All skills
wshobson avatar

/signed-audit-trails-recipe

@8b957cd
by Seth Hobsonwshobson/agents40k stars
4,281

Step-by-step cookbook for setting up cryptographically signed audit trails on Claude Code tool calls. Use when explaining, evaluating, or demonstrating the pattern before committing to the protect-mcp runtime hooks. Covers Cedar policy, Ed25519 receipts, offline verification, tamper detection, CI/CD integration, and SLSA composition.

Use this Skill: https://skilld.dev/gh/wshobson/agents/signed-audit-trails-recipe

This session only. Nothing lands on disk.

referenceshook-wiring.md

≈345 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Hook wiring for the signed audit trail recipe

The protect-mcp plugin registers both hooks for Step 1 of the recipe in its hooks/hooks.json. Installing the plugin adds them, so you do not need to edit .claude/settings.json.

{
  "hooks": {
    "PreToolUse": [
      { "matcher": ".*", "hooks": [{ "type": "command", "command": "\"${CLAUDE_PLUGIN_ROOT}\"/hooks/evaluate.sh" }] }
    ],
    "PostToolUse": [
      { "matcher": ".*", "hooks": [{ "type": "command", "command": "\"${CLAUDE_PLUGIN_ROOT}\"/hooks/sign.sh" }] }
    ]
  }
}

Claude Code sends each hook event to the command as JSON on stdin, and it does not set TOOL_NAME or TOOL_INPUT variables. Each script reads the JSON with node and passes the fields to protect-mcp as flags:

  • evaluate.sh reads tool_name and tool_input, and it runs protect-mcp@0.7.4 evaluate --policy ./protect.cedar --tool <name> --input <json>. Exit 0 allows the call, and exit 2 blocks it. If the evaluator cannot run, the script also exits 2, so the call is blocked.
  • sign.sh reads tool_name, and it runs protect-mcp@0.7.4 sign --tool <name> --receipts ./receipts/ --key ./protect-mcp.key. The 0.7.4 signer records only the tool name, and it appends each receipt to ./receipts/receipts.jsonl.

Set PROTECT_MCP_POLICY, PROTECT_MCP_RECEIPTS, or PROTECT_MCP_KEY to change these paths.

Source: SKILL.md on GitHub

No alerts4d3 checks · Risk SAFE
  • Gen Agent Trust Hub4d

    The skill is a comprehensive guide for implementing cryptographically signed audit trails and policy-based governance for AI agent tool calls. It follows security best practices, including input validation and proper secret management, and utilizes well-known package registries for its tooling.

  • Socket4d

    No alerts

  • Snyk4d

    Risk: LOW · No issues

Signed by skilld at 8b957cd. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 5 days ago

README badge

README badge for wshobson/agents/signed-audit-trails-recipe