---
name: receiz
description: Create and verify Receiz proof objects and use the connected nonfinancial Receiz tools with device-held identity and explicit user consent.
---

# Receiz tools

Use the connection's actual tool list and input schemas. Only claim success from
returned tool results. A capability description is not evidence that a tool is
available or that an action ran.

## Get started

- Use `receiz_capabilities` with `action: "describe"` to explain capabilities.
- For local execution, use `receiz_offline_seal_status` to check readiness.
- Use only files and operations the user selects or authorizes.
- If a tool or its required host is unavailable, explain the missing requirement.

## Create and verify proof objects

For a local file, propose the input and a new unique `.receized` output path.
Preserve the original and never overwrite an existing artifact without explicit
authorization. Use `receiz_offline_seal_file`, then independently verify the exact
saved output with `receiz_offline_verify_file`. Report creation and verification
separately. Inspection or a file hash alone is not artifact verification.

For an attachment, use the original platform-provided file reference only when
the connected tool supports it. Never invent URLs or substitute a screenshot,
summary or transcription for the user's original. Do not call device paths
download links. Report delivery only when a supported file delivery succeeds.

## Identity and consent

Keep private keys, passphrases, recovery files and access tokens out of chat and
tool arguments. Users configure identity custody privately on their device.
Use the admitted identity; do not silently create a replacement after an error.
For operations requiring a preview and confirmation, show the exact preview and
wait for the user's confirmation before execution. Creating an AI subject does
not make it the user's identity or publish it publicly.

## Scope and evidence

This connection uses `marketplace-nonfinancial`. Financial transfers, Settlement,
Reserve transaction planning and trading are outside its scope. Do not change
profiles, invoke the SDK directly, or route through another executor to bypass
an unavailable action. Use the connected tools for supported nonfinancial work.

Sealed source objects and verified history remain authoritative. AI answers are
interpretations and cannot rewrite their sources. Installation does not grant
automatic access to Receiz Mind memory or private AI conversations. Ask the user
to select what they want to share through a supported path. Mind desktop
observation crystals and MCP intelligence-source crystals have distinct readers;
do not assume one reader accepts the other format.

When a device request returns a pending attempt locator, inspect that attempt
instead of repeating the action. A timeout is an unknown outcome, not proof of
zero writes. Preserve existing identity, artifacts and history on failure.
