dev.zambo/zambo

Zambo

Trust Layer for AI work. Give your AI hands. Every run returns a verifiable receipt. No key needed.

4.1.0
Version
remote
Transport
19
Tools

Security review

Review passed

Reviewed 1d ago.

  • tools: 19 tools scanned
  • metadata: scanned

No findings.

Tools (19)

  • zambo_universal

    Universal Zambo entry point for routing natural-language requests across supported Zambo tools through one MCP connection. Covers strategy, code audits, lead generation, wallet intelligence, provenance certificates, swarm coordination, and live market data. Returns a route, execution state, downstream tool results when available, and receipt information.

  • new_session

    Starts fresh session context and returns a new session_id. Reuse that ID on subsequent calls for continuity; changing or omitting it starts clean context.

  • continuity_get_recent

    Reads only the private receipt timeline for the supplied job or thread ID. Returns receipt links, has_more, and a cursor for the next page. Use since to filter by an inclusive RFC3339 timestamp. Optional AI client labels are self-reported, not verified.

  • continuity_list_threads

    Lists named threads owned by the supplied job ID. Thread IDs can be used as _session_id by another AI client.

  • continuity_open_thread

    Opens a named thread or thread ID and returns only events with stored Zambo receipts, including links to open and check each receipt.

  • continuity_start_thread

    Creates or reuses a named thread under an existing job ID. Pass the returned thread_id as _session_id to append work from another AI client.

  • continuity_set_prefs

    Changes whether future successful calls are captured in the private timeline. It does not remove or hide public receipts already created.

  • journal_log

    Free anonymous or authenticated append-only log for an action performed outside Zambo. The entry is recorded as an agent-reported claim; Zambo does not claim it ran or observed the action. Limited to 20 calls per IP per day on the free tier.

  • live_price

    Real-time cryptocurrency price lookup for supported coins. Uses CoinGecko first, Coinbase as a secondary no-key provider, then the most recent cached verified value with its age if both live providers are unavailable. Returns live USD price, 24-hour percentage change, and market capitalization when verified.

  • pdf_extract

    Fetch and extract text content from any public URL - PDF documents, web pages, articles, docs. Returns the extracted text, word count, and a summary. Works on research papers, contracts, articles, reports. Use when user says 'read this PDF', 'extract from this URL', 'summarize this document', 'what does this say'.

  • leadsignal

    AI lead generation for contractors and local service businesses. Accepts a trade type and city. Returns qualified local leads with available contact information.

  • provibe_audit

    AI code audit for a public GitHub repository. Returns a Provibe score from 0 to 100, security vulnerabilities, a dead-code map, and an execution plan for addressing the findings.

  • ghost_audit_site

    Achilles 10-stage audit for a website. Returns SEO gaps, AI discoverability issues, conversion leaks, brand-presence gaps, competitor intelligence, a score from 0 to 100, stage findings, an audit ID, a live stream URL, and a report URL.

  • ghost_audit_status

    Status report for a Ghost Audit identified by audit_id. Returns whether the audit is running or complete, along with elapsed-time information and report availability.

  • ghost_audit_report

    Full markdown report for a completed Ghost Audit. Returns the Achilles 10-stage score, severity-ranked findings, stage analysis, and recommended fixes.

  • credithunt

    Live verified index of AI and cloud startup credit programs. Accepts optional stack, stage, and minimum value filters. Returns count, updated_at, opportunities, and api.

  • prompt_shield

    Detection and analysis of prompt injection, jailbreak, and policy-bypass attempts. Returns an injection risk score, a safe/review/block recommendation, attack indicators, and a safe rewritten version when available.

  • day_pass_activate

    Agent-native access activation endpoint. Accepts an optional payment envelope or existing access key and returns a payment challenge or verified activation result. Activation results include receipt URL, run ID, access key, expiration, usage guidance, and a spend receipt. Activation occurs only after a verified transfer.

  • capability_search

    Search across the supported Zambo tool catalog for a use case. Returns relevant tools with relevance scores, descriptions, taglines, and callable API endpoints.