Agent skill

Audit Log

by sickn33 in sickn33/agentic-awesome-skills

Audit trail register: timestamp, user, module, record, action, field changed, old and new value, and the reason for the change.

MITAuto-check passed

Install Audit Log

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill audit-log -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills audit-log --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/audit-log .claude/skills/audit-log && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-log
GitHub stars
47k
Used in
1 other repo
Token cost
~3.6k tokens
SKILL.md length
1,598 words
Files
1
Skills in repo
1,354
Repo updated
First seen
Licence
MIT

At a glance

Audit trail register: timestamp, user, module, record, action, field changed, old and new value, and the reason for the change.

  • Works in 5 steps: Identify intent → Ask only what is missing → Hold the internal context → …
  • Change history and control evidence
  • SKILL.md covers Overview, When to Use This Skill, How It Works and Field Reference, plus 11 more sections
  • Reaches json-schema.org

What it does

Audit Log is an agent skill from sickn33/agentic-awesome-skills. Audit trail register: timestamp, user, module, record, action, field changed, old and new value, and the reason for the change. Use for change history and control evidence.

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Change history and control evidence

Example prompts

  • “/audit-log”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Identify intent
  2. Ask only what is missing
  3. Hold the internal context
  4. Recommend the smallest workflow
  5. Build only on request

What it can do on your machine

Read from SKILL.md and the folder at commit ec02547. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml, csv, sql, json and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • json-schema.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Log loads about 3.6k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 1,598 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit ec02547, republished under its MIT licence (© sickn33). 1,598 words, ~3,560 tokens.

Download SKILL.mdSave it as .claude/skills/audit-log/SKILL.md (or your agent's skills folder).
name
audit-log
description
Audit trail register: timestamp, user, module, record, action, field changed, old and new value, and the reason for the change. Use for change history and control evidence.
category
business
risk
safe
source
self
source_type
self
date_added
2026-09-26
author
WHOISABHISHEKADHIKARI
tags
sme, business, operations, database, csv, notion, sql, protect
source_repo
WHOISABHISHEKADHIKARI/sme-ops-system-builder

Audit Log

What it is: Compliance trail.

Overview

Works out the smallest useful Audit Log setup for the business in front of it, then builds it only when asked. The default output is a short recommendation, not a spreadsheet. Artifacts - CSV, SQL DDL, JSON Schema, Notion mapping - are produced on request, from one field list so they cannot drift apart.

Layer: Layer 7: Protect. Fits: Scale stage. Table code: n/a.

When to Use This Skill

  • audit log
  • change history tracker
  • activity log database
  • compliance trail

Also use it when the user says "compliance trail", or describes the same process happening in a spreadsheet, a document or someone inboxes.

Do not use it for: payroll calculation, tax filing, or legal advice. This skill produces empty templates only - it never holds or processes real employee or customer data.

How It Works

Follow the shared execution contract. The module-specific rules below define only domain fields, decisions, calculations, and safety constraints.

Step 1 - Identify intent

Read the request and pick the intent before asking anything.

  • "set up" or "build" or "create" -> the user wants artifacts; go to Step 2.
  • "our process is ..." or "it is in a sheet" -> the user wants to move an existing process; capture it, then Step 2.
  • "is this right" or "review" or "audit" -> the user wants a check, not a build; answer from what they share.
  • "how do I ..." -> advice question; answer directly and offer the build only if it helps.

Ask only if this is the highest-value missing fact; otherwise proceed without an opener:

Q: What do you need to be able to prove?

Step 2 - Ask only what is missing

Skip anything the user already answered, in any earlier message. Ask the rest one at a time, and stop as soon as the remaining answers would not change the output.

  • Purpose - Which decision or process? / Internal or external? / Who asks for it?
  • Events - What must be recorded? / Approvals or changes? / How far back?
  • Evidence - Who can read it? / Tamper evidence needed? / Retention period?
  • Current process - Is anything logged now? / Email or spreadsheet? / Is it complete?
  • Outcome - What do you need? / A log definition, a register or reporting?

Never invent an answer. If the user does not know, record it as unknown and carry on.

Step 3 - Hold the internal context

Hold the answers in this shape. It stays internal - it is not shown to the user unless they ask, and it never carries a value the user did not give.

yaml
module: audit-log
intent: null            # setup | advice | review | fix | build | convert | export
scale: null             # Starter | Growth | Scale, only if the answer changes it
areas:
  "Purpose": null
  "Events": null
  "Evidence": null
  "Current process": null
  "Outcome": null
requested_outputs: []   # csv | sql | json | notion | xlsx - requested formats only
confirmed_facts: []     # only what the user actually said
open_questions: []      # the unanswered ones, in the order worth asking
Step 4 - Recommend the smallest workflow

If an artifact was requested, build it after resolving essential missing facts. Otherwise give a short recommendation and offer the relevant artifact.

Recommended approach: Define the small set of events worth keeping and record who did what and when. Depth follows the question you need to answer.

Why this one: Audit logs become useless when everything is captured. Start from the question you need to answer, then record only what answers it.

Workflow: Event recorded → Actor and time → Stored → Periodically reviewed → Evidence produced

Step 5 - Build only on request

Once the user asks for it, derive the fields from the confirmed context and emit the requested artifacts. For machine-readable text, keep prose outside the data; for files, provide a usable link. Report material validation failures or limitations separately.

A selected Notion output is rendered by notion-manual-import, so route the Notion step there. When the user selects Notion, hand that step to @notion-manual-import: it holds the CSV, the property mapping, the import steps and the verification checklist, and it renders the Field Reference below instead of defining a table of its own. Do not restate the mapping here and do not improvise the import steps. Manual CSV and mapping outputs need no connection. For requested workspace changes, follow the shared contract: verify actual tool access and the target before writing. A user saying "connected" is not tool evidence. Never ask for a Notion password or token.

For an Excel-compatible CSV, use UTF-8 with a byte order mark so Excel opens the text correctly. A CSV is not an .xlsx workbook; create .xlsx only when the user requests a workbook. A CSV carries no types, so after it, name the columns that need a number, date or currency format applied.

csv
Log Entry,Date and Time,User,Module,Record,Action,Field Changed,Old Value,New Value,Reason,Log ID
Policy updated,2026-01-15 09:30,Example User,Invoices & Billing,INV-EXAMPLE-001,Update,Status,Draft,Sent,Correction made after a review query,
sql
CREATE TABLE audit_log (
  log_entry VARCHAR(255),
  date_and_time TIMESTAMP NOT NULL,
  user_account VARCHAR(255),
  module VARCHAR(255),
  record VARCHAR(255),
  action VARCHAR(255),
  field_changed VARCHAR(255),
  old_value VARCHAR(255),
  new_value VARCHAR(255),
  reason VARCHAR(255),
  log_id SERIAL PRIMARY KEY,
  created_at TIMESTAMP DEFAULT NOW(),
  updated_at TIMESTAMP DEFAULT NOW()
);
json
{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "title": "Audit Log",
  "type": "object",
  "additionalProperties": false,
  "properties": {
      "Log Entry": { "type": "string" },
      "Date and Time": { "type": "string", "format": "date-time" },
      "User": { "type": "string" },
      "Module": { "type": "string" },
      "Record": { "type": "string" },
      "Action": { "type": "string" },
      "Field Changed": { "type": "string" },
      "Old Value": { "type": "string" },
      "New Value": { "type": "string" },
      "Reason": { "type": "string" },
      "Log ID": { "type": "integer" }
  },
  "required": [
      "Date and Time"
  ]
}
markdown
| CSV column | Notion property | Set after import |
|---|---|---|
| Log Entry | Title | Use as the database title |
| Date and Time | Date (include time) | Convert to Date (include time) |
| User | Text | Leave as Text |
| Module | Text | Leave as Text |
| Record | Text | Leave as Text |
| Action | Text | Leave as Text |
| Field Changed | Text | Leave as Text |
| Old Value | Text | Leave as Text |
| New Value | Text | Leave as Text |
| Reason | Text | Leave as Text |
| Log ID | Text (preserve source ID) | Keep imported IDs as Text; optionally add a separate Unique ID property |

The rows above are documentation examples only. Emit empty templates unless the user explicitly requests examples. Money stays currency, dates stay date, and anything pointing at another table stays relation.

Field Reference

#FieldTypeSQLJSON SchemaNotionCSV example
1Log EntrytextVARCHAR(255)stringTextPolicy updated
2Date and TimedatetimeTIMESTAMPstring, format: date-timeDate (include time)2026-01-15 09:30
3UsertextVARCHAR(255)stringTextExample User
4ModuletextVARCHAR(255)stringTextInvoices & Billing
5RecordtextVARCHAR(255)stringTextINV-EXAMPLE-001
6ActiontextVARCHAR(255)stringTextUpdate
7Field ChangedtextVARCHAR(255)stringTextStatus
8Old ValuetextVARCHAR(255)stringTextDraft
9New ValuetextVARCHAR(255)stringTextSent
10ReasontextVARCHAR(255)stringTextCorrection made after a review query
11Log IDidSERIAL PRIMARY KEYintegerText (preserve source ID)(blank)

Select Options

No Select fields.

Relations

Link fields: none

Examples

Prompt

When a client questioned an approval we had nothing to show.

Context first - one question per message, nothing already answered:

Q: Which process? A: Expense approvals.

Q: Who asks? A: Our accountant, at year end.

Q: How far back? A: Three years.

Recommended next step - offered, not built:

Define the small set of events worth keeping and record who did what and when. Depth follows the question you need to answer.

Workflow: Event recorded → Actor and time → Stored → Periodically reviewed → Evidence produced

Want the CSV, SQL, JSON Schema and Notion mapping for this?

Show full SKILL.md (656 more words)Show less

Best Practices

  • Build when requested; recommend and offer a build for advice-only requests.
  • One question per message. A batched intake reads as a form and gets guessed at.
  • Keep display names identical across CSV and JSON; document normalized SQL identifiers.
  • Use relation for anything that points at another table, text only for free text.
  • Money fields are currency, never text. Dates are date, never free text.
  • If the user requests an example row, keep it obviously fake so nobody imports it as real data.

Limitations

  • Empty template only. It does not compute payroll, tax, leave balances or KPIs.
  • Notion relations need both databases imported before the link column resolves.
  • Select options are a starting set. Rename them to match how the business talks.
  • No automation, reminders or sync. Those need the integration layer.
  • Does not provide legal assurance of compliance or act as a security control on its own.
  • Legal, tax and HR review is still required before this drives real decisions.

Security & Safety Notes

  • Never fill in real names, salaries, medical or banking data. Placeholders only.
  • Label example rows as synthetic, and keep bank details masked.
  • Local reads, generation commands, and validation are part of a requested artifact build. External writes, messages, provisioning, and publication require authorization for that action and target; existing explicit authorization does not need to be repeated.
  • If sensitive data is supplied, avoid repeating unnecessary identifiers. Use only what the requested review needs; keep generated templates empty. Do not claim deletion from the conversation or service storage.
  • Privacy, legal and disciplinary cases need a qualified human reviewer before anything is acted on.

Common Pitfalls

  • Problem: a static mapping is described as a completed workspace build. Solution: deliver manual mappings without a connection; claim a live change only after the authorized tool operation succeeds.
  • Problem: asked all six questions in one message. Solution: ask one, wait, and drop any the first answer already covered.
  • Problem: built a full system when one table was asked for. Solution: build what was requested; mention the parent skill separately.
  • Problem: all four artifacts drift apart. Solution: derive all four from the field list in this file, never by hand.
  • Problem: Notion import shows every column as Text. Solution: that is expected. Apply the property mapping table once, after import.

Audit Log Review Checklist

Before treating a change record as evidence, verify the event identity, actor, timestamp, target, action, result, and correlation reference as separate values. Preserve the original event text alongside any normalized fields, record the timezone and clock source, and mark missing values as Unknown. Group related events by a stable correlation ID, but do not merge distinct actions into one summary row.

For a review export, filter by the requested time window first, then check that the export is complete, ordered deterministically, and scoped to the authorized system. Redact secrets and personal data only after retaining a reversible reference to the source record; never rewrite the underlying audit event. Record retention, deletion, clock drift, failed writes, duplicate events, and any gap in sequence as review findings rather than silently filling them.

Event Taxonomy

Use a fixed action vocabulary such as create, read, update, delete, export, approve, reject, login, permission-change, and retention-delete. Store the resource type and resource identifier separately from the human-readable label. For bulk jobs, record the job identifier, item count, start and finish, partial-failure count, and final status; one bulk event must not be mistaken for one successful change per item.

For investigations, preserve the sequence as observed, then derive a second view grouped by actor, resource, or correlation ID. Mark derived views as derived and keep the query definition with the export. A missing event is a finding only when the expected event boundary and source system are known.

  • Module Catalog - find the relevant module, then read its skill.
  • @people-directory - the employee master record most modules link to.
  • @notification-reminder-hub - turns due dates in this module into reminders.

Reusable Prompt

I want to set up compliance trail for my company.
Ask me one short question at a time, and only about what I have not already told you.
Then recommend the smallest setup that fits, and wait for me to ask before you build it.
When I ask, output CSV, SQL DDL, JSON Schema, a Notion property mapping or an Excel workbook. Data only.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/audit-log of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit ec02547

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Audit Log next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Log compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Log this skillsickn33/agentic-awesome-skills47k1 repos~3.6kAutomated safety check: PassMIT
Analyze GitHub Action Logswithastro/astro63k1 repos~1.3kAutomated safety check: PassCustom licence
Implementing Cloud Trail Log Analysismukul975/Anthropic-Cybersecurity-Skills34k—~3.4kAutomated safety check: PassApache-2.0
Recordingcodewhale-hq/Codewhale41k—~540Automated safety check: PassMIT
ActionsJetBrains/intellij-community21k—~341Automated safety check: PassCustom licence
Browser Recordruvnet/ruflo74k—~735Automated safety check: NotesMIT

Similar skills

  • Official

    Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.

    63k GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed
  • Implementing Cloud Trail Log Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Implementing AWS CloudTrail log analysis for security monitoring, threat detection, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration to identify unauthorized…

    34k GitHub stars~3.4k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Recording

    codewhale-hq/Codewhale

    Capture screenshots on registered computers, record on macOS or HarmonyOS, and manage saved captures.

    41k GitHub stars~540 tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Actions

    JetBrains/intellij-community

    Official

    Implement or change IntelliJ AnAction actions and registrations.

    21k GitHub stars~341 tokensUpdated yesterday
    MobileAuto-check passed
  • Browser Record

    ruvnet/ruflo

    Open a named, traced browser session into an RVF cognitive container with a ruvector trajectory recording every action

    74k GitHub stars~735 tokensUpdated today
    Agent WorkflowsAuto-check: notes
  • Growth Log

    affaan-m/ECC

    Write growth log entries that extract reusable patterns from completed work — root cause, transferable rule, and a recognizable signal — instead of diary-style event narration, with a 4-8 sentence…

    275k GitHub starsUsed in 1 repo~1.7k tokens
    DevelopmentAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,354 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed
  • Content Creator

    sickn33/agentic-awesome-skills

    Drafts and reviews audience-specific content from supplied brand examples, with local scripts for brand voice and SEO diagnostics, channel templates and a content calendar.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed

Questions about Audit Log

What does Audit Log do?

Audit trail register: timestamp, user, module, record, action, field changed, old and new value, and the reason for the change. Audit Log is an agent skill from sickn33/agentic-awesome-skills. Audit trail register: timestamp, user, module, record, action, field changed, old and new value, and the reason for the change.

When should I use Audit Log?

Audit Log fits situations like: change history and control evidence.

How do I install Audit Log in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill audit-log -a claude-code`. Or copy the skill folder (skills/audit-log in sickn33/agentic-awesome-skills) into .claude/skills/audit-log in your project. Claude Code loads it when a task matches its description.

How do I install Audit Log in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill audit-log -a codex`. Or copy the skill folder (skills/audit-log in sickn33/agentic-awesome-skills) into .agents/skills/audit-log in your project. Codex loads it when a task matches its description.

Can I use Audit Log in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill audit-log -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-log, .gemini/skills/audit-log, .github/skills/audit-log and .opencode/skills/audit-log in your project.

What does Audit Log need to run?

SKILL.md names no scripts, command-line tools or credentials: Audit Log is instructions for the agent only.

Does Audit Log access the network?

SKILL.md names 1 domain. In commands or code: json-schema.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Audit Log safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Log use?

Audit Log is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Log use?

About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Log?

Skills that share tags, products or a category with Audit Log: Analyze GitHub Action Logs (withastro/astro, 63k stars), Implementing Cloud Trail Log Analysis (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Recording (codewhale-hq/Codewhale, 41k stars) and Actions (JetBrains/intellij-community, 21k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Log?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,343 GitHub stars. The repository holds 1,354 skills in this directory. The repository was last updated on October 7, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.