開発者ガイド

エージェント・マンデートを作成して検証する

マンデートが境界を表すのは、有効な強制フィールドを通じてのみです。無効なマンデートでは、すべての行為チェックが error を返します。

テンプレートから始める

このファイルサンドボックスの項目は、 public/try.1.jsに埋め込まれたテンプレートそのものです。第 1 条項は機微なプレフィックスを拒否し、第 2 条項は 1 つのワークスペース・プレフィックス配下でファイルの読み書きを許可し、デフォルトでは一致しないものをすべて拒否します。

  {
    "name": "file-sandbox",
    "title": "File sandbox",
    "description": "Deny sensitive directories and permit reads and writes under one bounded directory.",
    "mandate": {
      "schema_version": "0.2-draft",
      "mandate_id": "template-file-sandbox",
      "purpose": "Confine file reads and writes to one working directory.",
      "default": "deny",
      "clauses": [
        { "id": "deny-sensitive", "effect": "deny", "match": { "kind": ["file"], "target_prefix": ["~/.ssh/", "/etc/"] } },
        { "id": "permit-workspace", "effect": "permit", "match": { "kind": ["file"], "verb": ["read", "write"], "target_prefix": ["/workspace/project/"] } }
      ]
    },
    "action": {
      "schema_version": "0.1-draft",
      "requested_by": { "agent": "template-agent" },
      "operation": { "kind": "file", "verb": "write", "target": "/workspace/project/report.txt" },
      "justification": "Write the report inside the bounded workspace."
    },
    "outcome": "permit"
  },

追跡用のマンデート識別子を変更し、意図する権限に合わせて強制フィールドを変更します。purpose、note、justification は説明文であり、行為を制限することはありません。制限するのは条項の一致フィールド、 not_valid_after、 requires_human、および default だけです。最初に一致した条項が判断を決めるため、狭い拒否を広い許可より前に置いてください。マンデートに秘密、個人データ、または機密ポリシーを入れないでください。

マンデートを検証する

フォームは public/try.1.jsのこの検証フローをそのまま使用します。MCP を初期化し、 validate_mandateを呼び出し、構造化コンテンツまたはテキストのフォールバックを受け入れます。

export async function validateMandate(mandateText, fetchImpl = fetch) {
  const mandate = parseDocument(mandateText, "mandate");
  const initialized = await postJson(MCP_URL, {
    jsonrpc: "2.0",
    id: 1,
    method: "initialize",
    params: {
      protocolVersion: "2025-11-25",
      capabilities: {},
      clientInfo: { name: "hanria.ai-try-it", version: "1" }
    }
  }, fetchImpl);
  if (initialized.error) throw new Error(initialized.error.message || "initialize failed", { cause: "response" });
  const called = await postJson(MCP_URL, {
    jsonrpc: "2.0",
    id: 2,
    method: "tools/call",
    params: { name: "validate_mandate", arguments: { mandate } }
  }, fetchImpl);
  if (called.error) throw new Error(called.error.message || "validate_mandate failed", { cause: "response" });
  const structured = called.result?.structuredContent;
  if (structured && typeof structured === "object") return structured;
  const text = called.result?.content?.find((item) => item.type === "text")?.text;
  if (typeof text === "string") {
    try {
      return JSON.parse(text);
    } catch {
      throw new Error("invalid validate_mandate result", { cause: "response" });
    }
  }
  throw new Error("missing validate_mandate result", { cause: "response" });
}

実行する

  1. フォームを開く

    試用フォーム に移動し、「File sandbox」を選択します。

  2. マンデートを編集する

    例の識別子と境界を、意図する構造化された制限に置き換えます。

  3. 検証のみ

    マンデートのみ検証を選択します。結果が valid: true なら、検証器が文書を受け入れたことを意味します。結果が valid: false なら、検証上の問題が示されます。マンデートを使用する前に修正してください。

  4. 行為をチェックする

    代表的な行為にマンデートを使用し、結果、判断を決めた条項、署名付きレシートを確認します。

すべての結果を処理する

行為チェックは permit、 deny、または escalate を、判断を決めた条項および署名付きレシートとともに返します。チェックは助言的であり、行為を拒否するのは統合です。ホスト型チェックはリクエストをメモリ内で評価し、リクエスト内容を保持しません。

無効なマンデートでは、すべての行為チェックが errorを返します。統合はこれを deny として扱わなければなりません。無効なマンデートは境界を表しません。検証によってマンデートが強制境界に変わることもありません。

参照

チェックを試す · 署名付きレシートを検証する · OpenAPI 文書 · エージェント向け要約