MCP 서버

DCL Trust Oracle — AI/LLM Output Audit (x402 MCP)

com.fronesislabs/dcl-trust-oracle
AI 및 에이전트 암호화폐 및 Web3 보안 공개 · 연결 가능 MCP 2025-11-25

이 MCP로 할 수 있는 일

Audits AI and agent outputs for jailbreaks, secrets, PII, unsafe trading language, and quality issues, and records cryptographically linked audit receipts.

dcl_audit_decode
Basic Audit Decode
POST-ACTION Basic Audit ($0.10). Retrieves a record from the tamper-evident chain by tx_hash.
읽기 전용 멱등성
입력 스키마
{'type': 'object', 'title': 'dcl_audit_decodeArguments', 'required': ['tx_hash'], 'properties': {'tx_hash': {'type': 'string', 'title': 'Tx Hash', 'description': 'Transaction hash of the audit chain record to retrieve.'}}}
출력 스키마
{'type': 'object', 'title': 'AuditResult', 'properties': {'error': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Error', 'default': None, 'description': 'Set if tx_hash was not found; other fields are omitted.'}, 'reason': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Reason', 'default': None, 'description': 'Explanation recorded for the verdict.'}, 'tx_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Tx Hash', 'default': None, 'description': 'Hash of the audit chain record.'}, 'verdict': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Verdict', 'default': None, 'description': 'COMMIT or NO_COMMIT.'}, 'agent_id': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Agent Id', 'default': None, 'description': 'Identifier of the agent tied to this record.'}, 'prev_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Prev Hash', 'default': None, 'description': 'Hash of the preceding record in the chain.'}, 'seal_text': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Seal Text', 'default': None, 'description': 'Human-readable Leibniz Layer verification seal.'}, 'task_type': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Task Type', 'default': None, 'description': 'Task type tag recorded with this entry.'}, 'timestamp': {'anyOf': [{'type': 'number'}, {'type': 'null'}], 'title': 'Timestamp', 'default': None, 'description': 'Unix timestamp when the record was created.'}, 'confidence': {'anyOf': [{'type': 'number'}, {'type': 'null'}], 'title': 'Confidence', 'default': None, 'description': 'Confidence score recorded for the verdict.'}, 'verify_url': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Verify Url', 'default': None, 'description': 'Public URL to independently verify this seal.'}, 'chain_index': {'anyOf': [{'type': 'integer'}, {'type': 'null'}], 'title': 'Chain Index', 'default': None, 'description': 'Sequential index of the record in the chain.'}, 'chain_integrity': {'anyOf': [{'type': 'boolean'}, {'type': 'null'}], 'title': 'Chain Integrity', 'default': None, 'description': 'True if the full chain verifies as intact.'}}}
dcl_audit_decode_deep
Deep Forensic Audit Decode
POST-ACTION Deep Forensic Audit ($0.50). Extended output with drift_context and full chain integrity verification.
읽기 전용 멱등성
입력 스키마
{'type': 'object', 'title': 'dcl_audit_decode_deepArguments', 'required': ['tx_hash'], 'properties': {'tx_hash': {'type': 'string', 'title': 'Tx Hash', 'description': 'Transaction hash of the audit chain record to retrieve.'}}}
출력 스키마
{'type': 'object', 'title': 'AuditDeepResult', 'properties': {'error': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Error', 'default': None, 'description': 'Set if tx_hash was not found; other fields are omitted.'}, 'reason': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Reason', 'default': None, 'description': 'Explanation recorded for the verdict.'}, 'tx_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Tx Hash', 'default': None, 'description': 'Hash of the audit chain record.'}, 'verdict': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Verdict', 'default': None, 'description': 'COMMIT or NO_COMMIT.'}, 'agent_id': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Agent Id', 'default': None, 'description': 'Identifier of the agent tied to this record.'}, 'prev_hash': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Prev Hash', 'default': None, 'description': 'Hash of the preceding record in the chain.'}, 'seal_text': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Seal Text', 'default': None, 'description': 'Human-readable Leibniz Layer verification seal.'}, 'task_type': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Task Type', 'default': None, 'description': 'Task type tag recorded with this entry.'}, 'timestamp': {'anyOf': [{'type': 'number'}, {'type': 'null'}], 'title': 'Timestamp', 'default': None, 'description': 'Unix timestamp when the record was created.'}, 'confidence': {'anyOf': [{'type': 'number'}, {'type': 'null'}], 'title': 'Confidence', 'default': None, 'description': 'Confidence score recorded for the verdict.'}, 'verify_url': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Verify Url', 'default': None, 'description': 'Public URL to independently verify this seal.'}, 'chain_index': {'anyOf': [{'type': 'integer'}, {'type': 'null'}], 'title': 'Chain Index', 'default': None, 'description': 'Sequential index of the record in the chain.'}, 'drift_context': {'anyOf': [{'type': 'object', 'additionalProperties': True}, {'type': 'null'}], 'title': 'Drift Context', 'default': None, 'description': 'Extended forensic metadata captured at evaluation time.'}, 'tamper_reason': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Tamper Reason', 'default': None, 'description': 'Why chain_integrity is False â\x80\x94 a broken prev_hash link or an edited row whose stored tx_hash no longer matches its recomputed content hash.'}, 'chain_integrity': {'anyOf': [{'type': 'boolean'}, {'type': 'null'}], 'title': 'Chain Integrity', 'default': None, 'description': 'True if the full chain verifies as intact.'}, 'tampered_at_index': {'anyOf': [{'type': 'integer'}, {'type': 'null'}], 'title': 'Tampered At Index', 'default': None, 'description': 'Index where chain integrity broke, if any tampering was detected.'}}}
dcl_commit
Leibniz Layer Crypto Commit
FINAL-STEP Leibniz Layer Crypto Commit ($0.01). Writes a trading/agent decision to the append-only Leibniz Layer audit chain and returns a Merkle-proof-style receipt: `tx_hash` (proof of this specific commit), `chain_hash` (the previous commit's hash, linking this one into the chain), and `chain_depth` (this commit's position in the chain). Unlike the evaluate_* tools, this call has no pass/fail verdict of its own — it always succeeds and simply seals the decision. Passing `prior_checks` is optional but recommended: it records which earlier pipeline steps (firewall/wallet/trade/MEV) this specific commit is downstream of, in one auditable record. Always run this LAST, after every other crypto-suite check has passed.
입력 스키마
{'type': 'object', 'title': 'dcl_commitArguments', 'required': ['decision', 'agent_id'], 'properties': {'agent_id': {'type': 'string', 'title': 'Agent Id', 'description': 'Identifier of the agent whose decision is being committed.'}, 'decision': {'type': 'string', 'title': 'Decision', 'description': 'The final trading/agent decision text to commit to the audit chain.'}, 'prior_checks': {'anyOf': [{'type': 'object', 'additionalProperties': True}, {'type': 'null'}], 'title': 'Prior Checks', 'default': None, 'description': "Optional dict of tx_hashes from earlier pipeline steps (e.g. {'prompt_firewall_tx_hash': ..., 'trade_verifier_tx_hash': ..., 'mev_compliance_tx_hash': ...}), linking this commit to the specific checks that passed before it."}}}
출력 스키마
{'type': 'object', 'title': 'CommitResult', 'required': ['tx_hash', 'chain_hash', 'chain_depth', 'input_hash', 'timestamp'], 'properties': {'tx_hash': {'type': 'string', 'title': 'Tx Hash', 'description': 'Tamper-evident proof of this specific commit.'}, 'timestamp': {'type': 'number', 'title': 'Timestamp', 'description': 'Unix timestamp when this record was sealed.'}, 'chain_hash': {'type': 'string', 'title': 'Chain Hash', 'description': 'Hash of the previous commit in the append-only chain that this one links to.'}, 'input_hash': {'type': 'string', 'title': 'Input Hash', 'description': 'Hash of the committed decision text (raw content is never stored).'}, 'chain_depth': {'type': 'integer', 'title': 'Chain Depth', 'description': "This commit's position (index) in the chain."}}}
dcl_evaluate_batch
Batch Evaluation
PRE-ACTION Bulk Processing ($0.10). Evaluates a list of items in one call; each item is a dict shaped {"response": str, "policy"?: str}, where policy defaults to "default" if omitted and may be any built-in policy name (default, strict, anti_jailbreak, safety, content_quality). Each item gets its own independent COMMIT/NO_COMMIT verdict via the same logic as the matching single-item evaluate_* tool; results are returned in input order under `results`, plus a shared `batch_id`. Capped at 200 items per call — oversized batches are rejected. Use this instead of multiple single-item evaluate_* calls when checking several responses — optionally against different policies — in one priced call rather than paying per item separately.
입력 스키마
{'type': 'object', 'title': 'dcl_evaluate_batchArguments', 'required': ['items', 'agent_id'], 'properties': {'items': {'type': 'array', 'items': {'type': 'object', 'additionalProperties': True}, 'title': 'Items', 'description': "List of items to evaluate, each shaped like {'response': str, 'policy'?: str}."}, 'agent_id': {'type': 'string', 'title': 'Agent Id', 'description': 'Identifier of the agent that produced the responses.'}}}
출력 스키마
{'type': 'object', '$defs': {'EvaluateResult': {'type': 'object', 'title': 'EvaluateResult', 'required': ['verdict', 'confidence', 'reason', 'tx_hash', 'chain_index', 'input_hash', 'policy_version', 'drift_mode', 'drift_score', 'timestamp', 'seal_text', 'verify_url'], 'properties': {'reason': {'type': 'string', 'title': 'Reason', 'description': 'Human-readable explanation of why the verdict was reached.'}, 'tx_hash': {'type': 'string', 'title': 'Tx Hash', 'description': 'Hash of this record in the tamper-evident audit chain.'}, 'verdict': {'type': 'string', 'title': 'Verdict', 'description': 'COMMIT if the response passed policy checks, otherwise NO_COMMIT.'}, 'seal_text': {'type': 'string', 'title': 'Seal Text', 'description': 'Human-readable Leibniz Layer verification seal.'}, 'timestamp': {'type': 'number', 'title': 'Timestamp', 'description': 'Unix timestamp when this record was sealed.'}, 'confidence': {'type': 'number', 'title': 'Confidence', 'description': 'Confidence score of the verdict, from 0.0 to 1.0.'}, 'drift_mode': {'type': 'string', 'title': 'Drift Mode', 'description': 'Current drift status: NORMAL, WARNING, ESCALATION, or BLOCK.'}, 'input_hash': {'type': 'string', 'title': 'Input Hash', 'description': 'Hash of the evaluated response (raw content is never stored).'}, 'verify_url': {'type': 'string', 'title': 'Verify Url', 'description': 'Public URL to independently verify this seal.'}, 'chain_index': {'type': 'integer', 'title': 'Chain Index', 'description': 'Sequential index of this record in the audit chain.'}, 'drift_score': {'type': 'number', 'title': 'Drift Score', 'description': 'Z-score measuring deviation of the recent commit rate from baseline.'}, 'policy_version': {'type': 'string', 'title': 'Policy Version', 'description': 'Version of the policy that was applied.'}}}}, 'title': 'BatchResult', 'required': ['batch_id', 'agent_id', 'count', 'results'], 'properties': {'count': {'type': 'integer', 'title': 'Count', 'description': 'Number of items evaluated in this batch.'}, 'results': {'type': 'array', 'items': {'$ref': '#/$defs/EvaluateResult'}, 'title': 'Results', 'description': 'Per-item evaluation results, in input order.'}, 'agent_id': {'type': 'string', 'title': 'Agent Id', 'description': 'Identifier of the agent whose responses were evaluated.'}, 'batch_id': {'type': 'string', 'title': 'Batch Id', 'description': 'Unique identifier for this batch run.'}}}
dcl_evaluate_fast
Fast Pre-Action Audit
FAST Pre-Action Audit ($0.01). Runs the response through the server's "default" policy: a substring check against 3 forbidden phrases ("ignore previous instructions", "jailbreak", "bypass safety") with a 0.7 minimum-confidence threshold. Each forbidden match found costs 0.4 confidence; if confidence falls below 0.7, or any match is found, the verdict is NO_COMMIT and `reason` lists which phrase triggered it. Otherwise COMMIT. Use this as the default low-cost first-pass gate before a risky agent action; switch to dcl_evaluate_strict for a broader, higher-bar check, or to dcl_evaluate_jailbreak / dcl_evaluate_safety / dcl_evaluate_quality for a narrower, single-topic check instead of the general-purpose default policy.
입력 스키마
{'type': 'object', 'title': 'dcl_evaluate_fastArguments', 'required': ['response', 'agent_id'], 'properties': {'agent_id': {'type': 'string', 'title': 'Agent Id', 'description': 'Identifier of the agent that produced the response.'}, 'response': {'type': 'string', 'title': 'Response', 'description': 'The agent or LLM response text to audit.'}}}
출력 스키마
{'type': 'object', 'title': 'EvaluateResult', 'required': ['verdict', 'confidence', 'reason', 'tx_hash', 'chain_index', 'input_hash', 'policy_version', 'drift_mode', 'drift_score', 'timestamp', 'seal_text', 'verify_url'], 'properties': {'reason': {'type': 'string', 'title': 'Reason', 'description': 'Human-readable explanation of why the verdict was reached.'}, 'tx_hash': {'type': 'string', 'title': 'Tx Hash', 'description': 'Hash of this record in the tamper-evident audit chain.'}, 'verdict': {'type': 'string', 'title': 'Verdict', 'description': 'COMMIT if the response passed policy checks, otherwise NO_COMMIT.'}, 'seal_text': {'type': 'string', 'title': 'Seal Text', 'description': 'Human-readable Leibniz Layer verification seal.'}, 'timestamp': {'type': 'number', 'title': 'Timestamp', 'description': 'Unix timestamp when this record was sealed.'}, 'confidence': {'type': 'number', 'title': 'Confidence', 'description': 'Confidence score of the verdict, from 0.0 to 1.0.'}, 'drift_mode': {'type': 'string', 'title': 'Drift Mode', 'description': 'Current drift status: NORMAL, WARNING, ESCALATION, or BLOCK.'}, 'input_hash': {'type': 'string', 'title': 'Input Hash', 'description': 'Hash of the evaluated response (raw content is never stored).'}, 'verify_url': {'type': 'string', 'title': 'Verify Url', 'description': 'Public URL to independently verify this seal.'}, 'chain_index': {'type': 'integer', 'title': 'Chain Index', 'description': 'Sequential index of this record in the audit chain.'}, 'drift_score': {'type': 'number', 'title': 'Drift Score', 'description': 'Z-score measuring deviation of the recent commit rate from baseline.'}, 'policy_version': {'type': 'string', 'title': 'Policy Version', 'description': 'Version of the policy that was applied.'}}}
dcl_evaluate_jailbreak
Jailbreak Detection Check
PRE-ACTION Instruction Adherence Check ($0.02). Runs the "anti_jailbreak" policy: a substring check against 6 forbidden phrases ("ignore previous instructions", "jailbreak", "bypass safety", "pretend you are", "act as if", "DAN") with a 0.8 minimum-confidence threshold — each match costs 0.4 confidence. Returns COMMIT if no phrase matches and confidence stays at or above 0.8, otherwise NO_COMMIT with `reason` listing the matched phrase(s). Use this as a targeted, cheaper check when the concern is specifically prompt-injection / persona-hijack risk; use dcl_evaluate_strict instead when you also want safety- and default-policy phrases covered in the same call.
입력 스키마
{'type': 'object', 'title': 'dcl_evaluate_jailbreakArguments', 'required': ['response', 'agent_id'], 'properties': {'agent_id': {'type': 'string', 'title': 'Agent Id', 'description': 'Identifier of the agent that produced the response.'}, 'response': {'type': 'string', 'title': 'Response', 'description': 'The agent or LLM response text to check for jailbreak attempts.'}}}
출력 스키마
{'type': 'object', 'title': 'EvaluateResult', 'required': ['verdict', 'confidence', 'reason', 'tx_hash', 'chain_index', 'input_hash', 'policy_version', 'drift_mode', 'drift_score', 'timestamp', 'seal_text', 'verify_url'], 'properties': {'reason': {'type': 'string', 'title': 'Reason', 'description': 'Human-readable explanation of why the verdict was reached.'}, 'tx_hash': {'type': 'string', 'title': 'Tx Hash', 'description': 'Hash of this record in the tamper-evident audit chain.'}, 'verdict': {'type': 'string', 'title': 'Verdict', 'description': 'COMMIT if the response passed policy checks, otherwise NO_COMMIT.'}, 'seal_text': {'type': 'string', 'title': 'Seal Text', 'description': 'Human-readable Leibniz Layer verification seal.'}, 'timestamp': {'type': 'number', 'title': 'Timestamp', 'description': 'Unix timestamp when this record was sealed.'}, 'confidence': {'type': 'number', 'title': 'Confidence', 'description': 'Confidence score of the verdict, from 0.0 to 1.0.'}, 'drift_mode': {'type': 'string', 'title': 'Drift Mode', 'description': 'Current drift status: NORMAL, WARNING, ESCALATION, or BLOCK.'}, 'input_hash': {'type': 'string', 'title': 'Input Hash', 'description': 'Hash of the evaluated response (raw content is never stored).'}, 'verify_url': {'type': 'string', 'title': 'Verify Url', 'description': 'Public URL to independently verify this seal.'}, 'chain_index': {'type': 'integer', 'title': 'Chain Index', 'description': 'Sequential index of this record in the audit chain.'}, 'drift_score': {'type': 'number', 'title': 'Drift Score', 'description': 'Z-score measuring deviation of the recent commit rate from baseline.'}, 'policy_version': {'type': 'string', 'title': 'Policy Version', 'description': 'Version of the policy that was applied.'}}}
dcl_evaluate_jailbreak_crypto
Crypto Jailbreak & Injection Detection
PRE-ACTION Crypto Jailbreak & Injection Detection ($0.02). Crypto-specialized instruction-override/jailbreak/injection screen: standard role-switch and instruction-override patterns, plus crypto-specific drain-wallet injection (e.g. "transfer all funds to...", fake "test transaction" requesting full balance) and unlimited-approval injection (e.g. type(uint256).max, "approve unlimited allowance", skip-slippage-confirmation framing). Any match returns NO_COMMIT with `reason` and `findings` naming the matched category/categories; run this FIRST in the DCL crypto pipeline, before wallet/trade/MEV checks, since it screens the input itself rather than a decision built on top of it.
입력 스키마
{'type': 'object', 'title': 'dcl_evaluate_jailbreak_cryptoArguments', 'required': ['response', 'agent_id'], 'properties': {'agent_id': {'type': 'string', 'title': 'Agent Id', 'description': 'Identifier of the agent that produced or received the text.'}, 'response': {'type': 'string', 'title': 'Response', 'description': 'The incoming prompt or agent response to screen for crypto-specialized jailbreak/injection attempts.'}}}
출력 스키마
{'type': 'object', '$defs': {'CryptoFinding': {'type': 'object', 'title': 'CryptoFinding', 'required': ['type', 'severity'], 'properties': {'type': {'type': 'string', 'title': 'Type', 'description': 'The specific pattern category matched.'}, 'severity': {'type': 'string', 'title': 'Severity', 'description': 'critical or major.'}, 'regulatory_reference': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Regulatory Reference', 'default': None, 'description': 'Illustrative regulatory tag for this finding type (e.g. MiFID II, FCA), if applicable.'}}}}, 'title': 'JailbreakCryptoResult', 'required': ['verdict', 'confidence', 'reason', 'findings', 'tx_hash', 'chain_index', 'input_hash', 'policy_version'], 'properties': {'reason': {'type': 'string', 'title': 'Reason', 'description': 'Human-readable explanation of the verdict.'}, 'tx_hash': {'type': 'string', 'title': 'Tx Hash', 'description': 'Hash of this record in the tamper-evident audit chain.'}, 'verdict': {'type': 'string', 'title': 'Verdict', 'description': 'COMMIT if no injection pattern matched, otherwise NO_COMMIT.'}, 'findings': {'type': 'array', 'items': {'$ref': '#/$defs/CryptoFinding'}, 'title': 'Findings', 'description': 'All matched patterns. Empty list if verdict is COMMIT.'}, 'confidence': {'type': 'number', 'title': 'Confidence', 'description': 'Confidence score of the verdict, from 0.0 to 1.0.'}, 'input_hash': {'type': 'string', 'title': 'Input Hash', 'description': 'Hash of the screened text (raw content is never stored).'}, 'chain_index': {'type': 'integer', 'title': 'Chain Index', 'description': 'Sequential index of this record in the audit chain.'}, 'policy_version': {'type': 'string', 'title': 'Policy Version', 'description': 'Version of the crypto jailbreak policy that was applied.'}}}
dcl_evaluate_mev
MEV & Market-Abuse Compliance Screen
POST-ACTION MEV & Market-Abuse Compliance Screen ($0.03). Text-level screen (not a mempool/transaction analyzer) for front-running/sandwich-attack language, wash trading/layering/spoofing, KYC/AML red flags (mixers, structuring, obscuring fund origin), and pump-and-dump/rug-pull language. Any critical-severity finding, or two or more major-severity findings, returns NO_COMMIT; a single major-severity finding is also returned as NO_COMMIT but with a distinctly higher `confidence` (~0.55 vs ~0.05-0.2 for harder violations) so downstream callers can tell a soft single flag apart from a hard multi-finding block. Each finding includes an illustrative `regulatory_reference` tag (MiFID II, FCA, or an EU AI Act article).
입력 스키마
{'type': 'object', 'title': 'dcl_evaluate_mevArguments', 'required': ['response', 'agent_id'], 'properties': {'agent_id': {'type': 'string', 'title': 'Agent Id', 'description': 'Identifier of the agent that produced the response.'}, 'response': {'type': 'string', 'title': 'Response', 'description': 'The agent or LLM response text describing or proposing an on-chain/trading action, to screen for MEV and market-abuse language.'}}}
출력 스키마
{'type': 'object', '$defs': {'CryptoFinding': {'type': 'object', 'title': 'CryptoFinding', 'required': ['type', 'severity'], 'properties': {'type': {'type': 'string', 'title': 'Type', 'description': 'The specific pattern category matched.'}, 'severity': {'type': 'string', 'title': 'Severity', 'description': 'critical or major.'}, 'regulatory_reference': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Regulatory Reference', 'default': None, 'description': 'Illustrative regulatory tag for this finding type (e.g. MiFID II, FCA), if applicable.'}}}}, 'title': 'MevResult', 'required': ['verdict', 'confidence', 'findings', 'tx_hash', 'chain_index', 'input_hash', 'timestamp'], 'properties': {'tx_hash': {'type': 'string', 'title': 'Tx Hash', 'description': 'Hash of this record in the tamper-evident audit chain.'}, 'verdict': {'type': 'string', 'title': 'Verdict', 'description': 'COMMIT if the response passed the MEV/compliance screen, otherwise NO_COMMIT.'}, 'findings': {'type': 'array', 'items': {'$ref': '#/$defs/CryptoFinding'}, 'title': 'Findings', 'description': 'All matched patterns. Empty list if verdict is COMMIT.'}, 'timestamp': {'type': 'number', 'title': 'Timestamp', 'description': 'Unix timestamp when this record was sealed.'}, 'confidence': {'type': 'number', 'title': 'Confidence', 'description': 'Confidence score of the verdict, from 0.0 to 1.0.'}, 'input_hash': {'type': 'string', 'title': 'Input Hash', 'description': 'Hash of the screened text (raw content is never stored).'}, 'chain_index': {'type': 'integer', 'title': 'Chain Index', 'description': 'Sequential index of this record in the audit chain.'}}}
dcl_evaluate_output_sanitizer
Output Sanitizer — Final Gate
FINAL-GATE Output Sanitizer ($0.02). Post-processing checkpoint that strips secrets/credentials, PII, crypto material (seed phrases, private keys, wallet addresses), internal network details (private IPs, MAC addresses, .internal/.local/.corp hostnames), and unsafe shell/SQL/path-traversal fragments from a raw model response — plus a narrow, high-precision safety net for direct self-harm-instruction-seeking and targeted-harassment phrasing (not a general toxicity classifier). Returns a single `sanitized_output` with every match replaced by `[REDACTED]`; use that instead of the original whenever verdict is NO_COMMIT. Run this as the LAST gate before a response reaches its destination — after `dcl_evaluate_jailbreak_crypto`/other input-side checks have already run, and immediately before `dcl_commit` seals the final decision. Internally re-uses the same detection tables as `dcl_evaluate_secrets`/`dcl_evaluate_pii` for the secrets/PII categories, so results stay consistent with those tools.
입력 스키마
{'type': 'object', 'title': 'dcl_evaluate_output_sanitizerArguments', 'required': ['response', 'agent_id'], 'properties': {'agent_id': {'type': 'string', 'title': 'Agent Id', 'description': 'Identifier of the agent that produced the response.'}, 'response': {'type': 'string', 'title': 'Response', 'description': 'The raw LLM/agent response to sanitize before it is delivered to a user, downstream agent, or external system.'}}}
출력 스키마
{'type': 'object', '$defs': {'SanitizerFinding': {'type': 'object', 'title': 'SanitizerFinding', 'required': ['type', 'position', 'redacted_sample', 'severity', 'category'], 'properties': {'type': {'type': 'string', 'title': 'Type', 'description': 'e.g. api_key, email, seed_phrase, internal_ip, mac_address, internal_hostname, self_harm_instruction, targeted_harassment, shell_injection, sql_injection, path_traversal, and others.'}, 'category': {'type': 'string', 'title': 'Category', 'description': 'secrets, pii, crypto, network, toxic, or unsafe_instructions.'}, 'position': {'type': 'integer', 'title': 'Position', 'description': 'Character offset of the match in the submitted text.'}, 'severity': {'type': 'string', 'title': 'Severity', 'description': 'critical, major, or minor.'}, 'redacted_sample': {'type': 'string', 'title': 'Redacted Sample', 'description': 'Masked version of the match â\x80\x94 never the real value.'}}}}, 'title': 'OutputSanitizerResult', 'required': ['verdict', 'confidence', 'violations', 'findings', 'redaction_count', 'risk_score', 'tx_hash', 'chain_index', 'input_hash', 'timestamp'], 'properties': {'tx_hash': {'type': 'string', 'title': 'Tx Hash', 'description': 'Hash of this record in the tamper-evident audit chain.'}, 'verdict': {'type': 'string', 'title': 'Verdict', 'description': 'COMMIT if the response was clean, otherwise NO_COMMIT.'}, 'findings': {'type': 'array', 'items': {'$ref': '#/$defs/SanitizerFinding'}, 'title': 'Findings', 'description': 'All matches found, with position/severity/category detail. Empty list if verdict is COMMIT.'}, 'timestamp': {'type': 'number', 'title': 'Timestamp', 'description': 'Unix timestamp when this record was sealed.'}, 'confidence': {'type': 'number', 'title': 'Confidence', 'description': 'Confidence score of the verdict, from 0.0 to 1.0.'}, 'input_hash': {'type': 'string', 'title': 'Input Hash', 'description': 'Hash of the sanitized text (raw content is never stored).'}, 'risk_score': {'type': 'number', 'title': 'Risk Score', 'description': '0.0-1.0 composite severity score.'}, 'violations': {'type': 'array', 'items': {'type': 'string'}, 'title': 'Violations', 'description': "Distinct finding types matched (e.g. ['api_key', 'internal_ip']). Empty list if verdict is COMMIT."}, 'chain_index': {'type': 'integer', 'title': 'Chain Index', 'description': 'Sequential index of this record in the audit chain.'}, 'redaction_count': {'type': 'integer', 'title': 'Redaction Count', 'description': 'Total number of items redacted.'}, 'sanitized_output': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Sanitized Output', 'default': None, 'description': 'Input text with every match replaced by [REDACTED]. Null if verdict is COMMIT.'}}}
dcl_evaluate_pii
PII Detection Scan
POST-ACTION PII Detection Scan ($0.02). Regex-based scan across 8 personal-data categories, with a Luhn checksum on card numbers to reduce false positives. Any finding results in NO_COMMIT.
입력 스키마
{'type': 'object', 'title': 'dcl_evaluate_piiArguments', 'required': ['response', 'agent_id'], 'properties': {'agent_id': {'type': 'string', 'title': 'Agent Id', 'description': 'Identifier of the agent that produced the response.'}, 'response': {'type': 'string', 'title': 'Response', 'description': 'The text to scan for personal data: emails, phone numbers, national IDs, bank cards, IBANs, crypto addresses, IP addresses, passport numbers.'}}}
출력 스키마
{'type': 'object', '$defs': {'DetectionFinding': {'type': 'object', 'title': 'DetectionFinding', 'required': ['type', 'position', 'redacted_sample', 'severity', 'category'], 'properties': {'type': {'type': 'string', 'title': 'Type', 'description': "The specific pattern category matched (e.g. 'api_key', 'email')."}, 'category': {'type': 'string', 'title': 'Category', 'description': 'Checklist code, e.g. S1-S8 for secrets or T1-T8 for PII.'}, 'position': {'type': 'integer', 'title': 'Position', 'description': 'Character offset of the match in the submitted text.'}, 'provider': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Provider', 'default': None, 'description': 'Identified provider/service, if known.'}, 'severity': {'type': 'string', 'title': 'Severity', 'description': 'critical, major, or minor.'}, 'redacted_sample': {'type': 'string', 'title': 'Redacted Sample', 'description': 'Masked version of the match â\x80\x94 first 2 and last 4 chars only.'}}}}, 'title': 'ScanResult', 'required': ['verdict', 'risk_score', 'findings', 'detection_count', 'categories_checked', 'categories_clear', 'tx_hash', 'chain_index', 'input_hash', 'timestamp', 'seal_text', 'verify_url'], 'properties': {'tx_hash': {'type': 'string', 'title': 'Tx Hash', 'description': 'Hash of this record in the tamper-evident audit chain.'}, 'verdict': {'type': 'string', 'title': 'Verdict', 'description': 'COMMIT if nothing was found, otherwise NO_COMMIT.'}, 'findings': {'type': 'array', 'items': {'$ref': '#/$defs/DetectionFinding'}, 'title': 'Findings', 'description': 'All matches found. Empty list if verdict is COMMIT.'}, 'seal_text': {'type': 'string', 'title': 'Seal Text', 'description': 'Human-readable Leibniz Layer verification seal.'}, 'timestamp': {'type': 'number', 'title': 'Timestamp', 'description': 'Unix timestamp when this record was sealed.'}, 'input_hash': {'type': 'string', 'title': 'Input Hash', 'description': 'Hash of the scanned text (raw content is never stored).'}, 'risk_score': {'type': 'number', 'title': 'Risk Score', 'description': '0.0-1.0 risk score based on number and severity of findings.'}, 'verify_url': {'type': 'string', 'title': 'Verify Url', 'description': 'Public URL to independently verify this seal.'}, 'chain_index': {'type': 'integer', 'title': 'Chain Index', 'description': 'Sequential index of this record in the audit chain.'}, 'detection_count': {'type': 'integer', 'title': 'Detection Count', 'description': 'Number of findings.'}, 'categories_clear': {'type': 'array', 'items': {'type': 'string'}, 'title': 'Categories Clear', 'description': 'Categories with no findings.'}, 'categories_checked': {'type': 'array', 'items': {'type': 'string'}, 'title': 'Categories Checked', 'description': 'All checklist categories that were scanned.'}}}
dcl_evaluate_quality
Content Quality & Drift Check
PRE-ACTION Content Quality & Drift Check ($0.03). Runs the "content_quality" policy: flags 12 absolutist or unverifiable-claim phrases (e.g. "guaranteed returns", "100% accurate", "studies show", "without a doubt") with a 0.85 minimum-confidence threshold — the highest bar of any single-policy tool. Returns NO_COMMIT if any phrase matches or confidence falls below 0.85, with `reason` listing the matched phrase(s). Use this to catch overconfident or unsubstantiated claims in generated content — a different concern from jailbreak or safety phrasing — e.g. before publishing agent-written copy or reports.
입력 스키마
{'type': 'object', 'title': 'dcl_evaluate_qualityArguments', 'required': ['response', 'agent_id'], 'properties': {'agent_id': {'type': 'string', 'title': 'Agent Id', 'description': 'Identifier of the agent that produced the response.'}, 'response': {'type': 'string', 'title': 'Response', 'description': 'The agent or LLM response text to check for quality and drift.'}}}
출력 스키마
{'type': 'object', 'title': 'EvaluateResult', 'required': ['verdict', 'confidence', 'reason', 'tx_hash', 'chain_index', 'input_hash', 'policy_version', 'drift_mode', 'drift_score', 'timestamp', 'seal_text', 'verify_url'], 'properties': {'reason': {'type': 'string', 'title': 'Reason', 'description': 'Human-readable explanation of why the verdict was reached.'}, 'tx_hash': {'type': 'string', 'title': 'Tx Hash', 'description': 'Hash of this record in the tamper-evident audit chain.'}, 'verdict': {'type': 'string', 'title': 'Verdict', 'description': 'COMMIT if the response passed policy checks, otherwise NO_COMMIT.'}, 'seal_text': {'type': 'string', 'title': 'Seal Text', 'description': 'Human-readable Leibniz Layer verification seal.'}, 'timestamp': {'type': 'number', 'title': 'Timestamp', 'description': 'Unix timestamp when this record was sealed.'}, 'confidence': {'type': 'number', 'title': 'Confidence', 'description': 'Confidence score of the verdict, from 0.0 to 1.0.'}, 'drift_mode': {'type': 'string', 'title': 'Drift Mode', 'description': 'Current drift status: NORMAL, WARNING, ESCALATION, or BLOCK.'}, 'input_hash': {'type': 'string', 'title': 'Input Hash', 'description': 'Hash of the evaluated response (raw content is never stored).'}, 'verify_url': {'type': 'string', 'title': 'Verify Url', 'description': 'Public URL to independently verify this seal.'}, 'chain_index': {'type': 'integer', 'title': 'Chain Index', 'description': 'Sequential index of this record in the audit chain.'}, 'drift_score': {'type': 'number', 'title': 'Drift Score', 'description': 'Z-score measuring deviation of the recent commit rate from baseline.'}, 'policy_version': {'type': 'string', 'title': 'Policy Version', 'description': 'Version of the policy that was applied.'}}}
dcl_evaluate_safety
Baseline Safety Check
PRE-ACTION Baseline Safety Check ($0.01). Runs the "safety" policy: flags 2 forbidden disclaimers ("I cannot be held responsible", "no guarantees") and additionally REQUIRES the substring "AI" to appear somewhere in the response — missing it costs 0.2 confidence even with no forbidden phrase present. Minimum confidence is 0.75. Returns NO_COMMIT if confidence drops below 0.75, with `reason` naming the forbidden phrase found or the missing required pattern. Use this when you specifically need to confirm an AI-disclosure marker is present and the two disclaimer phrases are absent — not as a general-purpose safety net; for broader coverage use dcl_evaluate_fast or dcl_evaluate_strict instead.
입력 스키마
{'type': 'object', 'title': 'dcl_evaluate_safetyArguments', 'required': ['response', 'agent_id'], 'properties': {'agent_id': {'type': 'string', 'title': 'Agent Id', 'description': 'Identifier of the agent that produced the response.'}, 'response': {'type': 'string', 'title': 'Response', 'description': 'The agent or LLM response text to check for safety violations.'}}}
출력 스키마
{'type': 'object', 'title': 'EvaluateResult', 'required': ['verdict', 'confidence', 'reason', 'tx_hash', 'chain_index', 'input_hash', 'policy_version', 'drift_mode', 'drift_score', 'timestamp', 'seal_text', 'verify_url'], 'properties': {'reason': {'type': 'string', 'title': 'Reason', 'description': 'Human-readable explanation of why the verdict was reached.'}, 'tx_hash': {'type': 'string', 'title': 'Tx Hash', 'description': 'Hash of this record in the tamper-evident audit chain.'}, 'verdict': {'type': 'string', 'title': 'Verdict', 'description': 'COMMIT if the response passed policy checks, otherwise NO_COMMIT.'}, 'seal_text': {'type': 'string', 'title': 'Seal Text', 'description': 'Human-readable Leibniz Layer verification seal.'}, 'timestamp': {'type': 'number', 'title': 'Timestamp', 'description': 'Unix timestamp when this record was sealed.'}, 'confidence': {'type': 'number', 'title': 'Confidence', 'description': 'Confidence score of the verdict, from 0.0 to 1.0.'}, 'drift_mode': {'type': 'string', 'title': 'Drift Mode', 'description': 'Current drift status: NORMAL, WARNING, ESCALATION, or BLOCK.'}, 'input_hash': {'type': 'string', 'title': 'Input Hash', 'description': 'Hash of the evaluated response (raw content is never stored).'}, 'verify_url': {'type': 'string', 'title': 'Verify Url', 'description': 'Public URL to independently verify this seal.'}, 'chain_index': {'type': 'integer', 'title': 'Chain Index', 'description': 'Sequential index of this record in the audit chain.'}, 'drift_score': {'type': 'number', 'title': 'Drift Score', 'description': 'Z-score measuring deviation of the recent commit rate from baseline.'}, 'policy_version': {'type': 'string', 'title': 'Policy Version', 'description': 'Version of the policy that was applied.'}}}
dcl_evaluate_secrets
Secret & Credential Leak Scan
POST-ACTION Secret & Credential Leak Scan ($0.02). Regex-based scan across 8 categories (API keys, cloud credentials, tokens/JWTs, private keys, DB URLs, connection strings, env assignments, webhook secrets, internal endpoints with auth). Any finding results in NO_COMMIT.
입력 스키마
{'type': 'object', 'title': 'dcl_evaluate_secretsArguments', 'required': ['response', 'agent_id'], 'properties': {'agent_id': {'type': 'string', 'title': 'Agent Id', 'description': 'Identifier of the agent that produced the response.'}, 'response': {'type': 'string', 'title': 'Response', 'description': 'The text to scan for exposed API keys, tokens, private keys, DB URLs, and other credentials.'}}}
출력 스키마
{'type': 'object', '$defs': {'DetectionFinding': {'type': 'object', 'title': 'DetectionFinding', 'required': ['type', 'position', 'redacted_sample', 'severity', 'category'], 'properties': {'type': {'type': 'string', 'title': 'Type', 'description': "The specific pattern category matched (e.g. 'api_key', 'email')."}, 'category': {'type': 'string', 'title': 'Category', 'description': 'Checklist code, e.g. S1-S8 for secrets or T1-T8 for PII.'}, 'position': {'type': 'integer', 'title': 'Position', 'description': 'Character offset of the match in the submitted text.'}, 'provider': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Provider', 'default': None, 'description': 'Identified provider/service, if known.'}, 'severity': {'type': 'string', 'title': 'Severity', 'description': 'critical, major, or minor.'}, 'redacted_sample': {'type': 'string', 'title': 'Redacted Sample', 'description': 'Masked version of the match â\x80\x94 first 2 and last 4 chars only.'}}}}, 'title': 'ScanResult', 'required': ['verdict', 'risk_score', 'findings', 'detection_count', 'categories_checked', 'categories_clear', 'tx_hash', 'chain_index', 'input_hash', 'timestamp', 'seal_text', 'verify_url'], 'properties': {'tx_hash': {'type': 'string', 'title': 'Tx Hash', 'description': 'Hash of this record in the tamper-evident audit chain.'}, 'verdict': {'type': 'string', 'title': 'Verdict', 'description': 'COMMIT if nothing was found, otherwise NO_COMMIT.'}, 'findings': {'type': 'array', 'items': {'$ref': '#/$defs/DetectionFinding'}, 'title': 'Findings', 'description': 'All matches found. Empty list if verdict is COMMIT.'}, 'seal_text': {'type': 'string', 'title': 'Seal Text', 'description': 'Human-readable Leibniz Layer verification seal.'}, 'timestamp': {'type': 'number', 'title': 'Timestamp', 'description': 'Unix timestamp when this record was sealed.'}, 'input_hash': {'type': 'string', 'title': 'Input Hash', 'description': 'Hash of the scanned text (raw content is never stored).'}, 'risk_score': {'type': 'number', 'title': 'Risk Score', 'description': '0.0-1.0 risk score based on number and severity of findings.'}, 'verify_url': {'type': 'string', 'title': 'Verify Url', 'description': 'Public URL to independently verify this seal.'}, 'chain_index': {'type': 'integer', 'title': 'Chain Index', 'description': 'Sequential index of this record in the audit chain.'}, 'detection_count': {'type': 'integer', 'title': 'Detection Count', 'description': 'Number of findings.'}, 'categories_clear': {'type': 'array', 'items': {'type': 'string'}, 'title': 'Categories Clear', 'description': 'Categories with no findings.'}, 'categories_checked': {'type': 'array', 'items': {'type': 'string'}, 'title': 'Categories Checked', 'description': 'All checklist categories that were scanned.'}}}
dcl_evaluate_signal
Market Signal Fabrication Screen
POST-ACTION Market Signal Fabrication Screen ($0.03). Pattern-based heuristic on the output text alone (no source price feed) — flags guaranteed-price-prediction language ("will definitely hit $X"), absolute-certainty claims ("100% certain", "cannot go down"), a fabricated-price flag when a specific dollar figure co-occurs with a guaranteed-outcome claim, and an invented-token flag when a "$TICKER" cashtag doesn't match a small set of well-known symbols (false positives are possible for legitimate lesser-known tickers — this is a heuristic pre-check, not ground truth). For a full claim-by-claim check against an actual price-feed snapshot, use the local grounding workflow instead of this live tool. Verdict/confidence collapsing follows the same rule as dcl_evaluate_mev: any critical finding or 2+ major findings is a hard NO_COMMIT; exactly one major finding is a softer NO_COMMIT at ~0.55 confidence.
입력 스키마
{'type': 'object', 'title': 'dcl_evaluate_signalArguments', 'required': ['response', 'agent_id'], 'properties': {'agent_id': {'type': 'string', 'title': 'Agent Id', 'description': 'Identifier of the agent that produced the response.'}, 'response': {'type': 'string', 'title': 'Response', 'description': 'The market signal, analysis, or price-prediction text to screen.'}}}
출력 스키마
{'type': 'object', '$defs': {'CryptoFinding': {'type': 'object', 'title': 'CryptoFinding', 'required': ['type', 'severity'], 'properties': {'type': {'type': 'string', 'title': 'Type', 'description': 'The specific pattern category matched.'}, 'severity': {'type': 'string', 'title': 'Severity', 'description': 'critical or major.'}, 'regulatory_reference': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Regulatory Reference', 'default': None, 'description': 'Illustrative regulatory tag for this finding type (e.g. MiFID II, FCA), if applicable.'}}}}, 'title': 'SignalResult', 'required': ['verdict', 'confidence', 'reason', 'findings', 'tx_hash', 'chain_index', 'input_hash', 'timestamp'], 'properties': {'reason': {'type': 'string', 'title': 'Reason', 'description': 'Human-readable explanation of the verdict.'}, 'tx_hash': {'type': 'string', 'title': 'Tx Hash', 'description': 'Hash of this record in the tamper-evident audit chain.'}, 'verdict': {'type': 'string', 'title': 'Verdict', 'description': 'COMMIT if no fabrication/overconfidence pattern matched, otherwise NO_COMMIT.'}, 'findings': {'type': 'array', 'items': {'$ref': '#/$defs/CryptoFinding'}, 'title': 'Findings', 'description': 'All matched patterns. Empty list if verdict is COMMIT.'}, 'timestamp': {'type': 'number', 'title': 'Timestamp', 'description': 'Unix timestamp when this record was sealed.'}, 'confidence': {'type': 'number', 'title': 'Confidence', 'description': 'Confidence score of the verdict, from 0.0 to 1.0.'}, 'input_hash': {'type': 'string', 'title': 'Input Hash', 'description': 'Hash of the screened text (raw content is never stored).'}, 'chain_index': {'type': 'integer', 'title': 'Chain Index', 'description': 'Sequential index of this record in the audit chain.'}}}
dcl_evaluate_strict
Strict Pre-Action Audit
STRICT Pre-Action Audit ($0.05). Runs the response against a broader, higher-bar "strict" policy: the union of all forbidden phrases from the default, anti-jailbreak, and safety policies (8 phrases total), with a 0.85 minimum-confidence threshold instead of the default policy's 0.7. Each matched phrase costs 0.4 confidence; if confidence falls below 0.85, or any phrase matches, the verdict is NO_COMMIT with `reason` listing every match found. Use this instead of dcl_evaluate_fast when the cost of a false COMMIT is high — e.g. before an irreversible or high-stakes agent action — since it catches jailbreak- and safety-adjacent phrasing that the plain default policy would miss.
입력 스키마
{'type': 'object', 'title': 'dcl_evaluate_strictArguments', 'required': ['response', 'agent_id'], 'properties': {'agent_id': {'type': 'string', 'title': 'Agent Id', 'description': 'Identifier of the agent that produced the response.'}, 'response': {'type': 'string', 'title': 'Response', 'description': 'The agent or LLM response text to audit.'}}}
출력 스키마
{'type': 'object', 'title': 'EvaluateResult', 'required': ['verdict', 'confidence', 'reason', 'tx_hash', 'chain_index', 'input_hash', 'policy_version', 'drift_mode', 'drift_score', 'timestamp', 'seal_text', 'verify_url'], 'properties': {'reason': {'type': 'string', 'title': 'Reason', 'description': 'Human-readable explanation of why the verdict was reached.'}, 'tx_hash': {'type': 'string', 'title': 'Tx Hash', 'description': 'Hash of this record in the tamper-evident audit chain.'}, 'verdict': {'type': 'string', 'title': 'Verdict', 'description': 'COMMIT if the response passed policy checks, otherwise NO_COMMIT.'}, 'seal_text': {'type': 'string', 'title': 'Seal Text', 'description': 'Human-readable Leibniz Layer verification seal.'}, 'timestamp': {'type': 'number', 'title': 'Timestamp', 'description': 'Unix timestamp when this record was sealed.'}, 'confidence': {'type': 'number', 'title': 'Confidence', 'description': 'Confidence score of the verdict, from 0.0 to 1.0.'}, 'drift_mode': {'type': 'string', 'title': 'Drift Mode', 'description': 'Current drift status: NORMAL, WARNING, ESCALATION, or BLOCK.'}, 'input_hash': {'type': 'string', 'title': 'Input Hash', 'description': 'Hash of the evaluated response (raw content is never stored).'}, 'verify_url': {'type': 'string', 'title': 'Verify Url', 'description': 'Public URL to independently verify this seal.'}, 'chain_index': {'type': 'integer', 'title': 'Chain Index', 'description': 'Sequential index of this record in the audit chain.'}, 'drift_score': {'type': 'number', 'title': 'Drift Score', 'description': 'Z-score measuring deviation of the recent commit rate from baseline.'}, 'policy_version': {'type': 'string', 'title': 'Policy Version', 'description': 'Version of the policy that was applied.'}}}
dcl_evaluate_trade
Trade Decision Verifier
PRE-ACTION Trade Decision Verifier ($0.02). Screens trade-decision language for guaranteed-return claims, zero-risk/"can't lose" framing, and unqualified "buy/sell X now" directives — any match is NO_COMMIT. If no unsafe language is found, COMMIT additionally requires the word "risk" to appear anywhere in the text as a minimum disclosure marker; its absence alone triggers NO_COMMIT with `reason` noting the missing disclosure. Produces an immutable `trade_receipt` (tx_hash/chain_hash/chain_depth) distinct from the top-level audit hash, for downstream systems that specifically need a trade-shaped receipt object.
입력 스키마
{'type': 'object', 'title': 'dcl_evaluate_tradeArguments', 'required': ['response', 'agent_id'], 'properties': {'agent_id': {'type': 'string', 'title': 'Agent Id', 'description': 'Identifier of the agent that produced the response.'}, 'response': {'type': 'string', 'title': 'Response', 'description': 'The trade decision or recommendation text to screen.'}}}
출력 스키마
{'type': 'object', '$defs': {'TradeReceipt': {'type': 'object', 'title': 'TradeReceipt', 'required': ['tx_hash', 'chain_hash', 'chain_depth'], 'properties': {'tx_hash': {'type': 'string', 'title': 'Tx Hash', 'description': 'Tamper-evident proof of this specific trade-verification record.'}, 'chain_hash': {'type': 'string', 'title': 'Chain Hash', 'description': 'Hash of the previous commit in the append-only chain that this one links to.'}, 'chain_depth': {'type': 'integer', 'title': 'Chain Depth', 'description': "This record's position (index) in the chain."}}}, 'CryptoFinding': {'type': 'object', 'title': 'CryptoFinding', 'required': ['type', 'severity'], 'properties': {'type': {'type': 'string', 'title': 'Type', 'description': 'The specific pattern category matched.'}, 'severity': {'type': 'string', 'title': 'Severity', 'description': 'critical or major.'}, 'regulatory_reference': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Regulatory Reference', 'default': None, 'description': 'Illustrative regulatory tag for this finding type (e.g. MiFID II, FCA), if applicable.'}}}}, 'title': 'TradeResult', 'required': ['verdict', 'confidence', 'reason', 'findings', 'trade_receipt', 'input_hash', 'timestamp'], 'properties': {'reason': {'type': 'string', 'title': 'Reason', 'description': 'Human-readable explanation of the verdict.'}, 'verdict': {'type': 'string', 'title': 'Verdict', 'description': "COMMIT if the trade decision's language passed the screen, otherwise NO_COMMIT."}, 'findings': {'type': 'array', 'items': {'$ref': '#/$defs/CryptoFinding'}, 'title': 'Findings', 'description': 'All matched patterns. Empty list if verdict is COMMIT.'}, 'timestamp': {'type': 'number', 'title': 'Timestamp', 'description': 'Unix timestamp when this record was sealed.'}, 'confidence': {'type': 'number', 'title': 'Confidence', 'description': 'Confidence score of the verdict, from 0.0 to 1.0.'}, 'input_hash': {'type': 'string', 'title': 'Input Hash', 'description': 'Hash of the screened text (raw content is never stored).'}, 'trade_receipt': {'$ref': '#/$defs/TradeReceipt', 'description': 'Immutable receipt for this trade-verification record.'}}}
dcl_evaluate_wallet
Wallet Secret Guardian
POST-ACTION Wallet Secret Guardian ($0.02). Scans for BIP-39 seed phrases (12 or 24 consecutive wordlist words), raw hex or WIF-format private keys, Ethereum/Bitcoin wallet addresses, and API keys/bearer tokens appearing near wallet/custody/signing terminology. Any finding results in NO_COMMIT — wallet secrets have no safe threshold, unlike other DCL evaluators. Returns a `sanitized_output` with all matches redacted (null if nothing was found) and a masked `redacted_sample` per finding — the real value is never returned or stored server-side.
입력 스키마
{'type': 'object', 'title': 'dcl_evaluate_walletArguments', 'required': ['response', 'agent_id'], 'properties': {'agent_id': {'type': 'string', 'title': 'Agent Id', 'description': 'Identifier of the agent that produced the response.'}, 'response': {'type': 'string', 'title': 'Response', 'description': 'The text to scan for seed phrases, private keys, wallet addresses, and wallet-context API credentials.'}}}
출력 스키마
{'type': 'object', '$defs': {'WalletFinding': {'type': 'object', 'title': 'WalletFinding', 'required': ['type', 'position', 'redacted_sample', 'severity'], 'properties': {'type': {'type': 'string', 'title': 'Type', 'description': 'seed_phrase, private_key, wallet_address, or wallet_api_credential.'}, 'position': {'type': 'integer', 'title': 'Position', 'description': 'Character offset of the match in the submitted text.'}, 'severity': {'type': 'string', 'title': 'Severity', 'description': 'critical or major.'}, 'redacted_sample': {'type': 'string', 'title': 'Redacted Sample', 'description': 'Masked version of the match â\x80\x94 never the real value.'}}}}, 'title': 'WalletResult', 'required': ['verdict', 'confidence', 'reason', 'findings', 'risk_score', 'tx_hash', 'chain_index', 'input_hash', 'policy_version', 'timestamp'], 'properties': {'reason': {'type': 'string', 'title': 'Reason', 'description': 'Human-readable explanation of the verdict.'}, 'tx_hash': {'type': 'string', 'title': 'Tx Hash', 'description': 'Hash of this record in the tamper-evident audit chain.'}, 'verdict': {'type': 'string', 'title': 'Verdict', 'description': 'COMMIT if nothing was found, otherwise NO_COMMIT. Wallet secrets have no safe threshold.'}, 'findings': {'type': 'array', 'items': {'$ref': '#/$defs/WalletFinding'}, 'title': 'Findings', 'description': 'All matches found. Empty list if verdict is COMMIT.'}, 'timestamp': {'type': 'number', 'title': 'Timestamp', 'description': 'Unix timestamp when this record was sealed.'}, 'confidence': {'type': 'number', 'title': 'Confidence', 'description': 'Confidence score of the verdict, from 0.0 to 1.0.'}, 'input_hash': {'type': 'string', 'title': 'Input Hash', 'description': 'Hash of the scanned text (raw content is never stored).'}, 'risk_score': {'type': 'number', 'title': 'Risk Score', 'description': '0.0-1.0 risk score based on number and severity of findings.'}, 'chain_index': {'type': 'integer', 'title': 'Chain Index', 'description': 'Sequential index of this record in the audit chain.'}, 'policy_version': {'type': 'string', 'title': 'Policy Version', 'description': 'Version of the wallet-guardian policy that was applied.'}, 'sanitized_output': {'anyOf': [{'type': 'string'}, {'type': 'null'}], 'title': 'Sanitized Output', 'default': None, 'description': 'Input text with all matches redacted. Null if verdict is COMMIT.'}}}
dcl_pipeline_start
Start Pipeline Session
SESSION Management ($0.05). Generates a new `pipeline_id` and returns session metadata (scope, expiry, initial drift_mode) for organizing a series of related checks under one identifier. Note: this call does not currently link the returned pipeline_id to later evaluate_* calls — there is no server-side session state that ties subsequent audits back to it; it is an identifier/timestamp issuer, not an active tracking session. Use this to obtain a shared reference ID for your own client-side grouping of a multi-step audit sequence; do not rely on it to automatically aggregate drift across calls.
입력 스키마
{'type': 'object', 'title': 'dcl_pipeline_startArguments', 'required': ['agent_id'], 'properties': {'scope': {'type': 'string', 'title': 'Scope', 'default': 'default', 'description': 'Scope label for the session.'}, 'agent_id': {'type': 'string', 'title': 'Agent Id', 'description': 'Identifier of the agent that owns this session.'}, 'ttl_seconds': {'type': 'integer', 'title': 'Ttl Seconds', 'default': 3600, 'description': 'Session time-to-live, in seconds.'}}}
출력 스키마
{'type': 'object', 'title': 'PipelineStartResult', 'required': ['pipeline_id', 'agent_id', 'scope', 'expires_at', 'drift_mode'], 'properties': {'scope': {'type': 'string', 'title': 'Scope', 'description': 'Scope label for the session.'}, 'agent_id': {'type': 'string', 'title': 'Agent Id', 'description': 'Identifier of the agent that owns this session.'}, 'drift_mode': {'type': 'string', 'title': 'Drift Mode', 'description': 'Drift status at session start (always NORMAL for a new session).'}, 'expires_at': {'type': 'number', 'title': 'Expires At', 'description': 'Unix timestamp when the session expires.'}, 'pipeline_id': {'type': 'string', 'title': 'Pipeline Id', 'description': 'Unique identifier for the newly opened pipeline session.'}}}
추가됨
dcl_commit
2026년 9월 17일 12:34 PM
추가됨
dcl_evaluate_output_sanitizer
2026년 9월 17일 12:34 PM
추가됨
dcl_evaluate_signal
2026년 9월 17일 12:34 PM
추가됨
dcl_evaluate_mev
2026년 9월 17일 12:34 PM
추가됨
dcl_evaluate_trade
2026년 9월 17일 12:34 PM
추가됨
dcl_evaluate_wallet
2026년 9월 17일 12:34 PM
추가됨
dcl_evaluate_jailbreak_crypto
2026년 9월 17일 12:34 PM
추가됨
dcl_audit_decode_deep
2026년 9월 17일 12:34 PM
추가됨
dcl_audit_decode
2026년 9월 17일 12:34 PM
추가됨
dcl_pipeline_start
2026년 9월 17일 12:34 PM
추가됨
dcl_evaluate_batch
2026년 9월 17일 12:34 PM
추가됨
dcl_evaluate_pii
2026년 9월 17일 12:34 PM
추가됨
dcl_evaluate_secrets
2026년 9월 17일 12:34 PM
추가됨
dcl_evaluate_quality
2026년 9월 17일 12:34 PM
추가됨
dcl_evaluate_safety
2026년 9월 17일 12:34 PM
추가됨
dcl_evaluate_jailbreak
2026년 9월 17일 12:34 PM
추가됨
dcl_evaluate_strict
2026년 9월 17일 12:34 PM
추가됨
dcl_evaluate_fast
2026년 9월 17일 12:34 PM