Skip to main content
Glama

review

Read-only

Independent verdict on a proposed action before it is taken: a code diff, shell command, deployment plan, configuration change, another agent's output, or a proposed transaction. Returns approve / approve_with_concerns / reject with a confidence score, issues ranked by severity, suggested fixes and alternatives. With sign=true the verdict is returned as a signed proof that anyone can check later with verify_proof. The verdict is a reasoned second opinion, not a guarantee of outcome. Docs: https://api.babyblueviper.com/docs

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
signNoReturn the verdict as a portable signed proof (binds verdict, artifact hash and invinoveritas's public key, plus a content-addressed decision_ref). Anyone can check it later with verify_proof.
contextNoWhat you are trying to accomplish, why now, success criteria
artifactYesThe artifact to review: unified diff / patch, shell command, plan, config, analysis, agent output, or raw text
concernsNoSpecific things to check (e.g. 'production safety', 'edge cases in trading logic', 'regulatory risk')
artifact_typeNoType of artifact. 'code_diff' or 'patch' triggers deep code review. 'plan' for architecture/strategy. 'trade' triggers the capital-scale-aware risk-manager review of a proposed entry/exit. 'onchain_action' triggers the on-chain risk review of a proposed transfer/swap/approval/contract call (e.g. a Base MCP action) BEFORE you sign it — catches scam/honeypot tokens, unlimited-allowance drainers, address poisoning, slippage/MEV. 'sanctions_screening' for a compliance/AML result BEFORE acting on it — checks a categorical verdict (e.g. CLEAN) carries its own scope, not an unscoped claim. Tailors focus and suggestions. IMPORTANT for trade/onchain_action/sanctions_screening: a REJECT can happen purely from low confidence on an action you can't undo, even if content-wise the review leaned approve — see the response's reversibility_gate field. When present, epistemic_basis tells you WHY it's a reject: 'evidence_against' means a deterministic engine found a real positive finding (a known-bad address, an on-chain/sanctions hit); 'insufficient_evidence' means no finding either way, just confidence below the reversibility floor — different situations, do not treat them identically if your own logic branches on the reason.general
verdict_relayNoOptional (verdict-relay/v2): also return a BIP-340 signature an ERC-8414 InvinoveritasVerdictAuthoritySigned contract verifies on-chain (garyyang-finchip/task-token-standard#2). {chain_id, authority, task_contract, token_id, submission_id, task_version, result_hash, task_document}. Requires sign=true. result_hash must be sha256 of the exact artifact; task_document is the plaintext task document (sha256 = the kernel's tdHash) and is put into the review context. approved/decision_ref come from our own verdict (approve->true, reject->false; concerns/defer unsigned). Checked before any charge. Result field verdict_relay.
action_bindingNoOptional: the exact real-world action this verdict authorizes — tool identity, materialized (not templated) arguments, and the id of the agent that will execute it, e.g. {'tool': 'place_order', 'agent_id': 'your-stable-agent-id', 'args': {...}}. v14+: `tool` and `args` are bound as SEPARATE preimage fields (action_binding_tool_hash = sha256(tool), action_binding_args_hash = sha256(RFC-8785-JCS(args))) so a verifier can assert 'same tool, different arguments' as a checkable statement; `agent_id` is bound as a plain string (action_binding_agent_id, not hashed). All bound DIRECTLY into decision_ref — so the verdict commits to the exact action, not just the free-text `artifact` argument or the verdict conclusion. Recomputing decision_ref without byte-identical tool/args/agent_id values produces a different hash: an approval cannot be replayed against a different tool, different materialized arguments, or a different agent. Every sub-key is optional. Max ~8KB JSON-encoded. NOT independently verified by us — we hash exactly what you send. HONEST LIMIT: nothing stops a caller from submitting an under-specified action_binding (e.g. tool+side but not size) and getting an approval reusable across the omitted dimension — that's about who controls what goes into the fingerprint, not how it's hashed.
related_claimsNoOptional (policy v20): a structured claim about related_proof_event -- a non-empty subset of {artifact_hash, verdict, verified_at, policy_version, decision_ref}. Compared by exact equality against the referenced proof (which we re-verify); the claims hash, comparison version and result (matched|mismatched|missing_proof|unverifiable_proof; not_supplied if omitted) are bound into decision_ref. Faithful restatement only: not relevance, authorization or truth.
disclosed_summaryNoOnly used when confidentiality_tier='partial_disclosure'. A real, human-readable description of the reviewed artifact/decision you're choosing to make public — bound raw into decision_ref. Ignored for other tier values.
external_evidenceNoOptional (v17, 2026-09-10): third-party evidence this judgment relied on — e.g. a tool-reliability registry's own historical PASS/FAIL record, worked out live with arian-gogani/nobulex-registry#1. Array of {'source': str, 'record': str (the issuer's OWN exact saved bytes, verbatim — never re-parsed/re-emitted as JSON on our side), 'record_sha256': str (issuer-computed, not independently verified by us), 'evidence_type': str, 'observed_at': ISO 8601, 'validity_until': ISO 8601 | null}. All entries hashed together (RFC-8785-JCS) into external_evidence_hash, bound into decision_ref — so 'this exact evidence was what the verdict considered' is checkable, not just claimed in reasoning text. Does NOT authenticate the issuer, verify record_sha256, or establish freshness — that's the caller's own responsibility before relying on the cited evidence.
intended_audienceNoOptional: declare who/what this verdict is intended for (your own DID, endpoint URL, or gateway identifier). Bound into decision_ref so it can't be silently stripped or altered once issued. NOT independently verified — a reader compares this against their own identity and treats a mismatch as a signal the proof may be presented outside its intended context, a real context-binding replay-protection gap that earlier policy versions had no way to represent at all.
intended_verifierNoOptional: a CAIP-10 string naming the specific on-chain verifier/gate this verdict is meant to be checked against, e.g. 'eip155:8453:0x8004A169FB4a3325136EB29fA0ceB6D2e539a432'. Bound into decision_ref (itself inside the schnorr-signed content) so it achieves real crypto-level domain separation — the raw signed bytes otherwise bind only to our pubkey + content, nothing to a specific chain/contract, so a proof is technically replayable against any gate willing to accept it. NOT independently verified — a gate compares this against its own chain_id/address.
severity_thresholdNoMinimum severity to reportall
related_proof_eventNoOptional: if the artifact being reviewed IS another party's already-signed verdict proof (a verdict-of-verdict re-review), pass that proof's full signed event ({id, pubkey, created_at, kind, tags, content, sig}). We independently re-verify it ourselves before its source_class can affect this call's own — capped, never upgraded (an independent_mediator call reviewing an agent_reported inner verdict stays agent_reported). Fails closed to agent_reported if the inner event doesn't verify, regardless of your own registry status. One hop only. HONEST SCOPE: we verify the cited event's own authenticity, not that it's actually the thing your artifact claims to be re-reviewing.
request_capture_refNoOptional: a requester-controlled commitment (a hash/id you generated and can independently prove existed at request-time) that this artifact was submitted for review — the captured-admission-v0 review profile (trustless-ai/recompute-kit). Echoed back verbatim in the response's admission_receipt. NOT independently verified by us; closes the /ledger raw-tape-vs-published gap only for requesters who opt in.
confidentiality_tierNoWhich privacy/evidentiary tradeoff this verdict should use, only meaningful with sign=true. 'hash_only' (default): the proof carries only artifact_hash, raw content never disclosed — strongest privacy, weakest standalone evidentiary value (a third party can't confirm what the hash corresponds to without your later cooperation). 'partial_disclosure': pass disclosed_summary, bound raw into decision_ref, so a third party gets real checkable context without full exposure. 'full_disclosure': records intent to publish this verdict to the public /ledger (full_disclosure_requested=true in the proof) — strongest evidentiary tier, but actual publication is still a separate curated step on our side, not yet fully self-serve.hash_only
mediator_attestationNoOptional (v22): your mediator proves control of its own key. {key_url (https, mediator's own domain), public_key_ed25519_b64, requested_at (unix s, +-600 s), nonce (8-128 ASCII), signature_ed25519_b64} -- Ed25519 over the RFC 8785 JCS bytes of {schema:'invinoveritas.mediator_request.v1', artifact_hash (sha256 hex of the exact artifact), artifact_type, requested_at, nonce}; key_url must list the key. Requires sign=true; checked before any charge; bound into the proof as mediator_attestation_hash. Establishes key control at issue time, NOT independence.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changed
    • addedInput schema / properties / verdict_relay
      Added value: +{
      +  "description": "Optional (verdict-relay/v2): also return a BIP-340 signature an ERC-8414 InvinoveritasVerdictAuthoritySigned contract verifies on-chain (garyyang-finchip/task-token-standard#2). {chain_id, authority, task_contract, token_id, submission_id, task_version, result_hash, task_document}. Requires sign=true. result_hash must be sha256 of the exact artifact; task_document is the plaintext task document (sha256 = the kernel's tdHash) and is put into the review context. approved/decision_ref come from our own verdict (approve->true, reject->false; concerns/defer unsigned). Checked before any charge. Result field verdict_relay.",
      +  "type": "object"
      +}
  2. Changed2 schema fields changed
    • changedInput schema / examples
      Previous value: -[
      -  {
      -    "artifact": "systemctl restart my-trading-bot.service && curl -X POST https://api.exchange.com/v3/order -d '{\"side\":\"buy\",\"qty\":100000}'",
      -    "artifact_type": "shell_command",
      -    "concerns": "Is the order-of-operations safe? What can go wrong between restart and the order?",
      -    "context": "About to deploy a tuned config and immediately open a 100k-sat position on the exchange",
      -    "severity_threshold": "high"
      -  }
      -]New value: +[
      +  {
      +    "artifact": "rm -rf ./build && git push --force origin main",
      +    "artifact_type": "shell_command",
      +    "context": "About to force-push a rebuilt main branch that other people pull from.",
      +    "sign": true
      +  }
      +]
    • changedInput schema / properties / sign / description
      Previous value: -"Return a PORTABLE SIGNED proof of this verdict (binds verdict + artifact hash + our pubkey), including a content-addressed decision_ref = sha256(JCS({artifact_hash, artifact_type, policy_version, verdict, source_class})). Attach it to your output so a downstream agent can confirm via verify_proof — WITHOUT trusting you or us — that invinoveritas issued this verdict for this exact artifact. The agent-to-agent trust handshake. For artifact_type=trade|onchain_action|sanctions_screening, the proof also carries source_class ('agent_reported' today — no mediation-point integration exists yet) and, when applicable, a vantage_limitation field disclosing that the verdict is occurrence evidence, not an absence/completeness claim — check it before treating an irreversible-class verdict as sufficient on its own. The proof also carries an opaque engine_generation counter (informational, not bound into decision_ref) — compare it across two proofs to detect a backend/judgment-engine change between calls without us disclosing which model we run."New value: +"Return the verdict as a portable signed proof (binds verdict, artifact hash and invinoveritas's public key, plus a content-addressed decision_ref). Anyone can check it later with verify_proof."
  3. Changed1 schema field changed
    • removedInput schema / properties / include_trading_state
      Removed value: -{
      -  "default": false,
      -  "description": "Sentinel mode: inject live Sovereign Earner state (equity, regime, open position, PnL) for trading-related reviews. Highly recommended for any trading or risk decision.",
      -  "type": "boolean"
      -}
  4. Changed1 schema field changed
    • addedInput schema / properties / mediator_attestation
      Added value: +{
      +  "description": "Optional (v22): your mediator proves control of its own key. {key_url (https, mediator's own domain), public_key_ed25519_b64, requested_at (unix s, +-600 s), nonce (8-128 ASCII), signature_ed25519_b64} -- Ed25519 over the RFC 8785 JCS bytes of {schema:'invinoveritas.mediator_request.v1', artifact_hash (sha256 hex of the exact artifact), artifact_type, requested_at, nonce}; key_url must list the key. Requires sign=true; checked before any charge; bound into the proof as mediator_attestation_hash. Establishes key control at issue time, NOT independence.",
      +  "type": "object"
      +}
  5. Changed1 schema field changed
    • addedInput schema / properties / related_claims
      Added value: +{
      +  "description": "Optional (policy v20): a structured claim about related_proof_event -- a non-empty subset of {artifact_hash, verdict, verified_at, policy_version, decision_ref}. Compared by exact equality against the referenced proof (which we re-verify); the claims hash, comparison version and result (matched|mismatched|missing_proof|unverifiable_proof; not_supplied if omitted) are bound into decision_ref. Faithful restatement only: not relevance, authorization or truth.",
      +  "type": "object"
      +}
  6. Changed1 schema field changed
    • addedInput schema / properties / external_evidence
      Added value: +{
      +  "description": "Optional (v17, 2026-09-10): third-party evidence this judgment relied on — e.g. a tool-reliability registry's own historical PASS/FAIL record, worked out live with arian-gogani/nobulex-registry#1. Array of {'source': str, 'record': str (the issuer's OWN exact saved bytes, verbatim — never re-parsed/re-emitted as JSON on our side), 'record_sha256': str (issuer-computed, not independently verified by us), 'evidence_type': str, 'observed_at': ISO 8601, 'validity_until': ISO 8601 | null}. All entries hashed together (RFC-8785-JCS) into external_evidence_hash, bound into decision_ref — so 'this exact evidence was what the verdict considered' is checkable, not just claimed in reasoning text. Does NOT authenticate the issuer, verify record_sha256, or establish freshness — that's the caller's own responsibility before relying on the cited evidence.",
      +  "type": "array"
      +}
  7. Changed1 schema field changed
    • changedInput schema / properties / artifact_type / description
      Previous value: -"Type of artifact. 'code_diff' or 'patch' triggers deep code review. 'plan' for architecture/strategy. 'trade' triggers the capital-scale-aware risk-manager review of a proposed entry/exit. 'onchain_action' triggers the on-chain risk review of a proposed transfer/swap/approval/contract call (e.g. a Base MCP action) BEFORE you sign it — catches scam/honeypot tokens, unlimited-allowance drainers, address poisoning, slippage/MEV. 'sanctions_screening' for a compliance/AML result BEFORE acting on it — checks a categorical verdict (e.g. CLEAN) carries its own scope, not an unscoped claim. Tailors focus and suggestions. IMPORTANT for trade/onchain_action/sanctions_screening: a REJECT can happen purely from low confidence on an action you can't undo, even if content-wise the review leaned approve — see the response's reversibility_gate field."New value: +"Type of artifact. 'code_diff' or 'patch' triggers deep code review. 'plan' for architecture/strategy. 'trade' triggers the capital-scale-aware risk-manager review of a proposed entry/exit. 'onchain_action' triggers the on-chain risk review of a proposed transfer/swap/approval/contract call (e.g. a Base MCP action) BEFORE you sign it — catches scam/honeypot tokens, unlimited-allowance drainers, address poisoning, slippage/MEV. 'sanctions_screening' for a compliance/AML result BEFORE acting on it — checks a categorical verdict (e.g. CLEAN) carries its own scope, not an unscoped claim. Tailors focus and suggestions. IMPORTANT for trade/onchain_action/sanctions_screening: a REJECT can happen purely from low confidence on an action you can't undo, even if content-wise the review leaned approve — see the response's reversibility_gate field. When present, epistemic_basis tells you WHY it's a reject: 'evidence_against' means a deterministic engine found a real positive finding (a known-bad address, an on-chain/sanctions hit); 'insufficient_evidence' means no finding either way, just confidence below the reversibility floor — different situations, do not treat them identically if your own logic branches on the reason."
  8. Changed1 schema field changed
    • addedInput schema / properties / action_binding
      Added value: +{
      +  "description": "Optional: the exact real-world action this verdict authorizes — tool identity, materialized (not templated) arguments, and the id of the agent that will execute it, e.g. {'tool': 'place_order', 'agent_id': 'your-stable-agent-id', 'args': {...}}. v14+: `tool` and `args` are bound as SEPARATE preimage fields (action_binding_tool_hash = sha256(tool), action_binding_args_hash = sha256(RFC-8785-JCS(args))) so a verifier can assert 'same tool, different arguments' as a checkable statement; `agent_id` is bound as a plain string (action_binding_agent_id, not hashed). All bound DIRECTLY into decision_ref — so the verdict commits to the exact action, not just the free-text `artifact` argument or the verdict conclusion. Recomputing decision_ref without byte-identical tool/args/agent_id values produces a different hash: an approval cannot be replayed against a different tool, different materialized arguments, or a different agent. Every sub-key is optional. Max ~8KB JSON-encoded. NOT independently verified by us — we hash exactly what you send. HONEST LIMIT: nothing stops a caller from submitting an under-specified action_binding (e.g. tool+side but not size) and getting an approval reusable across the omitted dimension — that's about who controls what goes into the fingerprint, not how it's hashed.",
      +  "type": "object"
      +}
  9. Changed1 schema field changed
    • addedInput schema / properties / request_capture_ref
      Added value: +{
      +  "description": "Optional: a requester-controlled commitment (a hash/id you generated and can independently prove existed at request-time) that this artifact was submitted for review — the captured-admission-v0 review profile (trustless-ai/recompute-kit). Echoed back verbatim in the response's admission_receipt. NOT independently verified by us; closes the /ledger raw-tape-vs-published gap only for requesters who opt in.",
      +  "type": "string"
      +}
  10. Changed1 schema field changed
    • addedInput schema / properties / intended_verifier
      Added value: +{
      +  "description": "Optional: a CAIP-10 string naming the specific on-chain verifier/gate this verdict is meant to be checked against, e.g. 'eip155:8453:0x8004A169FB4a3325136EB29fA0ceB6D2e539a432'. Bound into decision_ref (itself inside the schnorr-signed content) so it achieves real crypto-level domain separation — the raw signed bytes otherwise bind only to our pubkey + content, nothing to a specific chain/contract, so a proof is technically replayable against any gate willing to accept it. NOT independently verified — a gate compares this against its own chain_id/address.",
      +  "type": "string"
      +}
  11. Changed2 schema fields changed
    • addedInput schema / properties / confidentiality_tier
      Added value: +{
      +  "default": "hash_only",
      +  "description": "Which privacy/evidentiary tradeoff this verdict should use, only meaningful with sign=true. 'hash_only' (default): the proof carries only artifact_hash, raw content never disclosed — strongest privacy, weakest standalone evidentiary value (a third party can't confirm what the hash corresponds to without your later cooperation). 'partial_disclosure': pass disclosed_summary, bound raw into decision_ref, so a third party gets real checkable context without full exposure. 'full_disclosure': records intent to publish this verdict to the public /ledger (full_disclosure_requested=true in the proof) — strongest evidentiary tier, but actual publication is still a separate curated step on our side, not yet fully self-serve.",
      +  "enum": [
      +    "hash_only",
      +    "partial_disclosure",
      +    "full_disclosure"
      +  ],
      +  "type": "string"
      +}
    • addedInput schema / properties / disclosed_summary
      Added value: +{
      +  "description": "Only used when confidentiality_tier='partial_disclosure'. A real, human-readable description of the reviewed artifact/decision you're choosing to make public — bound raw into decision_ref. Ignored for other tier values.",
      +  "type": "string"
      +}
  12. Changed1 schema field changed
    • addedInput schema / properties / intended_audience
      Added value: +{
      +  "description": "Optional: declare who/what this verdict is intended for (your own DID, endpoint URL, or gateway identifier). Bound into decision_ref so it can't be silently stripped or altered once issued. NOT independently verified — a reader compares this against their own identity and treats a mismatch as a signal the proof may be presented outside its intended context, a real context-binding replay-protection gap that earlier policy versions had no way to represent at all.",
      +  "type": "string"
      +}
  13. Changed1 schema field changed
    • addedInput schema / properties / related_proof_event
      Added value: +{
      +  "description": "Optional: if the artifact being reviewed IS another party's already-signed verdict proof (a verdict-of-verdict re-review), pass that proof's full signed event ({id, pubkey, created_at, kind, tags, content, sig}). We independently re-verify it ourselves before its source_class can affect this call's own — capped, never upgraded (an independent_mediator call reviewing an agent_reported inner verdict stays agent_reported). Fails closed to agent_reported if the inner event doesn't verify, regardless of your own registry status. One hop only. HONEST SCOPE: we verify the cited event's own authenticity, not that it's actually the thing your artifact claims to be re-reviewing.",
      +  "type": "object"
      +}
  14. Changed1 schema field changed
    • changedInput schema / properties / sign / description
      Previous value: -"Return a PORTABLE SIGNED proof of this verdict (binds verdict + artifact hash + our pubkey), including a content-addressed decision_ref = sha256(JCS({artifact_hash, artifact_type, policy_version, verdict, source_class})). Attach it to your output so a downstream agent can confirm via verify_proof — WITHOUT trusting you or us — that invinoveritas issued this verdict for this exact artifact. The agent-to-agent trust handshake. For artifact_type=trade|onchain_action|sanctions_screening, the proof also carries source_class ('agent_reported' today — no mediation-point integration exists yet) and, when applicable, a vantage_limitation field disclosing that the verdict is occurrence evidence, not an absence/completeness claim — check it before treating an irreversible-class verdict as sufficient on its own."New value: +"Return a PORTABLE SIGNED proof of this verdict (binds verdict + artifact hash + our pubkey), including a content-addressed decision_ref = sha256(JCS({artifact_hash, artifact_type, policy_version, verdict, source_class})). Attach it to your output so a downstream agent can confirm via verify_proof — WITHOUT trusting you or us — that invinoveritas issued this verdict for this exact artifact. The agent-to-agent trust handshake. For artifact_type=trade|onchain_action|sanctions_screening, the proof also carries source_class ('agent_reported' today — no mediation-point integration exists yet) and, when applicable, a vantage_limitation field disclosing that the verdict is occurrence evidence, not an absence/completeness claim — check it before treating an irreversible-class verdict as sufficient on its own. The proof also carries an opaque engine_generation counter (informational, not bound into decision_ref) — compare it across two proofs to detect a backend/judgment-engine change between calls without us disclosing which model we run."
  15. Changed1 schema field changed
    • changedInput schema / properties / sign / description
      Previous value: -"Return a PORTABLE SIGNED proof of this verdict (binds verdict + artifact hash + our pubkey), including a content-addressed decision_ref = sha256(JCS({artifact_hash, artifact_type, policy_version, verdict, source_class})). Attach it to your output so a downstream agent can confirm via verify_proof — WITHOUT trusting you or us — that invinoveritas issued this verdict for this exact artifact. The agent-to-agent trust handshake. For artifact_type=trade|onchain_action|sanctions_screening, the proof also carries source_class ('agent_reported' today — no mediation-point integration exists yet) and, when applicable, a vantage_limitation field disclosing that the verdict is occurrence evidence, not an absence/completeness claim — check it before treating an irreversible-class verdict as sufficient on its own. The proof also carries an opaque engine_generation counter (informational, not bound into decision_ref) — compare it across two proofs to detect a backend/judgment-engine change between calls without us disclosing which model we run."New value: +"Return a PORTABLE SIGNED proof of this verdict (binds verdict + artifact hash + our pubkey), including a content-addressed decision_ref = sha256(JCS({artifact_hash, artifact_type, policy_version, verdict, source_class})). Attach it to your output so a downstream agent can confirm via verify_proof — WITHOUT trusting you or us — that invinoveritas issued this verdict for this exact artifact. The agent-to-agent trust handshake. For artifact_type=trade|onchain_action|sanctions_screening, the proof also carries source_class ('agent_reported' today — no mediation-point integration exists yet) and, when applicable, a vantage_limitation field disclosing that the verdict is occurrence evidence, not an absence/completeness claim — check it before treating an irreversible-class verdict as sufficient on its own."
  16. Changed1 schema field changed
    • changedInput schema / properties / sign / description
      Previous value: -"Return a PORTABLE SIGNED proof of this verdict (binds verdict + artifact hash + our pubkey), including a content-addressed decision_ref = sha256(JCS({artifact_hash, artifact_type, policy_version, verdict, source_class})). Attach it to your output so a downstream agent can confirm via verify_proof — WITHOUT trusting you or us — that invinoveritas issued this verdict for this exact artifact. The agent-to-agent trust handshake. For artifact_type=trade|onchain_action|sanctions_screening, the proof also carries source_class ('agent_reported' today — no mediation-point integration exists yet) and, when applicable, a vantage_limitation field disclosing that the verdict is occurrence evidence, not an absence/completeness claim — check it before treating an irreversible-class verdict as sufficient on its own."New value: +"Return a PORTABLE SIGNED proof of this verdict (binds verdict + artifact hash + our pubkey), including a content-addressed decision_ref = sha256(JCS({artifact_hash, artifact_type, policy_version, verdict, source_class})). Attach it to your output so a downstream agent can confirm via verify_proof — WITHOUT trusting you or us — that invinoveritas issued this verdict for this exact artifact. The agent-to-agent trust handshake. For artifact_type=trade|onchain_action|sanctions_screening, the proof also carries source_class ('agent_reported' today — no mediation-point integration exists yet) and, when applicable, a vantage_limitation field disclosing that the verdict is occurrence evidence, not an absence/completeness claim — check it before treating an irreversible-class verdict as sufficient on its own. The proof also carries an opaque engine_generation counter (informational, not bound into decision_ref) — compare it across two proofs to detect a backend/judgment-engine change between calls without us disclosing which model we run."
  17. Changed1 schema field changed
    • changedInput schema / properties / sign / description
      Previous value: -"Return a PORTABLE SIGNED proof of this verdict (binds verdict + artifact hash + our pubkey), including a content-addressed decision_ref = sha256(JCS({artifact_hash, artifact_type, policy_version, verdict, source_class})). Attach it to your output so a downstream agent can confirm via verify_proof — WITHOUT trusting you or us — that invinoveritas issued this verdict for this exact artifact. The agent-to-agent trust handshake. For artifact_type=trade|onchain_action|sanctions_screening, the proof also carries source_class ('agent_reported' today — no mediation-point integration exists yet) and, when applicable, a vantage_limitation field disclosing that the verdict is occurrence evidence, not an absence/completeness claim — check it before treating an irreversible-class verdict as sufficient on its own. The proof also carries an opaque engine_generation counter (informational, not bound into decision_ref) — compare it across two proofs to detect a backend/judgment-engine change between calls without us disclosing which model we run."New value: +"Return a PORTABLE SIGNED proof of this verdict (binds verdict + artifact hash + our pubkey), including a content-addressed decision_ref = sha256(JCS({artifact_hash, artifact_type, policy_version, verdict, source_class})). Attach it to your output so a downstream agent can confirm via verify_proof — WITHOUT trusting you or us — that invinoveritas issued this verdict for this exact artifact. The agent-to-agent trust handshake. For artifact_type=trade|onchain_action|sanctions_screening, the proof also carries source_class ('agent_reported' today — no mediation-point integration exists yet) and, when applicable, a vantage_limitation field disclosing that the verdict is occurrence evidence, not an absence/completeness claim — check it before treating an irreversible-class verdict as sufficient on its own."
  18. Changed1 schema field changed
    • changedInput schema / properties / sign / description
      Previous value: -"Return a PORTABLE SIGNED proof of this verdict (binds verdict + artifact hash + our pubkey), including a content-addressed decision_ref = sha256(JCS({artifact_hash, artifact_type, policy_version, verdict, source_class})). Attach it to your output so a downstream agent can confirm via verify_proof — WITHOUT trusting you or us — that invinoveritas issued this verdict for this exact artifact. The agent-to-agent trust handshake. For artifact_type=trade|onchain_action|sanctions_screening, the proof also carries source_class ('agent_reported' today — no mediation-point integration exists yet) and, when applicable, a vantage_limitation field disclosing that the verdict is occurrence evidence, not an absence/completeness claim — check it before treating an irreversible-class verdict as sufficient on its own."New value: +"Return a PORTABLE SIGNED proof of this verdict (binds verdict + artifact hash + our pubkey), including a content-addressed decision_ref = sha256(JCS({artifact_hash, artifact_type, policy_version, verdict, source_class})). Attach it to your output so a downstream agent can confirm via verify_proof — WITHOUT trusting you or us — that invinoveritas issued this verdict for this exact artifact. The agent-to-agent trust handshake. For artifact_type=trade|onchain_action|sanctions_screening, the proof also carries source_class ('agent_reported' today — no mediation-point integration exists yet) and, when applicable, a vantage_limitation field disclosing that the verdict is occurrence evidence, not an absence/completeness claim — check it before treating an irreversible-class verdict as sufficient on its own. The proof also carries an opaque engine_generation counter (informational, not bound into decision_ref) — compare it across two proofs to detect a backend/judgment-engine change between calls without us disclosing which model we run."
  19. Changed3 schema fields changed
    • changedInput schema / properties / artifact_type / description
      Previous value: -"Type of artifact. 'code_diff' or 'patch' triggers deep code review. 'plan' for architecture/strategy. 'trade' triggers the capital-scale-aware risk-manager review of a proposed entry/exit. 'onchain_action' triggers the on-chain risk review of a proposed transfer/swap/approval/contract call (e.g. a Base MCP action) BEFORE you sign it — catches scam/honeypot tokens, unlimited-allowance drainers, address poisoning, slippage/MEV. Tailors focus and suggestions."New value: +"Type of artifact. 'code_diff' or 'patch' triggers deep code review. 'plan' for architecture/strategy. 'trade' triggers the capital-scale-aware risk-manager review of a proposed entry/exit. 'onchain_action' triggers the on-chain risk review of a proposed transfer/swap/approval/contract call (e.g. a Base MCP action) BEFORE you sign it — catches scam/honeypot tokens, unlimited-allowance drainers, address poisoning, slippage/MEV. 'sanctions_screening' for a compliance/AML result BEFORE acting on it — checks a categorical verdict (e.g. CLEAN) carries its own scope, not an unscoped claim. Tailors focus and suggestions. IMPORTANT for trade/onchain_action/sanctions_screening: a REJECT can happen purely from low confidence on an action you can't undo, even if content-wise the review leaned approve — see the response's reversibility_gate field."
    • changedInput schema / properties / artifact_type / enum
      Previous value: -[
      -  "code_diff",
      -  "patch",
      -  "shell_command",
      -  "plan",
      -  "config_change",
      -  "analysis",
      -  "agent_output",
      -  "trade",
      -  "onchain_action",
      -  "general"
      -]New value: +[
      +  "code_diff",
      +  "patch",
      +  "shell_command",
      +  "plan",
      +  "config_change",
      +  "analysis",
      +  "agent_output",
      +  "trade",
      +  "onchain_action",
      +  "sanctions_screening",
      +  "general"
      +]
    • changedInput schema / properties / sign / description
      Previous value: -"Return a PORTABLE SIGNED proof of this verdict (binds verdict + artifact hash + our pubkey). Attach it to your output so a downstream agent can confirm via verify_proof — WITHOUT trusting you or us — that invinoveritas issued this verdict for this exact artifact. The agent-to-agent trust handshake."New value: +"Return a PORTABLE SIGNED proof of this verdict (binds verdict + artifact hash + our pubkey), including a content-addressed decision_ref = sha256(JCS({artifact_hash, artifact_type, policy_version, verdict, source_class})). Attach it to your output so a downstream agent can confirm via verify_proof — WITHOUT trusting you or us — that invinoveritas issued this verdict for this exact artifact. The agent-to-agent trust handshake. For artifact_type=trade|onchain_action|sanctions_screening, the proof also carries source_class ('agent_reported' today — no mediation-point integration exists yet) and, when applicable, a vantage_limitation field disclosing that the verdict is occurrence evidence, not an absence/completeness claim — check it before treating an irreversible-class verdict as sufficient on its own."
  20. Changed2 schema fields changed
    • changedInput schema / properties / artifact_type / description
      Previous value: -"Type of artifact. 'code_diff' or 'patch' triggers deep code review. 'plan' for architecture/strategy. 'trade' triggers the capital-scale-aware risk-manager review of a proposed entry/exit. Tailors focus and suggestions."New value: +"Type of artifact. 'code_diff' or 'patch' triggers deep code review. 'plan' for architecture/strategy. 'trade' triggers the capital-scale-aware risk-manager review of a proposed entry/exit. 'onchain_action' triggers the on-chain risk review of a proposed transfer/swap/approval/contract call (e.g. a Base MCP action) BEFORE you sign it — catches scam/honeypot tokens, unlimited-allowance drainers, address poisoning, slippage/MEV. Tailors focus and suggestions."
    • changedInput schema / properties / artifact_type / enum
      Previous value: -[
      -  "code_diff",
      -  "patch",
      -  "shell_command",
      -  "plan",
      -  "config_change",
      -  "analysis",
      -  "agent_output",
      -  "trade",
      -  "general"
      -]New value: +[
      +  "code_diff",
      +  "patch",
      +  "shell_command",
      +  "plan",
      +  "config_change",
      +  "analysis",
      +  "agent_output",
      +  "trade",
      +  "onchain_action",
      +  "general"
      +]
  21. Changed1 schema field changed
    • addedInput schema / properties / sign
      Added value: +{
      +  "default": false,
      +  "description": "Return a PORTABLE SIGNED proof of this verdict (binds verdict + artifact hash + our pubkey). Attach it to your output so a downstream agent can confirm via verify_proof — WITHOUT trusting you or us — that invinoveritas issued this verdict for this exact artifact. The agent-to-agent trust handshake.",
      +  "type": "boolean"
      +}
  22. Changed2 schema fields changed
    • changedInput schema / properties / artifact_type / description
      Previous value: -"Type of artifact. 'code_diff' or 'patch' triggers deep code review. 'plan' for architecture/strategy. Tailors focus and suggestions."New value: +"Type of artifact. 'code_diff' or 'patch' triggers deep code review. 'plan' for architecture/strategy. 'trade' triggers the capital-scale-aware risk-manager review of a proposed entry/exit. Tailors focus and suggestions."
    • changedInput schema / properties / artifact_type / enum
      Previous value: -[
      -  "code_diff",
      -  "patch",
      -  "shell_command",
      -  "plan",
      -  "config_change",
      -  "analysis",
      -  "agent_output",
      -  "general"
      -]New value: +[
      +  "code_diff",
      +  "patch",
      +  "shell_command",
      +  "plan",
      +  "config_change",
      +  "analysis",
      +  "agent_output",
      +  "trade",
      +  "general"
      +]
  23. Changed1 schema field changed
    • removedInput schema / properties / return_suggestions
      Removed value: -{
      -  "default": true,
      -  "description": "Include concrete suggested fixes or alternative approaches (recommended for Grok Build / coding workflows)",
      -  "type": "boolean"
      -}
  24. Changed8 schema fields changed
    • changedInput schema / properties / artifact / description
      Previous value: -"The thing to review (diff, command, plan, config, analysis, output)"New value: +"The artifact to review: unified diff / patch, shell command, plan, config, analysis, agent output, or raw text"
    • changedInput schema / properties / artifact_type / description
      Previous value: -"What kind of artifact this is. Tailors review focus."New value: +"Type of artifact. 'code_diff' or 'patch' triggers deep code review. 'plan' for architecture/strategy. Tailors focus and suggestions."
    • changedInput schema / properties / artifact_type / enum
      Previous value: -[
      -  "code_diff",
      -  "shell_command",
      -  "plan",
      -  "config_change",
      -  "analysis",
      -  "agent_output",
      -  "general"
      -]New value: +[
      +  "code_diff",
      +  "patch",
      +  "shell_command",
      +  "plan",
      +  "config_change",
      +  "analysis",
      +  "agent_output",
      +  "general"
      +]
    • changedInput schema / properties / concerns / description
      Previous value: -"Optional: specific things you want checked (e.g., 'is this safe on production', 'any edge cases')"New value: +"Specific things to check (e.g. 'production safety', 'edge cases in trading logic', 'regulatory risk')"
    • changedInput schema / properties / context / description
      Previous value: -"Optional: what this is trying to accomplish, why now, what success looks like"New value: +"What you are trying to accomplish, why now, success criteria"
    • changedInput schema / properties / include_trading_state / description
      Previous value: -"Sentinel mode: auto-inject current Sovereign Earner state (equity, regime, open position, PnL, pause status) into review context. Use for trading-related diffs/configs/directives. Opt-in."New value: +"Sentinel mode: inject live Sovereign Earner state (equity, regime, open position, PnL) for trading-related reviews. Highly recommended for any trading or risk decision."
    • addedInput schema / properties / return_suggestions
      Added value: +{
      +  "default": true,
      +  "description": "Include concrete suggested fixes or alternative approaches (recommended for Grok Build / coding workflows)",
      +  "type": "boolean"
      +}
    • changedInput schema / properties / severity_threshold / description
      Previous value: -"Lowest severity to surface in issues list"New value: +"Minimum severity to report"
  25. Changed1 schema field changed
    • addedInput schema / properties / include_trading_state
      Added value: +{
      +  "default": false,
      +  "description": "Sentinel mode: auto-inject current Sovereign Earner state (equity, regime, open position, PnL, pause status) into review context. Use for trading-related diffs/configs/directives. Opt-in.",
      +  "type": "boolean"
      +}
  26. Added

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations only declare the safe-read profile (readOnlyHint=true, destructiveHint=false). The description adds substantial context beyond that: the verdict vocabulary (approve/approve_with_concerns/reject) with confidence score and severity-ranked issues, the meaning of sign=true and the signed-proof guarantee, the reversibility_gate / epistemic_basis response semantics, and the explicit caveat that the verdict is a reasoned second opinion, not a guarantee.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loads the core purpose in the first clause, then layers return shape, signing behavior, and caveats. Every sentence contributes (return contract, proof linkage, disclaimers). Slightly dense but appropriate for a tool with this much behavioral surface.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 17-parameter tool with nested objects and no output schema, the description supplies the missing response vocabulary (approve/reject/confidence/severity/fixes) and the sign→verify_proof relationship, plus honest limits. It gives an agent enough to call it and interpret the result correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the schema carries the per-parameter burden (baseline 3). The description modestly adds value by tying sign=true to verify_proof and illustrating usage. Since structured fields already document all 17 params thoroughly, the description does not need to compensate further, and it introduces no conflicting semantics.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource ('Independent verdict on a proposed action before it is taken') and enumerates exactly what can be reviewed — diff, shell command, deployment plan, config change, agent output, transaction. This clearly distinguishes it from siblings like verify_proof (used after the fact) and ledger/witness.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives clear timing context ('before it is taken') and routes to the alternative for the after-the-fact case ('check later with verify_proof'). It also encodes per-artifact_type usage conditions (e.g. onchain_action 'BEFORE you sign it'). No explicit when-not-to-use exclusions, but the routing guidance is strong.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.