signed-audit-trails
PackAI & modelssigned-audit-trails is a teaching skill in cookbook form that shows how to add tamper-proof signed logs recording every action a coding agent takes. It walks through Cedar policy, Ed25519 receipts, offline verification, CI/CD integration, and SLSA composition for signed audit trails on every Claude Code tool call. It pairs with the protect-mcp runtime plugin.
Unavailable. Delivery for this kind is on the roadmap — not serving yet.
Have a coding agent setup where tool calls can be audited, such as Claude Code.
What your AI can do with it
- Cookbook-style walkthrough for signed audit trails on every Claude Code tool call
- Writing Cedar policy for audit rules
- Generating Ed25519 receipts for tool calls
- Verifying receipts offline
- Integrating signed audit trails into CI/CD
- Composing attestations with SLSA
Getting started
- Have a coding agent setup where tool calls can be audited, such as Claude Code.
- Install the signed-audit-trails teaching skill.
- Follow the cookbook lessons on Cedar policy and Ed25519 receipts.
- Set up offline verification and CI/CD integration as described in the walkthrough.
- Optionally pair it with the protect-mcp runtime plugin for runtime enforcement.
Signals
- GitHub stars
- 40k
- Forks
- 4k
- Last commit
- Sep 2026
Questions
- What does signed-audit-trails do?
- It is a teaching skill that provides a cookbook-style walkthrough for adding tamper-proof signed logs that record every action a coding agent takes, covering Cedar policy, Ed25519 receipts, offline verification, CI/CD integration, and SLSA composition.
- Does it work on its own?
- It is designed to pair with the protect-mcp runtime plugin, which handles the runtime side while this skill teaches the setup.
- Can receipts be verified without a network connection?
- Yes, the walkthrough covers offline verification of Ed25519 receipts.
Advanced
- Item type
- plugin
- Key
wshobson-agents-signed-audit-trails- Source
- github.com/wshobson/agents