arifOS — Constitutional AI Kernel
Constitutional AI kernel with 13 MCP tools, 888_JUDGE verdict pipeline, and VAULT999 ledger.
我該用這個嗎
品質與安全性
根據工具定義與協定合規性的自動化分析。
上下文成本
這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。
安裝
一鍵安裝
將以下內容加入你的 `claude_desktop_config.json` 檔案:
{
"mcpServers": {
"arifos": {
"url": "https://arifos.arif-fazil.com/mcp"
}
}
}遠端端點
https://arifos.arif-fazil.com/mcpstreamable-http它能做什麼
工具清單
工具(8)
🟢arif_init(mode, actor_id, ack_irreversible, session_id, epoch_id, ...)
KERNEL 000 · Ignite a governed kernel session: binds actor identity, constitutional floors F1–F13, and the audit chain. Returns the session_id + session_token that every other arif_* verb requires. Use mode=preflight to inspect an existing session without re-igniting, mode=resume to continue one. Modes: init, preflight, resume, validate, canary, triage, epoch_open, epoch_seal, light, opt_out.
輸入結構描述
{
"type": "object",
"properties": {
"mode": {
"default": "init",
"type": "string",
"description": "What to do: 'init' (default) starts a new governed session; 'preflight' checks an existing session's state without creating one; 'resume' re-attaches to the session in session_id; 'validate' re-checks credentials; 'canary' is a transport probe; 'triage' reads session state; 'epoch_open'/'epoch_seal' bracket a long working window; 'light' is a minimal session; 'opt_out' records a privacy opt-out.",
"enum": [
"init",
"light",
"resume",
"validate",
"canary",
"preflight",
"triage",
"epoch_open",
"epoch_seal",
"opt_out",
"opt_out_profiling"
]
},
"actor_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Your agent identity, e.g. 'kimi-code/FI-008' or 'claude/sonnet'. Recorded in the audit log so this action is attributed to you."
},
"ack_irreversible": {
"default": false,
"type": "boolean",
"description": "Set true to acknowledge that session records are permanent audit artifacts and cannot be deleted afterwards."
},
"session_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Session id returned by arif_init (looks like 'sess-…'). Pass it on every call after init so the action is attributed to your governed session."
},
"epoch_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Optional id grouping related sessions into one long-running epoch, e.g. '2026-H2-ops'."
},
"previous_session_hash": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Hash string returned when your previous session closed; supplying it chains this session to that one, proving continuity."
},
"declared_model_key": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "The model you run on, e.g. 'zai-coding-plan/glm-5.3'. Informational only — the kernel records but never trusts it."
},
"actor_signature": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Cryptographic signature over the request, if your agent holds a key — proves the call genuinely came from actor_id. Omit if you have no key."
},
"nonce": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "One-time random string (e.g. a UUID) making this request unique; protects against replay of the same call."
},
"counterparty": {
"anyOf": [
{
"additionalProperties": true,
"type": "object"
},
{
"type": "null"
}
],
"default": null,
"description": "JSON describing the other party in a two-agent exchange, e.g. {\"agent_id\": \"hermes/1\", \"role\": \"verifier\"}."
},
"context": {
"anyOf": [
{
"additionalProperties": true,
"type": "object"
},
{
"type": "null"
}
],
"default": null,
"description": "JSON object of background facts to bind into the session, e.g. {\"repo\": \"arifOS\", \"task\": \"fix-tests\"}."
},
"evidence": {
"anyOf": [
{
"additionalProperties": true,
"type": "object"
},
{
"type": "null"
}
],
"default": null,
"description": "JSON list of facts you have already verified, e.g. [{\"fact\": \"pytest 299 passed\", \"source\": \"CI run\"}] — carried into the session record."
},
"tooling": {
"anyOf": [
{
"additionalProperties": true,
"type": "object"
},
{
"type": "null"
}
],
"default": null,
"description": "JSON list of the tools you can use, e.g. [\"Bash\", \"Read\"] — lets the kernel scope what it will permit you."
},
"agent_policy": {
"anyOf": [
{
"additionalProperties": true,
"type": "object"
},
{
"type": "null"
}
],
"default": null,
"description": "JSON constraints on your own behavior, e.g. {\"autonomy\": \"reversible_only\", \"forbidden\": [\"git push\"]}."
},
"intent": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Plain-language statement of what this session is for, e.g. 'repair the failing MCP tests'. Recorded for audit."
},
"requested_authority": {
"default": "OBSERVE_ONLY",
"type": "string",
"description": "The highest class of action you may take: 'OBSERVE_ONLY' (read-only, default) or a higher governed class granted by your policy."
},
"verbose": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Legacy on/off verbosity ('true'/'false'); prefer verbosity."
},
"verbosity": {
"default": "minimal",
"enum": [
"minimal",
"standard",
"full"
],
"type": "string",
"description": "How detailed responses should be: 'minimal' (default), 'standard', or 'full'."
},
"idempotency_key": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Client-chosen key (e.g. 'job-42-attempt-1'). Retrying with the same key will not repeat the effect — safe retries on flaky networks."
},
"trace_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Correlation id of your choosing (e.g. 'req-8f3a') — lets you find this call later across kernel logs and organ systems."
},
"caller_actor_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "If you are calling on behalf of another agent, that agent's id — builds a delegation chain for the audit log."
},
"executor_actor_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Id of the agent that will actually carry out work under this session's permissions, if different from actor_id."
},
"sovereign_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Identifier of the human principal you act for, when acting under their explicit delegation."
},
"delegation_mode": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Contract governing delegated calls, e.g. 'read_only' or 'governed'."
},
"payload": {
"default": null,
"title": "Payload",
"description": "Extra mode-specific data as a JSON object; the mode's response tells you which fields it expects."
},
"_envelope": {
"default": null,
"title": "Envelope",
"description": "Reserved for the transport layer — never fill this in."
},
"client_capabilities": {
"anyOf": [
{
"additionalProperties": true,
"type": "object"
},
{
"type": "null"
}
],
"default": null,
"description": "JSON declaring what your client supports, e.g. {\"transports\": [\"http\"], \"protocol\": \"2025-11-25\"}."
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Session Continuity Token (SCT) — the credential string arif_init returned alongside session_id. Pass it back on follow-up calls to prove the session is yours; without it the kernel treats you as unauthenticated."
},
"auth_context": {
"anyOf": [
{
"additionalProperties": true,
"type": "object"
},
{
"type": "null"
}
],
"default": null,
"description": "JSON carrying external authentication material, e.g. {\"token_class\": \"bearer\", \"issuer\": \"github\"} — used for gating."
}
},
"additionalProperties": false
}🟢arif_observe(mode, query, session_id, actor_id, session_token, ...)
KERNEL 111 · Collect evidence — facts and sources with epistemic tags (OBS) and uncertainty bounds, never conclusions. mode=search queries the open web/literature; mode=fetch retrieves a URL and records its provenance; mode=vitals reads kernel machine telemetry. Reason over what you gathered with arif_think; delegate domain analysis to an organ with arif_route. Modes: search, fetch, hybrid_discovery, ingest, compass, atlas, entropy_dS, vitals.
輸入結構描述
{
"type": "object",
"properties": {
"mode": {
"default": "search",
"type": "string",
"description": "'search' (default) — web/literature query; 'fetch' — retrieve one URL with provenance; 'hybrid_discovery' — combine sources; 'ingest' — absorb a document; 'compass'/'atlas' — guided navigation; 'entropy_dS' — measure system change; 'vitals' — kernel machine telemetry.",
"enum": [
"search",
"fetch",
"hybrid_discovery",
"ingest",
"compass",
"atlas",
"entropy_dS",
"vitals"
]
},
"query": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "What to look for, in plain language, e.g. 'TDQS scoring rubric MCP'."
},
"session_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Session id returned by arif_init (looks like 'sess-…'). Pass it on every call after init so the action is attributed to your governed session."
},
"actor_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Your agent identity, e.g. 'kimi-code/FI-008' or 'claude/sonnet'. Recorded in the audit log so this action is attributed to you."
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Session Continuity Token (SCT) — the credential string arif_init returned alongside session_id. Pass it back on follow-up calls to prove the session is yours; without it the kernel treats you as unauthenticated."
},
"url": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Exact URL to retrieve when mode=fetch, e.g. 'https://example.com/report.pdf'."
},
"layers": {
"anyOf": [
{
"items": {
"type": "string"
},
"type": "array"
},
{
"type": "null"
}
],
"default": null,
"description": "Restrict where to look, e.g. [\"web\"] or [\"canon\", \"memory\"]; omit to search everything available."
},
"result_limit": {
"default": 10,
"type": "integer",
"description": "Maximum number of results to return in search modes; default 10."
},
"_envelope": {
"default": null,
"title": "Envelope",
"description": "Reserved for the transport layer — never fill this in."
}
},
"additionalProperties": false
}🟢arif_think(mode, query, session_id, actor_id, session_token, ...)
KERNEL 333 · Structured reasoning pass: decomposes a query and returns reasoning steps labeled OBS (observed), DER (derived), INT (interpretation), SPEC (specification) under truth floors. Produces reasoning records only — no verdicts (those come from arif_judge) and no state changes. The plan-family modes draft/review/approve execution plans; simulate and wonder explore counterfactuals. Modes: reason, reflect, verify, axioms, plan, plan_review, plan_approve, refactor_plan, metabolize, simulate, wonder, atlas.
輸入結構描述
{
"type": "object",
"properties": {
"mode": {
"default": "reason",
"type": "string",
"description": "'reason' (default) — decompose a question; 'reflect' — self-review of prior reasoning; 'verify' — check a derivation; 'axioms' — surface hidden assumptions; 'plan'/'plan_review'/'plan_approve'/'refactor_plan' — execution-plan lifecycle; 'metabolize' — consolidate past reasoning; 'simulate' — what-if; 'wonder' — open exploration; 'atlas' — map the problem space.",
"enum": [
"reason",
"reflect",
"verify",
"axioms",
"plan",
"plan_review",
"plan_approve",
"refactor_plan",
"metabolize",
"simulate",
"wonder",
"atlas"
]
},
"query": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "The question, claim, or problem to reason about, in plain language."
},
"session_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Session id returned by arif_init (looks like 'sess-…'). Pass it on every call after init so the action is attributed to your governed session."
},
"actor_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Your agent identity, e.g. 'kimi-code/FI-008' or 'claude/sonnet'. Recorded in the audit log so this action is attributed to you."
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Session Continuity Token (SCT) — the credential string arif_init returned alongside session_id. Pass it back on follow-up calls to prove the session is yours; without it the kernel treats you as unauthenticated."
},
"plan_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Plan reference from an earlier plan-mode response — needed for the review/approve/refactor steps."
},
"witness_type": {
"default": "ai",
"type": "string",
"description": "Who vouches for the reasoning record: 'ai' (default), 'human', or 'external' system."
},
"_envelope": {
"default": null,
"title": "Envelope",
"description": "Reserved for the transport layer — never fill this in."
}
},
"additionalProperties": false
}🟢arif_route(intent, mode, organ, task, actor_id, ...)
KERNEL 444 · Intent→organ router: classifies a natural-language intent and dispatches it to the specialist organ (GEOX geoscience, WEALTH capital, WELL vitality, A-FORGE execution). Returns the routing decision only — no organ call — unless organ_tool names the target tool and arguments carries its inputs. Prefer this over guessing organs yourself; use arif_think for reasoning you keep in-kernel.
輸入結構描述
{
"type": "object",
"properties": {
"intent": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Natural-language description of what the user wants.\n e.g. \"interpret this seismic section\", \"assess portfolio risk\""
},
"mode": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": "route"
},
"organ": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Optional explicit organ override. If provided, intent matching\n is skipped and this organ is used directly."
},
"task": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Alias for intent (backward compat)."
},
"actor_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Your agent identity, e.g. 'kimi-code/FI-008' or 'claude/sonnet'. Recorded in the audit log so this action is attributed to you."
},
"session_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Session id returned by arif_init (looks like 'sess-…'). Pass it on every call after init so the action is attributed to your governed session."
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Session Continuity Token (SCT) — the credential string arif_init returned alongside session_id. Pass it back on follow-up calls to prove the session is yours; without it the kernel treats you as unauthenticated."
},
"organ_tool": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "The tool name on the target organ to call.\n If absent, returns routing decision only (no bridge call)."
},
"arguments": {
"anyOf": [
{
"additionalProperties": true,
"type": "object"
},
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Arguments to pass to organ_tool."
},
"mission_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Explicit human-cockpit mission binding (investigate|interpret|\n decide|build|monitor|remember). When set, skips keyword\n classification and binds the six-mission plan. Preferred\n over free-text when the agent already knows the mission."
},
"_envelope": {
"default": null,
"title": "Envelope",
"description": "Reserved for the transport layer — never fill this in."
},
"contract_c_kwargs": {
"anyOf": [
{
"additionalProperties": true,
"type": "object"
},
{
"type": "null"
}
],
"default": null,
"description": "Extra keyword arguments passed through to the organ tool call, as a JSON object."
}
},
"additionalProperties": false
}🔴arif_memory(mode, query, memory_id, content, tier, ...)
KERNEL 555 · Governed memory of the kernel itself: six tiers (L1–L6) with per-mode gating. recall, inspect, and audit are read paths; remember, revise, promote, and forget mutate tiers — promote and forget additionally require human_approval=true. Use for cross-session lessons, canon, and memory audit; external evidence belongs to arif_observe and reasoning artifacts to arif_think. Modes: recall, inspect, attest, remember, promote, revise, forget, audit, metabolize.
輸入結構描述
{
"type": "object",
"properties": {
"mode": {
"type": "string",
"default": "recall",
"enum": [
"recall",
"inspect",
"attest",
"remember",
"promote",
"revise",
"forget",
"audit",
"metabolize"
],
"description": "'recall' (default) — semantic search of stored memories; 'inspect' — read one memory in full; 'attest' — vouch for a memory's accuracy; 'remember' — store new text; 'promote' — move a memory up a tier; 'revise' — replace a memory's text; 'forget' — remove a memory (gated); 'audit' — integrity scan; 'metabolize' — compact and consolidate tiers."
},
"query": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "What to search for, in plain language (mode=recall/audit), e.g. 'past deploy rollback steps'."
},
"memory_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "UUID of the memory entry to inspect/revise/forget — it was returned when the memory was created or last listed."
},
"content": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "The text to store (mode=remember) — write it as a self-contained lesson or fact."
},
"tier": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Which memory tier to target, 'L1'–'L6' (L1 = hot working memory, L6 = sealed canon)."
},
"to_tier": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Destination tier when promoting, e.g. 'L4'."
},
"new_content": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Replacement text for the memory (mode=revise) — must refer to the same memory_id."
},
"human_approval": {
"type": "boolean",
"default": false,
"description": "Set true ONLY when the human owner explicitly approved this promote/forget — the gate refuses without it."
},
"payload": {
"anyOf": [
{
"type": "object"
},
{
"type": "null"
}
],
"default": null,
"description": "Extra mode-specific fields as JSON — e.g. {\"truth_class\": \"DERIVED\", \"provenance\": \"CI log\"} for remember."
},
"session_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Session id returned by arif_init; attributes this call to your governed session."
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Session Continuity Token (SCT) returned by arif_init — proves the session is yours."
},
"actor_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Your agent identity, e.g. 'kimi-code/FI-008' — recorded in the audit log."
},
"lease_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Id of a short-lived permission grant (lease) authorizing this write, when one was issued to you."
},
"idempotency_key": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Client-chosen key (e.g. 'memo-42'); retries with the same key will not store duplicates."
},
"trace_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Correlation id of your choosing (e.g. 'req-8f3a') to find this call later in the logs."
}
},
"additionalProperties": false
}🟢arif_judge(mode, candidate, session_id, session_token, actor_id, ...)
KERNEL 666 · Binding constitutional arbitration: evaluates a candidate action or claim and returns SEAL / HOLD / SABAR / VOID with the full reason chain. Weighs action class, blast radius, reversibility, entropy pathway, and cooling state; a SEAL verdict here is what arif_forge requires before it will execute anything. Judge arbitrates — it does not gather (evidence comes via arif_observe, reasoning via arif_think) and it does not mutate (execution is arif_forge, permanence is arif_seal). Modes: judge, intercept, validate, hold, escalate.
輸入結構描述
{
"type": "object",
"properties": {
"mode": {
"default": "judge",
"type": "string",
"description": "'judge' (default) — render a verdict on candidate; 'intercept' — pre-flight gate before an action runs; 'validate' — re-check a prior verdict; 'hold' — place an action into a cooling period; 'escalate' — refer the decision to the human owner.",
"enum": [
"intercept",
"judge",
"validate",
"hold",
"escalate"
]
},
"candidate": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "The action or claim being judged, stated plainly, e.g. 'delete table users in prod'."
},
"session_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Session id returned by arif_init (looks like 'sess-…'). Pass it on every call after init so the action is attributed to your governed session."
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Session Continuity Token (SCT) — the credential string arif_init returned alongside session_id. Pass it back on follow-up calls to prove the session is yours; without it the kernel treats you as unauthenticated."
},
"actor_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Your agent identity, e.g. 'kimi-code/FI-008' or 'claude/sonnet'. Recorded in the audit log so this action is attributed to you."
},
"constitutional_chain_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Id of the evidence chain this call belongs to (observe→think→judge→seal). Copy it from the earlier step's response to link the steps together."
},
"vault_entry_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Id of the permanent-ledger entry this verdict should attach to (from an earlier arif_seal response)."
},
"cooldown_entry_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Id of an existing cooling-period record to consult before this action may proceed."
},
"action_tier": {
"default": "standard",
"type": "string",
"description": "How risky the action is: 'standard', 'high', or 'critical' — higher tiers demand stronger evidence."
},
"heart_critique": {
"anyOf": [
{
"additionalProperties": true,
"type": "object"
},
{
"type": "null"
}
],
"default": null,
"description": "JSON result of an ethics/dignity check, e.g. {\"coercion\": false, \"dignity\": 0.9} — feeds the verdict."
},
"niat_params": {
"anyOf": [
{
"additionalProperties": true,
"type": "object"
},
{
"type": "null"
}
],
"default": null,
"description": "JSON intent-calibration settings, e.g. {\"sincerity\": 0.8, \"stated_goal\": \"verify the claim\"}."
},
"context_source": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Where the candidate came from: 'session', 'file', or 'memory'."
},
"sovereign_receipt": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Reference to the human owner's explicit approval, for the rare case where they have already decided directly."
},
"evidence": {
"anyOf": [
{
"additionalProperties": true,
"type": "object"
},
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "The facts the verdict should rest on — a JSON list like [{\"fact\": \"tests pass\", \"source\": \"CI\"}], or an object."
},
"actor_signature": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Cryptographic signature over the request, if your agent holds a key — proves the call genuinely came from actor_id. Omit if you have no key."
},
"nonce": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "One-time random string (e.g. a UUID) making this request unique; protects against replay of the same call."
},
"key_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Which of your registered keys produced actor_signature, e.g. 'key-1'."
},
"reversibility_level": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "How hard the action would be to undo: 'reversible', 'hard', or 'irreversible'."
},
"blast_radius": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Who or what the action can affect: 'self', 'session', 'organ', or 'federation'."
},
"seal_purpose": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "One sentence saying why this verdict/record must exist, e.g. 'closing deployment D-17'. Stored permanently alongside the record."
},
"authority_effect": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "What permission a SEAL verdict would grant, e.g. 'execute forge plan P-9'."
},
"action_class": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Kind of action under judgment: 'OBSERVE' (read-only), 'DRAFT' (compose text), 'MUTATE' (change state), 'IRREVERSIBLE' (permanent)."
},
"requested_capability": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "The specific capability being requested, e.g. 'forge.execute' — checked against the capability registry."
},
"domain": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Subject area for claim evaluation, e.g. 'geoscience' or 'finance'."
},
"claim_class": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Epistemic strength of the claim: 'OBS' (directly observed), 'DER' (derived from observations), 'INT' (interpreted), 'SPEC' (speculative)."
},
"claim_text": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "The exact claim sentence under judgment, e.g. 'uptime exceeded 99% in August'."
},
"actor_B": {
"anyOf": [
{
"type": "number"
},
{
"type": "null"
}
],
"default": null,
"description": "Your calibrated confidence for a prediction, 0.0–1.0 (Brier-style score component)."
},
"actor_Phi": {
"anyOf": [
{
"additionalProperties": true,
"type": "object"
},
{
"type": "null"
}
],
"default": null,
"description": "JSON map of supporting signals about you, e.g. {\"consistency\": 0.9, \"track_record\": 0.7}."
},
"entropy_pathway": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "How the action changes system order: 'reduces', 'neutral', or 'increases' complexity."
},
"entropy_receipt": {
"anyOf": [
{
"additionalProperties": true,
"type": "object"
},
{
"type": "null"
}
],
"default": null,
"description": "JSON receipt from an entropy computation, bound to this judgment."
},
"_envelope": {
"default": null,
"title": "Envelope",
"description": "Reserved for the transport layer — never fill this in."
}
},
"additionalProperties": false
}🔴arif_forge(mode, manifest, seal_verdict_id, approved_action_hash, query, ...)
KERNEL 777 · Governed execution: applies a mutation through A-FORGE only when carrying a SEAL verdict (seal_verdict_id) from arif_judge and a live session. The manifest/query defines exactly what changes; mode=dry_run previews the plan without applying it. This is the only verb that executes general mutations — kernel memory writes go to arif_memory and permanent records to arif_seal.
輸入結構描述
{
"type": "object",
"properties": {
"mode": {
"default": "engineer",
"type": "string",
"description": "'engineer' (default) — plan and apply the work; 'dry_run' — preview what would happen, nothing is applied; 'query' — read-only questions about the workspace; 'write' — write files; 'generate' — generate code or content; 'commit' — commit prepared work; 'recall' — retrieve past forge artifacts.",
"enum": [
"engineer",
"query",
"write",
"generate",
"commit",
"recall",
"dry_run"
]
},
"manifest": {
"default": "",
"type": "string",
"description": "The work order (usually JSON or markdown) describing exactly what to build or change — the more specific, the tighter the gate."
},
"seal_verdict_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "The SEAL verdict id arif_judge returned — without it, nothing is executed."
},
"approved_action_hash": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Hash of the exact action that was judged — execution is refused if what you submit differs from it."
},
"query": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "The task in plain language when no manifest is supplied, e.g. 'restart the gateway service'."
},
"artifact_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Id of an existing artifact (from an earlier forge or judge response) that this call operates on."
},
"session_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Session id returned by arif_init; scopes this execution to your governed session."
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Session Continuity Token (SCT) returned by arif_init — proves the session is yours."
},
"ack_irreversible": {
"default": false,
"type": "boolean",
"description": "Set true to confirm you accept this execution cannot be undone, when the judged action was irreversible."
},
"actor_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Your agent identity, e.g. 'kimi-code/FI-008' — recorded in the audit log."
},
"constitutional_chain_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Id of the evidence chain (observe→think→judge) that led to the SEAL — copy it from the judge response."
},
"judge_state_hash": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Hash string from the arif_judge SEAL response — proves the verdict has not been tampered with."
},
"vault_entry_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Id of the permanent-ledger entry linked to this execution, when one already exists."
},
"plan_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Plan id from arif_think's plan mode, when executing an approved plan."
},
"arif_ack_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Acknowledgment id from a prior step, for multi-step execution chains."
},
"_envelope": {
"default": null,
"title": "Envelope",
"description": "Internal transport envelope handle — server-side; omit."
}
},
"additionalProperties": false
}🔴arif_seal(mode, payload, session_id, actor_id, session_token, ...)
KERNEL 999 · Append an entry to VAULT999, the immutable ledger — accepted entries can never be edited or removed; there is no unseal. Use for permanent records of verified outcomes, lessons, and session closure once a verdict exists. ack_irreversible=true is the explicit acknowledgment of permanence, and judge_state_hash binds the entry to the verdict that authorized it. Reversible changes belong in arif_forge under a SEAL. Modes: seal, verify, ledger, changelog, audit, session_close.
輸入結構描述
{
"type": "object",
"properties": {
"mode": {
"default": "seal",
"type": "string",
"description": "'seal' (default) — append a permanent entry; 'verify' — check one entry; 'ledger' — read the ledger head; 'changelog' — recent appends; 'audit' — integrity check; 'session_close' — close out a session into the ledger.",
"enum": [
"seal",
"verify",
"ledger",
"changelog",
"audit",
"session_close"
]
},
"payload": {
"default": "",
"type": "string",
"description": "The content to store forever, as a string (usually JSON-serialized) — the outcome, lesson, or record itself."
},
"session_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Session id returned by arif_init (looks like 'sess-…'). Pass it on every call after init so the action is attributed to your governed session."
},
"actor_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Your agent identity, e.g. 'kimi-code/FI-008' or 'claude/sonnet'. Recorded in the audit log so this action is attributed to you."
},
"session_token": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Session Continuity Token (SCT) — the credential string arif_init returned alongside session_id. Pass it back on follow-up calls to prove the session is yours; without it the kernel treats you as unauthenticated."
},
"actor_signature": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Cryptographic signature over the request, if your agent holds a key — proves the call genuinely came from actor_id. Omit if you have no key."
},
"nonce": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "One-time random string (e.g. a UUID) making this request unique; protects against replay of the same call."
},
"constitutional_chain_id": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Id of the evidence chain this call belongs to (observe→think→judge→seal). Copy it from the earlier step's response to link the steps together."
},
"judge_state_hash": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "Hash string from the arif_judge SEAL response — ties this entry to the verdict that authorized it."
},
"witness_type": {
"default": "ai",
"type": "string",
"description": "Who witnessed the sealed fact: 'ai', 'human', or 'external' system."
},
"drift_events": {
"anyOf": [
{
"items": {
"additionalProperties": true,
"type": "object"
},
"type": "array"
},
{
"type": "null"
}
],
"default": null,
"description": "JSON list of deviations observed, e.g. [{\"what\": \"schema drift\", \"where\": \"tools/list\"}] — stored with the record."
},
"constitutional": {
"anyOf": [
{
"additionalProperties": true,
"type": "object"
},
{
"type": "null"
}
],
"default": null,
"description": "JSON block of governance metadata (floors consulted, chain references) — normally built by the kernel, not by callers."
},
"seal_purpose": {
"anyOf": [
{
"type": "string"
},
{
"type": "null"
}
],
"default": null,
"description": "One sentence saying why this verdict/record must exist, e.g. 'closing deployment D-17'. Stored permanently alongside the record."
},
"ack_irreversible": {
"default": false,
"type": "boolean",
"description": "Set true to confirm you understand sealed entries are PERMANENT — they can never be edited or removed."
},
"_envelope": {
"default": null,
"title": "Envelope",
"description": "Reserved for the transport layer — never fill this in."
}
},
"additionalProperties": false
}社群
證據