← Files Completion ReceiptARCHIVED FILE

receipt.schema.json

8.16 KB · Sep 30, 2026 · 23:15 UTC

↓ Download file

{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "$id": "https://github.com/SpannDaMan/agent-shipproof/blob/main/plugins/agent-shipproof/receipt.schema.json",
  "title": "Completion Receipt",
  "type": "object",
  "additionalProperties": false,
  "required": [
    "schema_version",
    "tool",
    "artifact_name",
    "claim_boundary",
    "captured_at_utc",
    "root",
    "claims",
    "command",
    "selection",
    "artifacts",
    "git",
    "observed_evidence",
    "integrity"
  ],
  "properties": {
    "schema_version": {"const": "1.0"},
    "tool": {
      "const": {"name": "agent-shipproof", "version": "0.1.5"}
    },
    "artifact_name": {"const": "Completion Receipt"},
    "claim_boundary": {
      "const": "Binds declared claims to observed local evidence; does not guarantee correctness, security, authenticity, authorship, authorization, or sandboxing."
    },
    "captured_at_utc": {"type": "string", "format": "date-time"},
    "root": {"const": "."},
    "claims": {
      "type": "array",
      "minItems": 1,
      "items": {
        "type": "object",
        "additionalProperties": false,
        "required": ["text", "status"],
        "properties": {
          "text": {"type": "string", "minLength": 1},
          "status": {"const": "declared_not_semantically_verified"}
        }
      }
    },
    "command": {
      "type": "object",
      "additionalProperties": false,
      "required": [
        "argv_display",
        "argv_sha256",
        "shell",
        "exit_code",
        "timed_out",
        "output_limit_exceeded",
        "output_limit_bytes",
        "duration_ms",
        "stdout",
        "stderr"
      ],
      "properties": {
        "argv_display": {
          "type": "array",
          "minItems": 1,
          "items": {"type": "string"}
        },
        "argv_sha256": {"$ref": "#/$defs/sha256"},
        "shell": {"const": false},
        "exit_code": {"type": "integer"},
        "timed_out": {"type": "boolean"},
        "output_limit_exceeded": {"type": "boolean"},
        "output_limit_bytes": {"type": "integer", "minimum": 1024, "maximum": 1000000000},
        "duration_ms": {"type": "integer", "minimum": 0},
        "stdout": {"$ref": "#/$defs/stream"},
        "stderr": {"$ref": "#/$defs/stream"}
      },
      "allOf": [
        {
          "if": {"properties": {"timed_out": {"const": true}}, "required": ["timed_out"]},
          "then": {"properties": {"exit_code": {"const": 124}, "output_limit_exceeded": {"const": false}}}
        },
        {
          "if": {"properties": {"output_limit_exceeded": {"const": true}}, "required": ["output_limit_exceeded"]},
          "then": {"properties": {"exit_code": {"const": 125}, "timed_out": {"const": false}}}
        }
      ]
    },
    "selection": {
      "type": "object",
      "additionalProperties": false,
      "required": ["includes", "excludes", "symlinks_followed"],
      "properties": {
        "includes": {
          "type": "array",
          "minItems": 1,
          "uniqueItems": true,
          "items": {"$ref": "#/$defs/relativePattern"}
        },
        "excludes": {
          "type": "array",
          "uniqueItems": true,
          "items": {"$ref": "#/$defs/relativePattern"}
        },
        "symlinks_followed": {"const": false}
      }
    },
    "artifacts": {
      "type": "array",
      "items": {
        "type": "object",
        "additionalProperties": false,
        "required": ["path", "bytes", "sha256"],
        "properties": {
          "path": {"$ref": "#/$defs/relativePath"},
          "bytes": {"type": "integer", "minimum": 0},
          "sha256": {"$ref": "#/$defs/sha256"}
        }
      }
    },
    "git": {
      "oneOf": [
        {
          "type": "object",
          "additionalProperties": false,
          "required": ["available"],
          "properties": {"available": {"const": false}}
        },
        {
          "type": "object",
          "additionalProperties": false,
          "required": ["available", "head", "branch", "status_sha256", "dirty_entry_count", "network_used"],
          "properties": {
            "available": {"const": true},
            "head": {"type": "string", "pattern": "^(?:[0-9a-f]{40}|[0-9a-f]{64})$"},
            "branch": {"type": "string", "minLength": 1},
            "status_sha256": {"$ref": "#/$defs/sha256"},
            "dirty_entry_count": {"type": "integer", "minimum": 0},
            "network_used": {"const": false}
          }
        }
      ]
    },
    "observed_evidence": {
      "type": "object",
      "additionalProperties": false,
      "required": ["contract", "command", "artifacts", "git", "environment", "omissions", "provenance", "claim_boundary"],
      "properties": {
        "contract": {"const": "observed-evidence-envelope-v1"},
        "command": {
          "type": "object",
          "additionalProperties": false,
          "required": ["argv_sha256", "exit_code", "timed_out", "output_limit_exceeded", "stdout_sha256", "stderr_sha256"],
          "properties": {
            "argv_sha256": {"$ref": "#/$defs/sha256"},
            "exit_code": {"type": "integer"},
            "timed_out": {"type": "boolean"},
            "output_limit_exceeded": {"type": "boolean"},
            "stdout_sha256": {"$ref": "#/$defs/sha256"},
            "stderr_sha256": {"$ref": "#/$defs/sha256"}
          }
        },
        "artifacts": {"$ref": "#/properties/artifacts"},
        "git": {"$ref": "#/properties/git"},
        "environment": {
          "type": "object",
          "additionalProperties": false,
          "required": ["cwd", "os_family", "python", "environment_variables_captured"],
          "properties": {
            "cwd": {"const": "."},
            "os_family": {"enum": ["nt", "posix"]},
            "python": {"type": "string", "pattern": "^[0-9]+\\.[0-9]+$"},
            "environment_variables_captured": {"const": false}
          }
        },
        "omissions": {"type": "array", "minItems": 1, "uniqueItems": true, "items": {"type": "string", "minLength": 1}},
        "provenance": {
          "type": "object",
          "additionalProperties": false,
          "required": ["root", "selection_sha256", "artifact_manifest_sha256", "git_observation_sha256"],
          "properties": {
            "root": {"const": "."},
            "selection_sha256": {"$ref": "#/$defs/sha256"},
            "artifact_manifest_sha256": {"$ref": "#/$defs/sha256"},
            "git_observation_sha256": {"$ref": "#/$defs/sha256"}
          }
        },
        "claim_boundary": {"const": "Records selected observations and explicit omissions only; it does not prove correctness, security, identity, authorization, certification, or sandboxing."}
      }
    },
    "integrity": {
      "type": "object",
      "additionalProperties": false,
      "required": ["payload_sha256", "authentication"],
      "properties": {
        "payload_sha256": {"$ref": "#/$defs/sha256"},
        "authentication": {
          "oneOf": [
            {"type": "null"},
            {
              "type": "object",
              "additionalProperties": false,
              "required": ["type", "key_id", "tag", "claim_boundary"],
              "properties": {
                "type": {"const": "pilot_hmac_sha256"},
                "key_id": {"type": "string", "minLength": 1},
                "tag": {"$ref": "#/$defs/sha256"},
                "claim_boundary": {
                  "const": "Shared-secret tamper authentication only; not a public-key signature, identity proof, or attestation."
                }
              }
            }
          ]
        }
      }
    }
  },
  "$defs": {
    "sha256": {"type": "string", "pattern": "^[0-9a-f]{64}$"},
    "stream": {
      "type": "object",
      "additionalProperties": false,
      "required": ["bytes", "sha256", "excerpt"],
      "properties": {
        "bytes": {"type": "integer", "minimum": 0},
        "sha256": {"$ref": "#/$defs/sha256"},
        "excerpt": {"type": "string"}
      }
    },
    "relativePattern": {
      "type": "string",
      "minLength": 1,
      "pattern": "^(?!/)(?![A-Za-z]:)(?!.*(?:^|/)\\.\\.(?:/|$)).+$"
    },
    "relativePath": {
      "type": "string",
      "minLength": 1,
      "pattern": "^(?!/)(?![A-Za-z]:)(?!.*(?:^|/)\\.\\.(?:/|$))[^*?\\[\\]\\\\]+$"
    }
  }
}

SHA-256: 4c77d97cdd8a3d12ac011b08b0f45453caf0400093b5699a14d5f338fb081d4a