Make every agent tool call independently auditable.
agent governance
Explains how to set up and verify cryptographically signed receipts for Claude Code tool calls.
When to use it
Use when explaining, evaluating, or demonstrating tamper-evident agent audit trails, especially for regulated, CI/CD, collaborative, or compliance settings.
Give it a signed-audit-trail question or demonstration goal; it returns a cookbook-style walkthrough.
This skill
GitHub
Stores keys and receipt artifacts
GitHub secret PROTECT_MCP_KEY
Reads your GitHub signing secret
protect-mcp
Installs the protect-mcp plugin
Claude Code hook configuration
Adds hooks to Claude Code
Node.js is required to initialize the signing key and extract its public key.
Python 3 is used to format receipts and perform the tampering demonstration.
The runtime implementation requires the protect-mcp plugin, although the teaching material can be read without it.
The signer and verifier use the private and public key material stored in ./protect-mcp.key.