signed-audit-trails-recipe
Cookbook for cryptographically signed, offline-verifiable audit trails on Claude Code tool calls.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for signed-audit-trails-recipe, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
An Agent Skill that teaches and demonstrates signing every Claude Code tool call: Cedar policy evaluation before execution and JCS-canonical, hash-chained Ed25519 receipts after. It covers offline verification, tamper detection, CI/CD integration, and SLSA composition. This is the teaching companion to the protect-mcp runtime plugin.
Key features and capabilities
- Cedar policy + Ed25519 receipt walkthrough
- Tamper detection and offline verification
- CI/CD and SLSA composition
Use cases
- Evaluating signed-audit patterns
- Demonstrating tamper-evident tool logging