Agent skill

Signed Audit Trails Recipe

by wshobson in wshobson/agents

Step-by-step cookbook for setting up cryptographically signed audit trails on Claude Code tool calls.

MITAuto-check passedDevOps & Cloud

Install Signed Audit Trails Recipe

skills CLI
$ npx skills add wshobson/agents --skill signed-audit-trails-recipe -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install wshobson/agents signed-audit-trails-recipe --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/signed-audit-trails/skills/signed-audit-trails-recipe .claude/skills/signed-audit-trails-recipe && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
signed-audit-trails-recipe
GitHub stars
40k
Token cost
~2.5k tokens
SKILL.md length
1,003 words
Files
5 (incl. references)
Skills in repo
142
Repo updated
First seen
Licence
MIT

At a glance

Step-by-step cookbook for setting up cryptographically signed audit trails on Claude Code tool calls.

  • Works in 6 steps: Install the hook configuration → Write a Cedar policy → Use Claude Code normally → …
  • Demonstrating the pattern before committing to the protect-mcp runtime hooks
  • SKILL.md covers What this gives you, When to use the pattern, Step 1: Install the hook… and Step 2: Write a Cedar policy, plus 11 more sections
  • Calls npx, npm and python3; reaches veritasacta.com

What it does

Signed Audit Trails Recipe is an agent skill from wshobson/agents. Step-by-step cookbook for setting up cryptographically signed audit trails on Claude Code tool calls. Use when explaining, evaluating, or demonstrating the pattern before committing to the protect-mcp runtime hooks. Covers Cedar policy, Ed25519 receipts, offline verification, tamper detection, CI/CD integration, and SLSA composition.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/cedar-policy.md`, `references/ci-cd.md` and `references/hook-wiring.md`).

It sits in DevOps & Cloud, covering Supply chain security and CI/CD. It works with Model Context Protocol. The repository describes itself as: Multi-harness agentic plugin marketplace for Claude Code, Codex, Cursor, OpenCode, GitHub Copilot, Google Antigravity, and Pi. The licence is MIT.

When your agent uses it

  • Demonstrating the pattern before committing to the protect-mcp runtime hooks
  • Tasks that involve Supply chain security
  • Tasks that involve CI/CD

Example prompts

  • “/signed-audit-trails-recipe”

Requirements

  • Python 3
  • Node.js

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Install the hook configuration
  2. Write a Cedar policy
  3. Use Claude Code normally
  4. Inspect a receipt
  5. Verify the receipts
  6. Demonstrate tamper detection

What it can do on your machine

Read from SKILL.md and the folder at commit 46891e7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • npm
    • python3
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • veritasacta.com

    Also links to:

    • github.com
    • datatracker.ietf.org
    • npmjs.com
    • refs.arewm.com
    • pypi.org
    • docs.cedarpolicy.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Signed Audit Trails Recipe loads about 2.5k tokens when it runs, and up to ~4.7k if it reads all its reference files. Until then it costs about 91 tokens; SKILL.md has 1,003 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~91
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from wshobson/agents at commit 46891e7, republished under its MIT licence (© wshobson). 1,003 words, ~2,518 tokens.

Download SKILL.mdSave it as .claude/skills/signed-audit-trails-recipe/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
signed-audit-trails-recipe
description
Step-by-step cookbook for setting up cryptographically signed audit trails on Claude Code tool calls. Use when explaining, evaluating, or demonstrating the pattern before committing to the protect-mcp runtime hooks. Covers Cedar policy, Ed25519 receipts, offline verification, tamper detection, CI/CD integration, and SLSA composition.

Signed Audit Trails for Claude Code Tool Calls

Cookbook-style walkthrough for cryptographically signed receipts on every Claude Code tool call. This is the teaching skill. For the runtime implementation, install the protect-mcp plugin.

What this gives you

Every tool call (Bash, Edit, Write, WebFetch) is:

  1. Evaluated against a Cedar policy before execution. If the policy denies the call, the tool does not run.
  2. Signed as an Ed25519 receipt after execution. Receipts are JCS-canonical and verifiable offline by anyone with the public key.

An auditor, regulator, or counterparty can verify every receipt later (Step 5). No network call, no vendor lookup, no trust in the operator.

When to use the pattern

  • Regulated environments (finance, healthcare, critical infrastructure) where you need tamper-evident evidence of agent behavior
  • CI/CD pipelines where you want to prove that a policy gate held for every automated build step
  • Multi-party collaboration where a counterparty wants to verify your agent's behavior without trusting your operator
  • Compliance contexts (EU AI Act Article 12, SLSA provenance for agent-built software) where standard logging is not sufficient

Step 1: Install the hook configuration

Install the protect-mcp plugin with /plugin install protect-mcp. Its hooks run evaluate.sh before each tool call and sign.sh after it. Both scripts read the hook event from stdin, because Claude Code sets no TOOL_NAME or TOOL_INPUT variables. See references/hook-wiring.md for the hook configuration and what each script passes to protect-mcp.

protect-mcp 0.7.4 does not create the signing key, and without a key the receipts are unsigned. Create ./protect-mcp.key once. The command never replaces an existing key:

bash
if [ ! -e ./protect-mcp.key ]; then
  d=$(mktemp -d) && npx protect-mcp@0.7.4 init --dir "$d" && mv "$d/keys/gateway.json" ./protect-mcp.key
fi

Give auditors the publicKey value from that file. Do not commit the file, because it also holds the private key.

Add the private key and receipt directory to .gitignore:

bash
echo "/protect-mcp.key" >> .gitignore
echo "/receipts/" >> .gitignore

Step 2: Write a Cedar policy

Create ./protect.cedar from the example in references/cedar-policy.md. It allows read-only tools and a short list of Bash commands, denies shell chaining and destructive commands, and limits writes to the project with .. segments denied.

Step 3: Use Claude Code normally

Start Claude Code. Every tool call goes through both hooks:

You: Please read the README and summarize it.

Claude: I will read README.md.
  [PreToolUse: Read ./README.md -> allow]
  [Tool: Read executes]
  [PostToolUse: receipt rcpt-a8f3c9d2 signed to ./receipts/]

... summary of README ...

A session of 20 tool calls appends 20 receipts to ./receipts/receipts.jsonl.

Step 4: Inspect a receipt

protect-mcp 0.7.4 appends each receipt as one line of ./receipts/receipts.jsonl. Print the newest one:

bash
tail -n 1 ./receipts/receipts.jsonl | python3 -m json.tool

The receipt is a signed v2 envelope that names the tool, and it holds no public key. See references/receipt-format.md for a sample and the signed fields.

Step 5: Verify the receipts

Pass the publicKey value from ./protect-mcp.key to the verifier:

bash
PUB=$(node -p 'JSON.parse(require("fs").readFileSync("./protect-mcp.key")).publicKey')
npx @veritasacta/verify@0.9.2 --replay-chain ./receipts/receipts.jsonl --key "$PUB"

Exit codes:

CodeMeaning
0Every receipt verified
1A receipt failed verification (tampered, wrong key, or malformed line)
2The receipts file could not be read

Step 6: Demonstrate tamper detection

Change the newest receipt's decision from allow to deny:

bash
python3 -c "
import json
path = './receipts/receipts.jsonl'
lines = open(path).read().splitlines()
r = json.loads(lines[-1])
r['payload']['decision'] = 'deny'
lines[-1] = json.dumps(r)
open(path, 'w').write('\n'.join(lines) + '\n')
"

npx @veritasacta/verify@0.9.2 --replay-chain ./receipts/receipts.jsonl --key "$PUB"

The verifier exits with code 1 and reports which line failed. The Ed25519 signature no longer matches the JCS-canonical bytes of the tampered payload.

Restore the field and verification passes again.

How the cryptography works

Two invariants make receipts verifiable offline across any conformant implementation:

  1. JCS canonicalization (RFC 8785) before signing. Keys sorted, whitespace minimized, strings NFC-normalized. Two independent implementations produce byte-identical signing payloads for the same receipt content.
  2. Ed25519 signatures (RFC 8032) over the canonical bytes. Deterministic, fixed-size, no nonce dependency.

protect-mcp 0.7.4 receipts carry no link to the previous receipt, so a deleted receipt goes undetected.

For the formal wire format see draft-farley-acta-signed-receipts.

Cross-implementation interop

The receipt format has four independent implementations today:

ImplementationLanguageUse case
protect-mcpTypeScriptClaude Code, Cursor, MCP hosts
protect-mcp-adkPythonGoogle Agent Development Kit
sb-runtimeRustOS-level sandbox (Landlock + seccomp)
APS governance hookPythonCrewAI, LangChain

A receipt produced by any of them verifies against @veritasacta/verify. The auditor does not need to trust the operator's tooling choice: the format is the contract.

Show full SKILL.md (378 more words)Show less

CI/CD integration

Verify receipts in CI so a tampered receipt fails the build. references/ci-cd.md has a GitHub Actions workflow that runs on pushes to the default branch. It installs the signing key from a branch-limited environment, runs the agent, verifies the receipts, and uploads them. It does not run on pull requests, because that would hand the key to unreviewed code.

Composition with SLSA provenance for agent-built software

When Claude Code builds and releases software (running npm install, npm build, npm publish as tool calls), the receipt chain is the per-step build log. SLSA Provenance v1 has an extension point for this: the byproducts field can reference the receipt chain alongside the build attestation.

The agent-commit build type documents the pattern using the ResourceDescriptor shape:

json
{
  "name": "decision-receipts",
  "digest": { "sha256": "..." },
  "uri": "oci://registry/org/build-xyz/receipts:sha256-...",
  "annotations": {
    "predicateType": "https://veritasacta.com/attestation/decision-receipt/v0.1",
    "signerRole": "supervisor-hook"
  }
}

The SLSA provenance is signed by the builder identity; the receipt attestation is signed by the supervisor-hook identity. Two trust domains, cross-referenced at the byproduct layer. See slsa-framework/slsa#1594 for the composition discussion.

Common pitfalls

Private key in version control. The generated ./protect-mcp.key must not be committed. The examples above add it to .gitignore. If a key is accidentally committed, rotate it immediately. Move the key and ./receipts/receipts.jsonl to an archive, then run the Step 1 command again. Verify the archived receipts with the old public key.

Hook payload on stdin. Claude Code sets no $TOOL_NAME or $TOOL_INPUT variables. A hook command that passes --tool "$TOOL_NAME" sends an empty tool name, so the policy denies every call. Read the payload from stdin as the plugin scripts do.

Receipts directory in CI. If Claude Code runs in CI, upload receipts as an artifact at the end of the job or the receipts are lost at job end.

Policy is missing. When ./protect.cedar does not exist, evaluate.sh prints a warning to stderr and allows the call. No call is gated until you create the policy in Step 2.

  • protect-mcp — the runtime hook implementation (use this plugin in production)
  • review-agent-governance — require human approval before review-surface actions; composes with protect-mcp

References

© wshobson, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in plugins/signed-audit-trails/skills/signed-audit-trails-recipe of wshobson/agents.

  • SKILL.md
  • references/cedar-policy.md
  • references/ci-cd.md
  • references/hook-wiring.md
  • references/receipt-format.md

Open the folder on GitHubat commit 46891e7

Compare with similar skills

Signed Audit Trails Recipe next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Signed Audit Trails Recipe compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Signed Audit Trails Recipe this skillwshobson/agents40k—~2.5kAutomated safety check: PassMIT
GitHub Actions Supply Chain Pinningasyncapi/generator1.1k—~1.9kAutomated safety check: PassApache-2.0
Vibe CI Supply Chainmistralai/mistral-vibe5.1k—~1kAutomated safety check: PassApache-2.0
CI/CD Pipeline Principlesirahardianto/awesome-agv156—~2.7kAutomated safety check: NotesMIT
Atmos CIcloudposse/atmos1.4k—~4.7kAutomated safety check: PassApache-2.0
Detecting Supply Chain Attacks In CI CDmukul975/Anthropic-Cybersecurity-Skills34k—~655Automated safety check: PassApache-2.0

Similar skills

  • A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).

    1.1k GitHub stars~1.9k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Vibe CI Supply Chain

    mistralai/mistral-vibe

    Official

    Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe.

    5.1k GitHub stars~1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • CI/CD Pipeline Principles

    irahardianto/awesome-agv

    Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.

    156 GitHub stars~2.7k tokensUpdated 6 days ago
    DevOps & CloudAuto-check: notes
  • Atmos CI

    cloudposse/atmos

    Atmos CI: Native CI with GitHub Actions containers, native outputs, SBOM workflow-artifact publication, collapsible log groups, affected/all matrix workflows, OIDC profiles, toolchain-aware jobs…

    1.4k GitHub stars~4.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Detecting Supply Chain Attacks In CI CD

    mukul975/Anthropic-Cybersecurity-Skills

    Scans GitHub Actions workflows and CI/CD pipeline configurations for supply chain attack vectors including unpinned actions, script injection via expressions, dependency confusion, and secrets…

    34k GitHub stars~655 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Supply Chain Guard

    davila7/claude-code-templates

    Detect and remediate software supply chain attacks in npm, PyPI, crates.io, GitHub Actions, and CI/CD pipelines by scanning for known compromised packages, malicious versions, filesystem IOCs, C2…

    33k GitHub stars~1.7k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes

More from wshobson/agents

All 142 skills in this repo
  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 14 repos~1.7k tokens
    Auto-check passed
  • Billing Automation

    wshobson/agents

    Covers building subscription billing: billing cycles, subscription states, invoice generation, proration, tax handling and dunning for failed payments.

    40k GitHub starsUsed in 13 repos~473 tokens
    Auto-check passed
  • Profiles slow Python code with cProfile and memory profilers, then applies targeted fixes for CPU, memory, I/O and query bottlenecks.

    40k GitHub starsUsed in 13 repos~814 tokens
    Auto-check passed
  • Writes unit tests for shell scripts with Bats: error-condition tests, fixtures and mocks, cross-shell checks, parallel runs, helper files and CI integration.

    40k GitHub starsUsed in 12 repos~1.3k tokens
    Auto-check passed
  • Distributed Tracing

    wshobson/agents

    Implement distributed tracing with Jaeger and Tempo to track requests across microservices and identify performance bottlenecks.

    40k GitHub starsUsed in 12 repos~527 tokens
    Auto-check passed
  • Reference for designing and tuning production LLM prompts: few-shot examples, chain-of-thought, structured outputs, templates and system prompts.

    40k GitHub stars~1.3k tokensUpdated 6 days ago
    Auto-check passed

Questions about Signed Audit Trails Recipe

What does Signed Audit Trails Recipe do?

Step-by-step cookbook for setting up cryptographically signed audit trails on Claude Code tool calls. Signed Audit Trails Recipe is an agent skill from wshobson/agents. Step-by-step cookbook for setting up cryptographically signed audit trails on Claude Code tool calls.

When should I use Signed Audit Trails Recipe?

Signed Audit Trails Recipe fits situations like: demonstrating the pattern before committing to the protect-mcp runtime hooks; tasks that involve Supply chain security; tasks that involve CI/CD.

How do I install Signed Audit Trails Recipe in Claude Code?

Run `npx skills add wshobson/agents --skill signed-audit-trails-recipe -a claude-code`. Or copy the skill folder (plugins/signed-audit-trails/skills/signed-audit-trails-recipe in wshobson/agents) into .claude/skills/signed-audit-trails-recipe in your project. Claude Code loads it when a task matches its description.

How do I install Signed Audit Trails Recipe in Codex?

Run `npx skills add wshobson/agents --skill signed-audit-trails-recipe -a codex`. Or copy the skill folder (plugins/signed-audit-trails/skills/signed-audit-trails-recipe in wshobson/agents) into .agents/skills/signed-audit-trails-recipe in your project. Codex loads it when a task matches its description.

Can I use Signed Audit Trails Recipe in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add wshobson/agents --skill signed-audit-trails-recipe -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/signed-audit-trails-recipe, .gemini/skills/signed-audit-trails-recipe, .github/skills/signed-audit-trails-recipe and .opencode/skills/signed-audit-trails-recipe in your project.

What does Signed Audit Trails Recipe need to run?

Going by SKILL.md and its folder, Signed Audit Trails Recipe needs the command-line tools its instructions call (npx, npm, python3 and node). Our summary lists: Python 3; Node.js.

Does Signed Audit Trails Recipe access the network?

SKILL.md names 7 domains. In commands or code: veritasacta.com; the agent is likely to contact it when it follows the instructions. As links in the text: github.com, datatracker.ietf.org, npmjs.com, refs.arewm.com, pypi.org and docs.cedarpolicy.com. This is read from the text; nothing was executed.

Is Signed Audit Trails Recipe safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Signed Audit Trails Recipe use?

Signed Audit Trails Recipe is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Signed Audit Trails Recipe use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.2k tokens, read only when the agent opens those files.

What are the alternatives to Signed Audit Trails Recipe?

Skills that share tags, products or a category with Signed Audit Trails Recipe: GitHub Actions Supply Chain Pinning (asyncapi/generator, 1.1k stars), Vibe CI Supply Chain (mistralai/mistral-vibe, 5.1k stars), CI/CD Pipeline Principles (irahardianto/awesome-agv, 156 stars) and Atmos CI (cloudposse/atmos, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Signed Audit Trails Recipe?

wshobson (a GitHub user) maintains it in wshobson/agents, which has 40,314 GitHub stars. The repository holds 142 skills in this directory. The repository was last updated on October 5, 2026.

Source: wshobson/agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.