@agentlaw/audit
v0.1.0
Published
Tamper-evident audit log for AI agent actions: hash-chained JSONL writer and verifier.
Maintainers
Readme
@agentlaw/audit
Tamper-evident audit log for AI agent actions, part of AgentLaw. Hash-chained JSONL: every decision the policy engine takes lands as an entry whose hash covers its content plus the previous entry — an edit or deletion anywhere breaks the chain.
import { AuditWriter, verifyAuditDir } from "@agentlaw/audit";
const audit = await AuditWriter.open({ dir: ".agentlaw/audit", policyHash });
audit.append("decision", { tool: "shell", decision: "deny", ruleId: "no-rm" });
const report = await verifyAuditDir(".agentlaw/audit");
// the report flags the exact entry the moment anything was altered- Writer — append-only JSONL, one chain per environment, secret redaction before anything is persisted.
- Verifier — recomputes the whole chain from canonical content; used by
agentlaw audit verify.
Spec: RFC-0002 — audit log.
Apache-2.0.
