Lightlines
By wshobson

signed-audit-trails-recipe

wshobson

Make every agent tool call independently auditable.

agent governance

What it does

Explains how to set up and verify cryptographically signed receipts for Claude Code tool calls.

When to use it

Use when explaining, evaluating, or demonstrating tamper-evident agent audit trails, especially for regulated, CI/CD, collaborative, or compliance settings.

How to use it

Give it a signed-audit-trail question or demonstration goal; it returns a cookbook-style walkthrough.

Uses


Access · 4

This skill

GitHub

Write

Stores keys and receipt artifacts

GitHub secret PROTECT_MCP_KEY

Read

Reads your GitHub signing secret

protect-mcp

Execute

Installs the protect-mcp plugin

Claude Code hook configuration

Write

Adds hooks to Claude Code

What you need · 6

Node.js is required to initialize the signing key and extract its public key.

Python 3 is used to format receipts and perform the tampering demonstration.

The runtime implementation requires the protect-mcp plugin, although the teaching material can be read without it.

The signer and verifier use the private and public key material stored in ./protect-mcp.key.


About this skill

Visibility
Public
Repository
wshobson/agents
Created
Oct 8, 2026
Updated
Oct 8, 2026
Files
5