Inspect signed Codex execution receipts, import provider audit events, and explain whether an action has local evidence, a candidate correlation, or a provider binding.
67
80%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Use this skill when the user asks who or what ran a command, whether an agent action reached a provider, or which agent-originated changes lack provider attribution.
receipts.ndjson from the configured receipt directory.LookupEvents response when provider observations are available.Local evidence only: a signed local receipt exists.Candidate correlation: one provider event has a one-to-one evidence match, but no trusted binding.Provider bound: an authenticated provider event passes the configured account, dedicated role, action ID, action, and time checks.Never treat a process name, user agent, startedBy value, local transcript, session-wide identifier, or user-imported JSON as provider-bound attribution.
20bd7fe
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.