Metadata-Version: 2.5
Name: crewai-alex-evidence
Version: 0.1.0
Summary: Verify signed ALEX evidence bundles as a CrewAI tool. Thin adapter, no second verifier.
Project-URL: Homepage, https://alexproof.de/langchain
Project-URL: Documentation, https://alexproof.de/langchain
Author: Bewusst.Ki
License: Copyright 2026 Bewusst.Ki
        
        Licensed under the Apache License, Version 2.0 (the "License");
        you may not use this file except in compliance with the License.
        You may obtain a copy of the License at
        
            http://www.apache.org/licenses/LICENSE-2.0
        
        Unless required by applicable law or agreed to in writing, software
        distributed under the License is distributed on an "AS IS" BASIS,
        WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
        See the License for the specific language governing permissions and
        limitations under the License.
License-File: LICENSE
Classifier: Development Status :: 3 - Alpha
Classifier: Intended Audience :: Developers
Classifier: License :: OSI Approved :: Apache Software License
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.10
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Python :: 3.13
Requires-Python: >=3.10
Requires-Dist: crewai>=0.80
Requires-Dist: langchain-alex<0.2,>=0.1.1
Provides-Extra: dev
Requires-Dist: build>=1.2.2; extra == 'dev'
Requires-Dist: pytest>=8.3; extra == 'dev'
Requires-Dist: ruff>=0.11; extra == 'dev'
Description-Content-Type: text/markdown

# crewai-alex-evidence

Verify signed ALEX Evidence Packages as a CrewAI tool. This is a thin adapter around the same
independent verifier that [`langchain-alex`](https://pypi.org/project/langchain-alex/) exposes as
a LangChain tool and [`alex-evidence-verify-mcp`](https://pypi.org/project/alex-evidence-verify-mcp/)
exposes as an MCP tool — no second verification algorithm is maintained here.

The tool returns one of three verdicts, never a bare true/false:

- `VERIFIED` — signature, schema, and declared outcome all passed. This means the bundle matches
  the formal contract, **not** that the underlying work is correct.
- `FAILED` — a real integrity or structure problem: wrong trust anchor, tampered signature,
  unsupported schema, missing required attestation.
- `INCONCLUSIVE` — the bundle is authentically signed and structurally valid, but it honestly
  declares a non-success outcome (e.g. the underlying task was never completed or had no CI).
  This is deliberately not folded into `FAILED`: a correctly-signed admission of "inconclusive" is
  not the same failure mode as a broken signature.

## Requirements

- Python 3.10 or newer
- OpenSSL available as `openssl` on `PATH`

## Install

```bash
pip install crewai-alex-evidence
```

For development, install from source inside this repository instead:

```bash
pip install -e packages/crewai-alex-evidence
```

## See all three verdicts without writing any code

```bash
crewai-alex-evidence-demo
```

Runs the tool against three bundled example evidence packages (shipped with the package, no
network access, no access to this repository needed) and prints the real `VERIFIED`, `FAILED`,
and `INCONCLUSIVE` verdicts. The keys under `src/crewai_alex_evidence/examples/keys/*.TEST-KEY.pem`
are public test keys for this demo only — never a real ALEX production trust anchor. Source for
the demo: `src/crewai_alex_evidence/examples/run_verdicts.py`.

## Use in a crew

```python
from crewai import Agent, Task
from crewai_alex_evidence import AlexEvidenceVerifyTool

verify_tool = AlexEvidenceVerifyTool()

agent = Agent(
    role="Evidence Auditor",
    goal="Verify evidence packages before any decision relies on them",
    tools=[verify_tool],
)
```

The agent calls the tool with a path to the evidence bundle and a path to the trust anchor public
key — both supplied by the caller, never read from an environment variable or taken from inside
the bundle under test. A public key embedded only in the bundle itself is never trusted.

## Development

```bash
python -m pip install -e ".[dev]"
python -m pytest
ruff check .
python -m build
```

The verifier implementation lives in `langchain-alex` (`langchain_alex._verifier`). This package
adds a `crewai.tools.BaseTool` wrapper only.
