All skills
wshobson avatar

/signed-audit-trails-recipe

@8b957cd
by Seth Hobsonwshobson/agents40k stars
4,281

Step-by-step cookbook for setting up cryptographically signed audit trails on Claude Code tool calls. Use when explaining, evaluating, or demonstrating the pattern before committing to the protect-mcp runtime hooks. Covers Cedar policy, Ed25519 receipts, offline verification, tamper detection, CI/CD integration, and SLSA composition.

Use this Skill: https://skilld.dev/gh/wshobson/agents/signed-audit-trails-recipe

This session only. Nothing lands on disk.

referencesreceipt-format.md

≈317 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Receipt format written by protect-mcp 0.7.4

The recipe's sign.sh hook runs protect-mcp@0.7.4 sign, which appends one receipt per line to ./receipts/receipts.jsonl. Each line is a v2 envelope like this one:

{
  "v": 2,
  "type": "decision_receipt",
  "algorithm": "ed25519",
  "kid": "generated",
  "issuer": "protect-mcp",
  "issued_at": "2026-09-26T12:59:48.265Z",
  "payload": {
    "tool": "Read",
    "decision": "allow",
    "reason_code": "post_execution_receipt",
    "policy_digest": "none",
    "scope": "tu-1790427588265-c8x5",
    "mode": "enforce",
    "request_id": "tu-1790427588265-c8x5",
    "spec": "draft-farley-acta-signed-receipts-01",
    "issuer_certification": "self-signed"
  },
  "signature": "0b5d28f45db30666c6addbc6e417e4825104b04b..."
}

The receipt records the tool name, and it does not record the tool input or output. Changing any signed field after signing, such as issued_at, issuer, or payload.decision, makes verification fail.

The receipt holds no public key. The verifier needs the publicKey value from ./protect-mcp.key, which you pass with --key.

The receipts also carry no hash of the previous receipt. The verifier checks each signature, so it cannot detect a deleted or reordered line.

Source: SKILL.md on GitHub

No alerts4d3 checks · Risk SAFE
  • Gen Agent Trust Hub4d

    The skill is a comprehensive guide for implementing cryptographically signed audit trails and policy-based governance for AI agent tool calls. It follows security best practices, including input validation and proper secret management, and utilizes well-known package registries for its tooling.

  • Socket4d

    No alerts

  • Snyk4d

    Risk: LOW · No issues

Signed by skilld at 8b957cd. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 5 days ago

README badge

README badge for wshobson/agents/signed-audit-trails-recipe