"type": {
"description": "The specific pattern category matched.",
"title": "Type",
"type": "string"
},
"severity": {
"description": "critical or major.",
"title": "Severity",
"type": "string"
},
"regulatory_reference": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Illustrative regulatory tag for this finding type (e.g. MiFID II, FCA), if applicable.",
"title": "Regulatory Reference"
}
},
"required": [
"type",
"severity"
],
"title": "CryptoFinding",
"type": "object"
}
},
"title": "SignalResult"
}🟡dcl_evaluate_output_sanitizer(response, agent_id)
FINAL-GATE Output Sanitizer ($0.02). Post-processing checkpoint that strips secrets/credentials, PII, crypto material (seed phrases, private keys, wallet addresses), internal network details (private IPs, MAC addresses, .internal/.local/.corp hostnames), and unsafe shell/SQL/path-traversal fragments from a raw model response — plus a narrow, high-precision safety net for direct self-harm-instruction-seeking and targeted-harassment phrasing (not a general toxicity classifier). Returns a single `sanitized_output` with every match replaced by `[REDACTED]`; use that instead of the original whenever verdict is NO_COMMIT. Run this as the LAST gate before a response reaches its destination — after `dcl_evaluate_jailbreak_crypto`/other input-side checks have already run, and immediately before `dcl_commit` seals the final decision. Internally re-uses the same detection tables as `dcl_evaluate_secrets`/`dcl_evaluate_pii` for the secrets/PII categories, so results stay consistent with those tools.
入力スキーマ
{
"type": "object",
"properties": {
"response": {
"description": "The raw LLM/agent response to sanitize before it is delivered to a user, downstream agent, or external system.",
"title": "Response",
"type": "string"
},
"agent_id": {
"description": "Identifier of the agent that produced the response.",
"title": "Agent Id",
"type": "string"
}
},
"required": [
"response",
"agent_id"
],
"title": "dcl_evaluate_output_sanitizerArguments"
}出力スキーマ
{
"type": "object",
"properties": {
"verdict": {
"description": "COMMIT if the response was clean, otherwise NO_COMMIT.",
"title": "Verdict",
"type": "string"
},
"confidence": {
"description": "Confidence score of the verdict, from 0.0 to 1.0.",
"title": "Confidence",
"type": "number"
},
"violations": {
"description": "Distinct finding types matched (e.g. ['api_key', 'internal_ip']). Empty list if verdict is COMMIT.",
"items": {
"type": "string"
},
"title": "Violations",
"type": "array"
},
"findings": {
"description": "All matches found, with position/severity/category detail. Empty list if verdict is COMMIT.",
"items": {
"$ref": "#/$defs/SanitizerFinding"
},
"title": "Findings",
"type": "array"
},
"sanitized_output": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Input text with every match replaced by [REDACTED]. Null if verdict is COMMIT.",
"title": "Sanitized Output"
},
"redaction_count": {
"description": "Total number of items redacted.",
"title": "Redaction Count",
"type": "integer"
},
"risk_score": {
"description": "0.0-1.0 composite severity score.",
"title": "Risk Score",
"type": "number"
},
"tx_hash": {
"description": "Hash of this record in the tamper-evident audit chain.",
"title": "Tx Hash",
"type": "string"
},
"chain_index": {
"description": "Sequential index of this record in the audit chain.",
"title": "Chain Index",
"type": "integer"
},
"input_hash": {
"description": "Hash of the sanitized text (raw content is never stored).",
"title": "Input Hash",
"type": "string"
},
"timestamp": {
"description": "Unix timestamp when this record was sealed.",
"title": "Timestamp",
"type": "number"
}
},
"required": [
"verdict",
"confidence",
"violations",
"findings",
"redaction_count",
"risk_score",
"tx_hash",
"chain_index",
"input_hash",
"timestamp"
],
"$defs": {
"SanitizerFinding": {
"properties": {
"type": {
"description": "e.g. api_key, email, seed_phrase, internal_ip, mac_address, internal_hostname, self_harm_instruction, targeted_harassment, shell_injection, sql_injection, path_traversal, and others.",
"title": "Type",
"type": "string"
},
"position": {
"description": "Character offset of the match in the submitted text.",
"title": "Position",
"type": "integer"
},
"redacted_sample": {
"description": "Masked version of the match — never the real value.",
"title": "Redacted Sample",
"type": "string"
},
"severity": {
"description": "critical, major, or minor.",
"title": "Severity",
"type": "string"
},
"category": {
"description": "secrets, pii, crypto, network, toxic, or unsafe_instructions.",
"title": "Category",
"type": "string"
}
},
"required": [
"type",
"position",
"redacted_sample",
"severity",
"category"
],
"title": "SanitizerFinding",
"type": "object"
}
},
"title": "OutputSanitizerResult"
}🟢dcl_commit(decision, agent_id, prior_checks)
FINAL-STEP Leibniz Layer Crypto Commit ($0.01). Writes a trading/agent decision to the append-only Leibniz Layer audit chain and returns a Merkle-proof-style receipt: `tx_hash` (proof of this specific commit), `chain_hash` (the previous commit's hash, linking this one into the chain), and `chain_depth` (this commit's position in the chain). Unlike the evaluate_* tools, this call has no pass/fail verdict of its own — it always succeeds and simply seals the decision. Passing `prior_checks` is optional but recommended: it records which earlier pipeline steps (firewall/wallet/trade/MEV) this specific commit is downstream of, in one auditable record. Always run this LAST, after every other crypto-suite check has passed.
入力スキーマ
{
"type": "object",
"properties": {
"decision": {
"description": "The final trading/agent decision text to commit to the audit chain.",
"title": "Decision",
"type": "string"
},
"agent_id": {
"description": "Identifier of the agent whose decision is being committed.",
"title": "Agent Id",
"type": "string"
},
"prior_checks": {
"anyOf": [
{
"additionalProperties": true,
"type": "object"
},
{
"type": "null"
}
],
"default": null,
"description": "Optional dict of tx_hashes from earlier pipeline steps (e.g. {'prompt_firewall_tx_hash': ..., 'trade_verifier_tx_hash': ..., 'mev_compliance_tx_hash': ...}), linking this commit to the specific checks that passed before it.",
"title": "Prior Checks"
}
},
"required": [
"decision",
"agent_id"
],
"title": "dcl_commitArguments"
}出力スキーマ
{
"type": "object",
"properties": {
"tx_hash": {
"description": "Tamper-evident proof of this specific commit.",
"title": "Tx Hash",
"type": "string"
},
"chain_hash": {
"description": "Hash of the previous commit in the append-only chain that this one links to.",
"title": "Chain Hash",
"type": "string"
},
"chain_depth": {
"description": "This commit's position (index) in the chain.",
"title": "Chain Depth",
"type": "integer"
},
"input_hash": {
"description": "Hash of the committed decision text (raw content is never stored).",
"title": "Input Hash",
"type": "string"
},
"timestamp": {
"description": "Unix timestamp when this record was sealed.",
"title": "Timestamp",
"type": "number"
}
},
"required": [
"tx_hash",
"chain_hash",
"chain_depth",
"input_hash",
"timestamp"
],
"title": "CommitResult"
}コミュニティ
エビデンス