Skip to main content

agent-execution-receipts

Inspect signed Codex execution receipts, import provider audit events, and explain whether an action has local evidence, a candidate correlation, or a provider binding.

Zur Installation springen

Quellinformationen

Repository
writer/cerebro
Letzte Quellaktivität
16. Juli 2026 um 08:39
Erkannte Sprache von SKILL.md
Englisch
Sterne
15
Forks
3

Installationsoptionen

Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.

Quelldateien prüfen

Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.

SKILL.md wird angezeigt

SKILL.md
Quellanweisungen · Schreibgeschützte Vorschau
name
agent-execution-receipts
description
Inspect signed Codex execution receipts, import provider audit events, and explain whether an action has local evidence, a candidate correlation, or a provider binding.
# Agent Execution Receipts Use this skill when the user asks who or what ran a command, whether an agent action reached a provider, or which agent-originated changes lack provider attribution. ## Procedure 1. Open the Cerebro Agent Receipts app or read `receipts.ndjson` from the configured receipt directory. 2. Verify each receipt signature and the append-only digest chain before using it as evidence. 3. Import a CloudTrail `LookupEvents` response when provider observations are available. 4. Report one of three states without collapsing them: - `Local evidence only`: a signed local receipt exists. - `Candidate correlation`: one provider event has a one-to-one evidence match, but no trusted binding. - `Provider bound`: an authenticated provider event passes the configured account, dedicated role, action ID, action, and time checks. 5. Start from the provider-event population and identify every provider mutation without a completed one-to-one action match. Never treat a process name, user agent, `startedBy` value, local transcript, session-wide identifier, or user-imported JSON as provider-bound attribution.
Auf GitHub ansehen