audit-chain
Verify every receipt in ./receipts/receipts.jsonl against the signer's public key. Detects tampered or malformed receipts across the audit trail.
- 0
- Installs
- —
- Rating
- —
- Success rate
- 1
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 1a3a2e480336a636… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
audit-chain.md
Audit Chain
Verify every receipt in the audit trail, not just a single receipt.
protect-mcp 0.7.4 appends receipts to receipts.jsonl in ./receipts/ (or
the specified directory), one per line, and this command checks the signature
on each line.
Usage
/audit-chain # Verify all receipts in ./receipts/
/audit-chain --last 50 # Verify only the last 50 receipts
/audit-chain --dir /var/log/receipts # Use a different directory
What This Command Does
- Reads
receipts.jsonlin the target directory - Keeps only the last N lines when
--last Nis given - Verifies each Ed25519 signature against the
publicKeyvalue in./protect-mcp.key(or the file named byPROTECT_MCP_KEY) - Reports the line number of each receipt that fails. With
--last N, the verifier numbers the selected lines from 1, so the command prints the offset to add to get the line inreceipts.jsonl
protect-mcp 0.7.4 receipts carry no link to the previous receipt, so this check cannot detect a deleted, inserted, or reordered line. To detect deleted lines, keep a copy of the receipts file where the operator cannot change it.
Implementation
RECEIPT_DIR="./receipts"; N=""
while [ $# -gt 0 ]; do
case "$1" in
--last|--dir)
if [ $# -lt 2 ]; then
echo "usage: /audit-chain [--last N] [--dir path]" >&2; exit 2
fi
if [ "$1" = "--last" ]; then
case "$2" in
''|*[!0-9]*) echo "--last takes a positive whole number" >&2; exit 2 ;;
esac
N="$2"
else
RECEIPT_DIR="$2"
fi
shift 2 ;;
*) shift ;;
esac
done
FILE="$RECEIPT_DIR/receipts.jsonl"
if [ -n "$N" ]; then
N=$((10#$N))
[ "$N" -gt 0 ] || { echo "--last takes a positive whole number" >&2; exit 2; }
TOTAL=$(wc -l < "$FILE"); OFFSET=$(( TOTAL > N ? TOTAL - N : 0 ))
echo "Checking lines $((OFFSET + 1)) to $((TOTAL)). Add $OFFSET to each reported line number."
TMP="$(mktemp)"; tail -n "$N" "$FILE" > "$TMP"; FILE="$TMP"
fi
PUB=$(node -p 'JSON.parse(require("fs").readFileSync(process.env.PROTECT_MCP_KEY || "./protect-mcp.key")).publicKey')
npx @veritasacta/verify@0.9.2 --replay-chain "$FILE" --key "$PUB"
Exit 0 means every receipt verified. Exit 1 means at least one receipt
failed, because it was tampered with, a line is malformed, the key is wrong or
missing, or the algorithm is unsupported. With --replay-chain, the verifier
reports those cases per line with exit 1. Exit 2 means the check could not
run, e.g., because the file could not be read or an option had no value.
npx downloads @veritasacta/verify@0.9.2 the first time it runs. For an
offline machine, install it in the project first with
npm install --no-save @veritasacta/verify@0.9.2, and npx then runs the
local copy without network access.
What to Show the User
All receipts verify
Audit verification: PASSED
Scanned: 247 receipts in ./receipts/receipts.jsonl
Signatures: 247/247 valid ✓
Key: 0faf558a90dfbf88...
All 247 receipts verify. A deleted or reordered line would not show here,
because 0.7.4 receipts carry no link to the previous receipt.
Tampered receipt
Audit verification: FAILED
Scanned: 247 receipts
Signatures: 246/247 valid (1 failed)
FAILED at line 89: invalid_signature
Request: tu-1790427588265-c8x5
Tool: Bash
Issued at: 2026-09-26T14:22:01Z
The signature on this line does not verify, so the receipt was modified
after signing, or the key is not the signer's key. Compare the line against
a known-good copy to find the altered field.
When to Run This
- Before shipping a release, to confirm that no development receipt was altered
- During security audits, to show auditors that every receipt verifies
- After incidents — verify logs were not tampered with during the incident
- Periodically — CI/CD job to catch silent corruption
- Before compliance reviews — provide evidence of continuous integrity
References
- @veritasacta/verify on npm
- Use
/verify-receiptfor single-receipt verification
Files
1- audit-chain.md
9bd263b41e4.4 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from wshobson/agents8
Audit UI code for WCAG compliance
Audit web accessibility for WCAG compliance with automated axe-core tests, keyboard and screen reader checks, and remediation guidance
Build AI assistant application with NLU, dialog management, and integrations
Run an AI-assisted code review that combines static analysis tools with AI review of security, performance, and architecture
Build realistic API mock servers with request stubbing, dynamic data, test scenarios, and contract testing
Open a review-action approval window by creating the ./.review-approved flag file. Takes an optional reason string that is recorded in the flag file and an unsigned approval log.
Set up PreToolUse hook to block --no-verify and other git bypass flags in Claude Code projects
Generate comprehensive investor-ready business case document with market, solution, financials, and strategy
Related knowledge skillsscan passed
Onboard a Code-with-Claude Makers Cardputer — fetch the build-with-claude repo, flash firmware, and install the Claude Buddy apps.
Explain Stripe error codes and provide solutions with code examples
Define and enforce this project's quality bar — interview, sane defaults, CONSTRAINTS.md
Detects timing side-channels in cryptographic code
Ask a question about the repository using wiki context and source file references
Run Sanity TypeGen and troubleshoot type generation issues.