CtrlK
BlogDocsLog inGet started
Tessl Logo

agent-execution-receipts

Inspect signed Codex execution receipts, import provider audit events, and explain whether an action has local evidence, a candidate correlation, or a provider binding.

67

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Agent Execution Receipts

Use this skill when the user asks who or what ran a command, whether an agent action reached a provider, or which agent-originated changes lack provider attribution.

Procedure

  1. Open the Cerebro Agent Receipts app or read receipts.ndjson from the configured receipt directory.
  2. Verify each receipt signature and the append-only digest chain before using it as evidence.
  3. Import a CloudTrail LookupEvents response when provider observations are available.
  4. Report one of three states without collapsing them:
    • Local evidence only: a signed local receipt exists.
    • Candidate correlation: one provider event has a one-to-one evidence match, but no trusted binding.
    • Provider bound: an authenticated provider event passes the configured account, dedicated role, action ID, action, and time checks.
  5. Start from the provider-event population and identify every provider mutation without a completed one-to-one action match.

Never treat a process name, user agent, startedBy value, local transcript, session-wide identifier, or user-imported JSON as provider-bound attribution.

Repository
writer/cerebro
Last updated
First committed

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.