Aziel Runtime
此 MCP 可以做什么
Provides a governed MCP runtime with registry discovery, controlled tool execution, provenance receipts, integrity checks, memory controls, and audit chains.
工具
输入模式
{'type': 'object', 'required': ['fact'], 'properties': {'c': {'enum': ['genesis', 'identity', 'ssh', 'session', 'acts', 'evidence', 'recall', 'mesh', 'library', 'learn'], 'type': 'string', 'description': 'Optional chain name. One of genesis, identity, ssh, session, acts, evidence, recall, mesh, library, learn. Alias: chain. Omit both to stamp the session chain.'}, 'k': {'type': 'string', 'description': 'Optional kind label. Omit to store kind stamp. Alias: kind.'}, 'fact': {'type': 'string', 'maxLength': 160, 'description': 'Required fact text clipped to 160 characters. Empty or hash-only after clip refuses no-fact. Alias: f.'}, 'chain': {'enum': ['genesis', 'identity', 'ssh', 'session', 'acts', 'evidence', 'recall', 'mesh', 'library', 'learn'], 'type': 'string', 'description': 'Alias of c. Omit both to stamp the session chain.'}, 'confirm': {'type': 'boolean', 'description': 'Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation.'}, 'dry_run': {'type': 'boolean', 'description': 'Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation.'}, 'subject': {'type': 'string', 'maxLength': 80, 'description': 'Optional subject clipped to 80 characters. Alias: s.'}}, 'description': 'fact is required. Omit c/chain to stamp session. Extra keys such as s/f/kind are aliases; they do not change the append-only rule. Mutation requires confirm=true or dry_run=true.', 'additionalProperties': True}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'Append body: ok, stamp (id, c, k, fact, fh, stamp_sha256, prev), card, seq, vault path. Refuses: no-fact, unknown-chain, card-cap.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'properties': {'c': {'enum': ['genesis', 'identity', 'ssh', 'session', 'acts', 'evidence', 'recall', 'mesh', 'library', 'learn'], 'type': 'string', 'description': 'Optional chain name. One of genesis, identity, ssh, session, acts, evidence, recall, mesh, library, learn. Alias: chain. Omit both to scan session, acts, recall, and learn — not the full roster.'}, 'q': {'type': 'string', 'description': 'Optional case-insensitive substring over subject/fact. Alias: query. Empty does not invent matches.'}, 'chain': {'enum': ['genesis', 'identity', 'ssh', 'session', 'acts', 'evidence', 'recall', 'mesh', 'library', 'learn'], 'type': 'string', 'description': 'Alias of c. Omit both to scan session, acts, recall, and learn — not the full roster.'}, 'depth': {'type': 'number', 'maximum': 5, 'minimum': 0, 'description': 'Optional recall depth. Omit for 1. 0 = tip only; 5 = genesis/budget maximum. Values outside 0–5 are clipped. Alias: d.'}}, 'description': 'All fields optional. Default depth is 1. Default chains are session, acts, recall, learn.', 'additionalProperties': True}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'properties': {'ts': {'type': 'string', 'description': 'Optional ISO-8601 timestamp copied onto the TemporalLock block. Omit to use now. Never backdates authority, prior stamps, or godlock.uk.'}, 'confirm': {'type': 'boolean', 'description': 'Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation.'}, 'dry_run': {'type': 'boolean', 'description': 'Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation.'}}, 'description': 'No required arguments. Empty {} seals current live tips. Optional ts is TemporalLock metadata only. Mutation requires confirm=true or dry_run=true.', 'additionalProperties': True}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'Seal body: ok, lockset (members, temporal, godlock, lockset_sha256), or refuse empty-vault when no live tips exist. Does not write godlock.uk.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'properties': {'c': {'enum': ['genesis', 'identity', 'ssh', 'session', 'acts', 'evidence', 'recall', 'mesh', 'library', 'learn'], 'type': 'string', 'description': 'Optional chain name. One of genesis, identity, ssh, session, acts, evidence, recall, mesh, library, learn. Alias: chain. Omit both to read the session chain tip.'}, 'chain': {'enum': ['genesis', 'identity', 'ssh', 'session', 'acts', 'evidence', 'recall', 'mesh', 'library', 'learn'], 'type': 'string', 'description': 'Alias of c. Omit both to read the session chain tip.'}}, 'description': 'Omit c/chain to read the session chain tip. Extra properties are rejected.', 'additionalProperties': False}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'Tip body: ok, chain, tip card or null, empty flag, seq when a stamp exists. Empty chain is ok+empty, not an invented card.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'properties': {'c': {'enum': ['genesis', 'identity', 'ssh', 'session', 'acts', 'evidence', 'recall', 'mesh', 'library', 'learn'], 'type': 'string', 'description': 'Optional chain name. One of genesis, identity, ssh, session, acts, evidence, recall, mesh, library, learn. Alias: chain. Omit both to verify every roster chain plus the stored LOCKSET.'}, 'chain': {'enum': ['genesis', 'identity', 'ssh', 'session', 'acts', 'evidence', 'recall', 'mesh', 'library', 'learn'], 'type': 'string', 'description': 'Alias of c. Omit both to verify every roster chain plus the stored LOCKSET.'}, 'require_seal': {'type': 'boolean', 'description': 'Optional. When true, fail-closed if receipts/LOCKSET.json is missing. When omitted, a stored lockset is still checked if present.'}}, 'description': 'Optional chain selector. Omit to verify the live vault / LOCKSET.', 'additionalProperties': True}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'properties': {'values': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Optional values list.'}, 'confirm': {'type': 'boolean', 'description': 'Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation.'}, 'dry_run': {'type': 'boolean', 'description': 'Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation.'}, 'evidence': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Optional evidence strings. Missing evidence can fail a gate.'}, 'statement': {'type': 'string', 'description': 'Optional proposal statement to evaluate.'}, 'impact_neg': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Optional negative-impact list.'}, 'impact_pos': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Optional positive-impact list.'}, 'accountable': {'type': 'string', 'description': 'Optional accountable party string.'}}, 'description': 'All schema fields optional. Empty proposals still run the five gates and stamp the ledger. Live stamp still needs confirm=true at tools/call, or dry_run=true for a preview.', 'additionalProperties': True}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'required': ['op'], 'properties': {'op': {'type': 'string', 'description': 'Required public allowlisted op from fraggate_describe (for example fold-preview, ethical_search, blank_key_status). UI aliases (list_modules, place, genesis_boot, hold, airlock, home, classify, doctor, pair) forward to catalog ops. Unknown ops refuse FG-UNKNOWN-OP; stubs refuse FG-STUB.'}, 'name': {'type': 'string', 'description': 'Optional registry display name (for example FoldLock, EmbryoLock, AZHub). Use name or slug — one is enough. Combined name/op forms such as foldlock/fold-preview are accepted by the door parser. Unknown names refuse FG-HALLUC-TOOL.'}, 'slug': {'type': 'string', 'description': 'Optional catalog slug (lowercase a-z0-9-, for example foldlock, embryolock, azhub). Alternative to name. Prefer the slug returned by fraggate_list or GET /v1/software.'}, 'claim': {'type': 'object', 'properties': {'values': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Optional values the proposal claims to honor.'}, 'evidence': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Optional evidence strings supporting the statement.'}, 'statement': {'type': 'string', 'description': 'Optional proposal statement (what is being asked).'}, 'impact_neg': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Optional negative impacts.'}, 'impact_pos': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Optional positive impacts.'}, 'accountable': {'type': 'string', 'description': 'Optional accountable party. Identity on this runtime is Aziel Eliab only.'}}, 'description': 'Optional DecisionGATE proposal attached to this call. Also runs automatically inside the door even when omitted (defaults). Freedom without clarity is chaos.', 'additionalProperties': True}, 'job_id': {'type': 'string', 'pattern': '^job_[a-f0-9]{16}$', 'description': 'Optional job id from a background call (job_ + 16 hex). When set, the call reads that job and does not start another. confirm=true is still required. It does not re-run the op.'}, 'confirm': {'type': 'boolean', 'description': 'Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation.'}, 'dry_run': {'type': 'boolean', 'description': 'Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation.'}, 'payload': {'type': 'object', 'description': 'Optional op payload object. Shape is engine-specific (see fraggate_describe). Malformed fields are refused by the engine, not by this door schema. If omitted, leftover top-level keys are used as the payload.', 'additionalProperties': True}, 'attempt_n': {'type': 'integer', 'minimum': 1, 'description': 'Optional 1-based attempt number for this call. Omitted means attempt 1 of a new request_id.'}, 'background': {'type': 'boolean', 'description': 'Optional. When true, FragGate admits the call and returns Running with a job_id before the op finishes. Done is returned only after a receipt hash exists. dry_run does not start a job. A missing job is Quiet, not Done.'}, 'request_id': {'type': 'string', 'description': 'Optional logical request id. The same value groups retries of one action on the ResultEnvelope and, for ForgeReceipts, inside the receipt hash.'}, 'correlation_id': {'type': 'string', 'nullable': True, 'description': 'Optional client correlation id. Sealed inside a ForgeReceipts hash when this call mints one.'}, 'parent_receipt_id': {'type': 'string', 'nullable': True, 'description': 'Optional prior attempt receipt hash. Null on the first attempt. This is not FragGate ledger prev, which stays call order only.'}}, 'description': 'Required: op, unless job_id is set. Also pass slug or name. Shorthand foldlock/fold-preview is accepted. Mutation requires confirm=true or dry_run=true. background=true returns Running until a receipt hash exists.', 'additionalProperties': True}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'properties': {'name': {'type': 'string', 'description': 'Optional registry display name (for example FoldLock, EmbryoLock, AZHub). Use name or slug — one is enough. Combined name/op forms such as foldlock/fold-preview are accepted by the door parser. Unknown names refuse FG-HALLUC-TOOL.'}, 'slug': {'type': 'string', 'description': 'Optional catalog slug (lowercase a-z0-9-, for example foldlock, embryolock, azhub). Alternative to name. Prefer the slug returned by fraggate_list or GET /v1/software.'}}, 'description': 'Exactly one of name or slug is enough. Extra properties are rejected by the schema; the door still only reads name/slug.', 'additionalProperties': False}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'properties': {}, 'description': 'No arguments. Send {}. Discovery first — not describe or execute.', 'additionalProperties': False}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'properties': {'name': {'type': 'string', 'description': 'Optional registry display name (for example FoldLock, EmbryoLock, AZHub). Use name or slug — one is enough. Combined name/op forms such as foldlock/fold-preview are accepted by the door parser. Unknown names refuse FG-HALLUC-TOOL.'}, 'slug': {'type': 'string', 'description': 'Optional catalog slug (lowercase a-z0-9-, for example foldlock, embryolock, azhub). Alternative to name. Prefer the slug returned by fraggate_list or GET /v1/software.'}, 'digest': {'type': 'string', 'pattern': '^[a-fA-F0-9]{64}$', 'description': 'Optional 64-char lowercase hex engine_digest or registry digest to verify. When digest is set without name/slug, the tool compares the live registry digest.'}}, 'description': 'Provide name, slug, and/or digest. Empty {} refuses FG-HALLUC-TOOL. Digest-only checks the whole registry hash.', 'additionalProperties': False}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'properties': {'q': {'type': 'string', 'description': 'Optional public-corpus query for op=search. Empty q returns an empty or default hit set, not an invented cite. Not a memory or ChainLock query.'}, 'op': {'enum': ['search', 'example', 'skill', 'health'], 'type': 'string', 'description': 'Optional library verb. search (default) looks up public corpus text; example returns a sample; skill returns the library skill; health is liveness. Other values refuse FG-UNKNOWN-OP.'}}, 'description': 'q is the search text. op selects the library verb. Extra keys are forwarded as corpus payload.', 'additionalProperties': True}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'properties': {'fact': {'type': 'string', 'maxLength': 160, 'description': 'Fact text clipped to 160 characters. Required on observe. Hash-only cards refuse AKM-NO-FACT.'}, 'confirm': {'type': 'boolean', 'description': 'Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation.'}, 'dry_run': {'type': 'boolean', 'description': 'Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation.'}, 'subject': {'type': 'string', 'maxLength': 80, 'description': 'Optional subject key clipped to 80 characters. Used to find or create memory_id.'}, 'use_case': {'type': 'string', 'description': 'Optional use-case label for calibration / adaptive recall ranking. Not a truth claim.'}, 'memory_id': {'type': 'string', 'description': 'Optional existing memory id. Alternative to subject for resolve/calibrate/get.'}}, 'description': 'subject or memory_id recommended. Extra keys are accepted. Mutation requires confirm=true or dry_run=true.', 'additionalProperties': True}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'properties': {'id': {'type': 'string', 'description': 'Alias of memory_id. Do not send two different values.'}, 'view': {'enum': ['get', 'history', 'calibration'], 'type': 'string', 'description': 'Optional slice. Omit or get = stored node; history = events/resolutions; calibration = posterior, triad legs, effective N, Brier.'}, 'memory_id': {'type': 'string', 'description': 'Memory id to explain. Alternative to id. Missing both refuses AKM-NOT-FOUND.'}}, 'description': 'Pass memory_id or id (aliases). Omit view for the node slice. Extra properties are rejected.', 'additionalProperties': False}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'Explain body: ok, memory_id, status, plus node or events or calibration fields. belief_is_not_truth. Refuses AKM-NOT-FOUND when the id is missing or unknown.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'required': ['fact'], 'properties': {'fact': {'type': 'string', 'maxLength': 160, 'description': 'Fact text clipped to 160 characters. Required on observe. Hash-only cards refuse AKM-NO-FACT.'}, 'confirm': {'type': 'boolean', 'description': 'Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation.'}, 'dry_run': {'type': 'boolean', 'description': 'Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation.'}, 'subject': {'type': 'string', 'maxLength': 80, 'description': 'Optional subject key clipped to 80 characters. Used to find or create memory_id.'}, 'use_case': {'type': 'string', 'description': 'Optional use-case label for calibration / adaptive recall ranking. Not a truth claim.'}, 'memory_id': {'type': 'string', 'description': 'Optional existing memory id. Alternative to subject for resolve/calibrate/get.'}}, 'description': 'fact is required. subject/memory_id/use_case optional. Mutation requires confirm=true or dry_run=true.', 'additionalProperties': True}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'properties': {'q': {'type': 'string', 'description': 'Optional lexical rank query (subject/fact). Alias: query. Empty still runs verify-then-rank; it does not invent facts.'}, 'depth': {'type': 'number', 'maximum': 5, 'minimum': 0, 'description': 'Optional ChainLock recall depth after verify. Omit for 5 (full budget). 0 is tip-only ranking.'}, 'limit': {'type': 'number', 'maximum': 16, 'minimum': 1, 'description': 'Optional result cap. Hard ceiling is 16 (MEMORY_CONTEXT_CAP) even if a larger number is sent.'}, 'use_case': {'type': 'string', 'description': 'Optional use-case label that weights triad_fit in ranking. Not a permission and not a truth claim.'}}, 'description': 'All fields optional. Default depth is 5. Empty q still runs verify-then-rank and does not invent facts.', 'additionalProperties': True}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'Adaptive recall body: ok, adaptive=true, verified, count, facts (ranked cards with score/retrieval), belief_is_not_truth, authorizes_action=false. Refuses CHAIN_VERIFY_FAIL or no-stamp.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'properties': {'fact': {'type': 'string', 'maxLength': 160, 'description': 'Fact text clipped to 160 characters. Required on observe. Hash-only cards refuse AKM-NO-FACT.'}, 'confirm': {'type': 'boolean', 'description': 'Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation.'}, 'dry_run': {'type': 'boolean', 'description': 'Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation.'}, 'outcome': {'type': 'number', 'maximum': 1, 'minimum': 0, 'description': 'Optional graded outcome in [0, 1]. Omit (or pass UNKNOWN) for an UNKNOWN resolution — distinct from MISS.'}, 'subject': {'type': 'string', 'maxLength': 80, 'description': 'Optional subject key clipped to 80 characters. Used to find or create memory_id.'}, 'use_case': {'type': 'string', 'description': 'Optional use-case label for calibration / adaptive recall ranking. Not a truth claim.'}, 'memory_id': {'type': 'string', 'description': 'Optional existing memory id. Alternative to subject for resolve/calibrate/get.'}, 'outcome_label': {'type': 'string', 'description': 'Optional label (for example HIT, MISS, GRADED, UNKNOWN). UNKNOWN is a first-class state, not a miss.'}}, 'description': 'Requires memory_id or a previously observed subject. outcome may be omitted for UNKNOWN. Extra keys are accepted. Mutation requires confirm=true or dry_run=true.', 'additionalProperties': True}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'required': ['sha256'], 'properties': {'title': {'type': 'string', 'description': 'Optional short title for the receipt. Not the file contents.'}, 'sha256': {'type': 'string', 'pattern': '^[a-fA-F0-9]{64}$', 'maxLength': 64, 'minLength': 64, 'description': 'Required 64-character hex SHA-256 of the local file. Hash receipt only — not a publish path.'}, 'confirm': {'type': 'boolean', 'description': 'Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation.'}, 'dry_run': {'type': 'boolean', 'description': 'Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation.'}, 'product': {'type': 'string', 'description': 'Optional catalog product slug to attribute the receipt. Not required.'}}, 'description': 'sha256 is required (64 hex). This is a receipt, not a blob upload. Mutation requires confirm=true or dry_run=true.', 'additionalProperties': False}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'properties': {}, 'description': 'No arguments. Send {}. Public suite disable is refused.', 'additionalProperties': False}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'required': ['bearer'], 'properties': {'bearer': {'type': 'string', 'description': 'Required declared bearer name. Example: suite-presence. Login / account / recover / recovery / gate / IP / publish / phoenix / heal names refuse MESH-ENABLE. This is not a login mesh.'}, 'confirm': {'type': 'boolean', 'description': 'Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation.'}, 'dry_run': {'type': 'boolean', 'description': 'Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation.'}}, 'description': 'bearer is required. Empty object is MESH-ENABLE refuse. Mutation requires confirm=true or dry_run=true.', 'additionalProperties': False}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'required': ['node_id'], 'properties': {'prev': {'type': 'string', 'description': 'Optional 64-hex prev the receiver already holds. Same prev + a different tip_hash isolates this node (MESH-EQUIVOCATION).'}, 'confirm': {'type': 'boolean', 'description': 'Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation.'}, 'dry_run': {'type': 'boolean', 'description': 'Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation.'}, 'node_id': {'type': 'string', 'description': 'Required node id returned by mesh_join.'}, 'presence': {'enum': ['live', 'locked', 'isolated'], 'type': 'string', 'description': 'Optional replacement presence class. Other values refuse MESH-BAD-INPUT.'}, 'tip_hash': {'type': 'string', 'description': 'Optional 64-hex tip hash on the fast tick. Fixed-size. No body. Split the wires.'}}, 'description': 'node_id is required. Missing node_id refuses MESH-BAD-INPUT. Mutation requires confirm=true or dry_run=true.', 'additionalProperties': False}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'required': ['product'], 'properties': {'label': {'type': 'string', 'description': 'Optional short label for the roster. Display only; not a score.'}, 'confirm': {'type': 'boolean', 'description': 'Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation.'}, 'dry_run': {'type': 'boolean', 'description': 'Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation.'}, 'node_id': {'type': 'string', 'pattern': '^[a-z0-9._-]+$', 'maxLength': 80, 'minLength': 8, 'description': 'Optional stable node id. When set, must be 8–80 characters matching [a-z0-9._-]. Omit to receive a generated id.'}, 'product': {'type': 'string', 'description': 'Required catalog product slug (a-z0-9-, for example godlock, azmail). AnonBroadcast is refused. Unknown slugs refuse MESH-BAD-INPUT.'}, 'presence': {'enum': ['live', 'locked', 'isolated'], 'type': 'string', 'description': 'Optional rollup class. live (default), locked, or isolated. No scores. Other values refuse MESH-BAD-INPUT.'}}, 'description': 'product is required. presence must be live|locked|isolated when set. node_id must be 8–80 [a-z0-9._-]. Radios off refuses MESH-OFF. Mutation requires confirm=true or dry_run=true.', 'additionalProperties': False}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'required': ['node_id'], 'properties': {'confirm': {'type': 'boolean', 'description': 'Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation.'}, 'dry_run': {'type': 'boolean', 'description': 'Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation.'}, 'node_id': {'type': 'string', 'description': 'Required node id to drop from the rollup.'}}, 'description': 'node_id is required. Missing node_id refuses MESH-BAD-INPUT. Mutation requires confirm=true or dry_run=true.', 'additionalProperties': False}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'properties': {}, 'description': 'No arguments. Send {}.', 'additionalProperties': False}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'properties': {}, 'description': 'No arguments. Send {}. Never enables radios.', 'additionalProperties': False}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'FragGate body: ok, code, door, slug, op, engine_digest, ran_in, provenance, refusal, limitations, receipt, plus the engine result. Unknown names refuse FG-HALLUC-TOOL; stubs refuse FG-STUB.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'properties': {}, 'description': 'No arguments. Send {}.', 'additionalProperties': False}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'properties': {}, 'description': 'No required arguments. Extra keys are ignored.', 'additionalProperties': True}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'required': ['slug'], 'properties': {'slug': {'type': 'string', 'description': 'Required catalog slug from GET /v1/software or fraggate_list (for example foldlock). Alias: product. Not an exec path.'}, 'product': {'type': 'string', 'description': 'Alias of slug. Do not send two different values.'}}, 'description': 'slug or product required. Extra keys are ignored by the pull helper — not an exec payload.', 'additionalProperties': True}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'One hub product card: name, version, skill markdown, download, ops, skill_source. Unknown slug is unknown product — not a FragGate FG-HALLUC-TOOL envelope.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'required': ['slug', 'op'], 'properties': {'op': {'type': 'string', 'description': 'Required allowlisted op. Stubs refuse FG-STUB.'}, 'slug': {'type': 'string', 'description': 'Required catalog slug (or name alias). Unknown slugs refuse FG-HALLUC-TOOL.'}, 'confirm': {'type': 'boolean', 'description': 'Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation.'}, 'dry_run': {'type': 'boolean', 'description': 'Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation.'}, 'payload': {'type': 'object', 'description': 'Optional op payload object. Engine-specific.', 'additionalProperties': True}, 'session_id': {'type': 'string', 'description': 'Optional existing raw session id. If omitted, a session is opened automatically. Prefer leaving session plumbing invisible unless asked.'}}, 'description': 'slug and op are required. Extra keys other than payload/session_id may be treated as payload. Mutation requires confirm=true or dry_run=true.', 'additionalProperties': True}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'required': ['session_id'], 'properties': {'id': {'type': 'string', 'pattern': '^sess_[a-f0-9]{32}$', 'description': 'Alias of session_id. The door accepts either key; do not send two different values.'}, 'confirm': {'type': 'boolean', 'description': 'Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation.'}, 'dry_run': {'type': 'boolean', 'description': 'Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation.'}, 'session_id': {'type': 'string', 'pattern': '^sess_[a-f0-9]{32}$', 'description': 'Required. Raw session id from runtime_session_open (sess_ + 32 lowercase hex). Alias: id. Missing both fails with session_id required; unknown id returns session_not_found.'}}, 'description': 'session_id or id required. Extra keys are ignored. This is not chainlock_seal. Mutation requires confirm=true or dry_run=true.', 'additionalProperties': True}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'Close body: sealed session, close receipt, verified. Errors: session_id required, session_not_found, session_closed (already sealed; does not reopen).'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'required': ['session_id', 'slug', 'op'], 'properties': {'id': {'type': 'string', 'pattern': '^sess_[a-f0-9]{32}$', 'description': 'Alias of session_id. The door accepts either key; do not send two different values.'}, 'op': {'type': 'string', 'description': 'Required allowlisted op. Stubs refuse FG-STUB. UI aliases still forward only after FragGate admit.'}, 'slug': {'type': 'string', 'description': 'Required catalog slug to exec. Alias: product. Unknown slugs refuse FG-HALLUC-TOOL. This tool does not auto-open.'}, 'confirm': {'type': 'boolean', 'description': 'Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation.'}, 'dry_run': {'type': 'boolean', 'description': 'Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation.'}, 'outcome': {'enum': ['retry', 'failed', 'completed'], 'type': 'string', 'description': 'Optional sealed status. completed marks the attempt that finished the action. retry and failed are earlier attempts. Defaults from HTTP status when omitted.'}, 'payload': {'type': 'object', 'description': 'Optional op payload object. Engine-specific. Unlike fraggate_call, leftover top-level keys are not used as payload.', 'additionalProperties': True}, 'product': {'type': 'string', 'description': 'Alias of slug. Do not send two different values.'}, 'attempt_n': {'type': 'integer', 'minimum': 1, 'description': 'Optional 1-based attempt number. Omitted increments from the prior session receipt with the same request_id, or 1.'}, 'request_id': {'type': 'string', 'description': 'Optional logical request id shared by retries of one action. Same value across attempts. Omitted mints a new id for this exec.'}, 'session_id': {'type': 'string', 'pattern': '^sess_[a-f0-9]{32}$', 'description': 'Required. Raw session id from runtime_session_open (sess_ + 32 lowercase hex). Alias: id. Missing both fails with session_id required; unknown id returns session_not_found.'}, 'correlation_id': {'type': 'string', 'nullable': True, 'description': 'Optional client correlation id. Sealed on the session receipt. Null when omitted.'}, 'parent_receipt_id': {'type': 'string', 'nullable': True, 'description': 'Optional prior attempt receipt hash. Null on the first attempt. Omitted links to the prior session receipt with the same request_id. Not FragGate ledger prev.'}}, 'description': 'session_id (or id), slug, and op are required. Extra keys besides payload are not treated as the op payload. Mutation requires confirm=true or dry_run=true.', 'additionalProperties': True}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'Exec body: session, receipt, engine_slug, engine_op, engine_digest, ran_in, refusal when gated. Errors: session_id required, session_closed, session_expired, receipt_cap, FG-HALLUC-TOOL, FG-STUB.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'properties': {'id': {'type': 'string', 'pattern': '^sess_[a-f0-9]{32}$', 'description': 'Optional caller-chosen session id. Must already match sess_ + 32 lowercase hex or the open refuses bad_session_id. Omit to mint one.'}, 'source': {'type': 'string', 'description': 'Optional open metadata label. Default worker. Not a permission and not a catalog slug.'}, 'confirm': {'type': 'boolean', 'description': 'Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation.'}, 'dry_run': {'type': 'boolean', 'description': 'Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation.'}}, 'description': 'No required arguments. Empty {} mints a sess_ + 32 hex id. Extra keys may be stored as open metadata. Mutation requires confirm=true or dry_run=true.', 'additionalProperties': True}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'Open body: session.id, receipts[0], already=true when the id already exists. Errors: bad_session_id, session_binding_missing, session_expired.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'required': ['session_id'], 'properties': {'id': {'type': 'string', 'pattern': '^sess_[a-f0-9]{32}$', 'description': 'Alias of session_id. The door accepts either key; do not send two different values.'}, 'confirm': {'type': 'boolean', 'description': 'Documented confirmation flag. Optional in inputSchema.required (connector refresh must not break). tools/call still refuses MCP-CONFIRM-REQUIRED when confirm is missing or false unless dry_run=true. confirm is consent to run the call. It is not tenant auth and it does not upgrade shared public-demo isolation.'}, 'dry_run': {'type': 'boolean', 'description': 'Optional preview flag. When true, do not write and do not stamp a ledger tip. Allowlist, hallucination, stub, and local-only checks still run and return the same FragGate refuse code a confirm call would get. MCP-DRY-RUN is returned only when that call would have been allowed to proceed. confirm is consent, not tenant auth, and it does not upgrade shared public-demo isolation.'}, 'allow_ops': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Optional replacement allowlist of ops this session may exec. Omit to keep the current list.'}, 'session_id': {'type': 'string', 'pattern': '^sess_[a-f0-9]{32}$', 'description': 'Required. Raw session id from runtime_session_open (sess_ + 32 lowercase hex). Alias: id. Missing both fails with session_id required; unknown id returns session_not_found.'}, 'allow_slugs': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Optional replacement allowlist of catalog slugs this session may exec. Omit to keep the current list.'}, 'kv_increment': {'type': 'boolean', 'description': 'Optional. When true, allow KV increment side effects on later exec. Not an increment itself.'}, 'max_payload_bytes': {'type': 'integer', 'maximum': 1048576, 'minimum': 1, 'description': 'Optional max payload size in bytes for later exec (integer 1..1048576). Overlay only; not the exec body. Out of range refuses bad_policy.'}}, 'description': 'session_id or id required. Other fields are optional policy overlays (also accepted nested under policy). Mutation requires confirm=true or dry_run=true.', 'additionalProperties': True}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'Policy body: updated session allow lists and a policy receipt. Refuses session_id required, session_not_found, session_closed, session_expired.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'required': ['session_id'], 'properties': {'id': {'type': 'string', 'pattern': '^sess_[a-f0-9]{32}$', 'description': 'Alias of session_id. The door accepts either key; do not send two different values.'}, 'session_id': {'type': 'string', 'pattern': '^sess_[a-f0-9]{32}$', 'description': 'Required. Raw session id from runtime_session_open (sess_ + 32 lowercase hex). Alias: id. Missing both fails with session_id required; unknown id returns session_not_found.'}}, 'description': 'session_id or id required. Extra keys are ignored.', 'additionalProperties': True}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'Last-receipt body: receipt (or null), verified chain flag, public session. Errors: session_id required, session_not_found.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'required': ['session_id'], 'properties': {'id': {'type': 'string', 'pattern': '^sess_[a-f0-9]{32}$', 'description': 'Alias of session_id. The door accepts either key; do not send two different values.'}, 'session_id': {'type': 'string', 'pattern': '^sess_[a-f0-9]{32}$', 'description': 'Required. Raw session id from runtime_session_open (sess_ + 32 lowercase hex). Alias: id. Missing both fails with session_id required; unknown id returns session_not_found.'}}, 'description': 'session_id or id required. Extra keys are ignored. No cursor/limit.', 'additionalProperties': True}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'Receipt-chain body: receipts[] (cap 64), verified, public session. Errors: session_id required, session_not_found.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'properties': {}, 'description': 'No arguments. Send {}. Returns the agent skill text.', 'additionalProperties': False}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'Machine payload. FragGate-style results commonly include ok, code, slug, op, status, engine_slug, engine_op, engine_digest, ran_in, provenance, refusal, limitations, and ledger_tip.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
输入模式
{'type': 'object', 'properties': {}, 'description': 'No arguments. Send {}. First call — pick a slug, then fraggate_call. Not exec and not fraggate_list.', 'additionalProperties': False}
输出模式
{'type': 'object', 'properties': {'code': {'type': 'string', 'description': 'FragGate or fabric code when present: FG-OK, FG-HALLUC-TOOL, FG-STUB, FG-LOCAL-ONLY, FG-UNKNOWN-OP, FG-GATE-REFUSE, FG-LAMB-REFUSE, or a module refuse such as MESH-* / AKM-*.'}, 'door': {'type': 'string', 'description': 'Door name. The public door is fraggate.'}, 'ran_in': {'type': 'string', 'description': 'Execution locale (for example aziel-runtime) when present.'}, 'result': {'description': 'Software-tab catalog JSON (products/cards with name, slug, ops, worker_home, sort lanes Plain→Gate→Lock). Not a hashed registry roster.'}, 'status': {'type': 'integer', 'description': 'HTTP-like status when present on wrappers (200 ok; 400+ error / refuse).'}, 'display': {'type': 'object', 'properties': {'next': {'type': 'string', 'description': 'What the agent should do after showing this output.'}, 'image': {'type': 'object', 'properties': {'url': {'type': 'string', 'description': 'Cited http(s) image URL when the production named one. Not invented.'}, 'data': {'type': 'string', 'description': 'Base64 image bytes copied from the production. Omitted for a URL-only cite. Never present on dry_run.'}, 'source': {'type': 'string', 'description': 'Production field the image was taken from (for example png_b64, jpeg_b64, or image_url).'}, 'mimeType': {'type': 'string', 'description': 'Sniffed image media type (image/png, image/jpeg, image/webp, or image/gif).'}, 'reviewed': {'type': 'boolean', 'description': 'True only when data came from an executed production. False for a URL cite without bytes. Never true on dry_run.'}}, 'description': 'Present only when a real production included png_b64, jpeg_b64 (or the same byte family), or a cited http(s) image URL. No invented thumbs. Omitted on dry_run. reviewed is true only when executed production bytes are attached; a dry_run never mints reviewed.', 'additionalProperties': True}, 'title': {'type': 'string', 'description': 'Product verb title for the AI client. Not a raw tool name.'}, 'action': {'type': 'string', 'description': 'Human-visible run frame. Always "Run aziel runtime". Product verb titles stay on title. Not a tool name.'}, 'fields': {'type': 'array', 'items': {'type': 'object', 'properties': {'label': {'type': 'string', 'description': 'Field label.'}, 'value': {'type': 'string', 'description': 'Field value as text.'}}, 'additionalProperties': True}, 'description': 'Optional labeled scalars copied from the result for display.'}, 'summary': {'type': 'string', 'description': 'One-line outcome or refuse reason.'}}, 'description': 'Human-facing envelope. Show display.action, title, and summary, then take the next input. Never echo raw tool names.', 'additionalProperties': True}, 'receipt': {'description': 'Optional receipt, ledger tip, or TemporalLock/ForgeReceipts exit when the door stamped one.'}, 'refusal': {'description': 'Explicit refuse object, code, or message when the door or engine refused.'}, 'engine_op': {'type': 'string', 'description': 'Resolved engine op when present (often inside result).'}, 'ledger_tip': {'description': 'Ask/refuse ledger tip when the door stamped one.'}, 'provenance': {'description': 'Provenance / input packet when the pipeline attached one.'}, 'session_id': {'type': 'string', 'description': 'Raw session id when session plumbing was used. Hidden unless the user asked for the chain.'}, 'engine_slug': {'type': 'string', 'description': 'Resolved engine slug when present (often inside result).'}, 'limitations': {'description': 'Capability limitations or Remain-OFF notes when present.'}, 'engine_digest': {'type': 'string', 'description': '64-hex engine_digest when a true in-process engine ran (often inside result).'}}, 'description': 'Display envelope shown to the user (display.action / display.title / display.summary) plus the machine result. Extra engine fields may appear. Do not echo raw tool names.', 'additionalProperties': True}
近期工具变更
类似的 MCP 服务器
hyperion
Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…
aaaa-nexus — Formally Verified AI Safety APIs
Provides formally constrained agent safety and governance APIs for tool authorization, prompt-injection-resistant execution, iden…
Sigistry Plugin & Skill Catalog
Searches verified Claude Code plugins and skills, retrieves portable skill sources, and provides MCP server security scorecards.
fetchgate
Fetches web pages as Markdown or metadata, exposes a digital-goods catalog, and scans remote MCP tool descriptions for poisoning …
AIMEAT
Provides a self-hosted agent operating system with agent work delegation, access controls, federation, hooks, SSO, security admin…
Vee3
Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…
Japan Public Ledgers MCP
Provides agent identity, memory, audit, trust, proxy, temporary email, webhook, CAPTCHA, and alerting capabilities alongside publ…
IA-QA — 130+ QA & Dev Tools for AI Agents
Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…