auditkit
Tamper-evident audit log for B2B SaaS: hash-chained, anchored to Sigstore Rekor and OpenTimestamps, verifiable offline. Claude MCP connector included.
Install / Use
claude mcp add AuditKitDev -- npx -y github:AuditKitDev/auditkitIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
Data & AnalyticsSupported Platforms
Tags
Our assessment of auditkit
auditkit scores 76/100 on our quality scale, 551st of 602 Data & Analytics skills we index.
Its MCP Server is 3.1 KB long, split into 7 sections with 4 code examples: a solid amount of guidance for an agent.
It has 3 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated yesterday, so auditkit is actively maintained.
- No license is declared. By default that means all rights are reserved: you can read it, but reusing or redistributing it is not clearly permitted. Ask the author before building on it commercially.
- Its trust signals score 80/100, with 2 cautions from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful.
AI review by kimi-k2.7-code on 2026-10-08. Automated pattern scan on 2026-10-08. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
auditkit compared with similar skills
All 4 of these similar skills score higher than auditkit; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| auditkit (this skill)by AuditKitDev | 76 | 3 | 1d ago | MCP Server |
| claude-memby thedotmack | 100 | 97.7k | 1d ago | CLAUDE.md |
| Agent-Reachby Panniantong | 100 | 93.2k | today | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.6k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.3k | today | CLAUDE.md |
Frequently asked questions
- How do I install auditkit?
- Run
claude mcp add AuditKitDev -- npx -y github:AuditKitDev/auditkit. The install tabs above show the steps for each supported agent. - Which AI agents does auditkit work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is auditkit safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful. It declares no license and scores 80/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is auditkit still maintained?
- The repository was last updated yesterday, so auditkit is actively maintained.
Skill content
View source on GitHubAuditKit
Tamper-evident audit log for B2B SaaS. Events are hash-chained per tenant, signed, batched into Merkle trees, and the roots are published to two public logs AuditKit does not control: Sigstore Rekor and OpenTimestamps. An export can be verified offline, with AuditKit's servers switched off, by @auditkit/verify.
Live: https://api.auditkit.dev (API, dashboard and docs). AuditKit audits itself; the platform's own chain is public at https://api.auditkit.dev/audit.
What is in this repository
| Package | What it is |
|---|---|
| packages/core | RFC 8785 canonicalization, hash chain, RFC 6962 Merkle trees, the Anchor contract and the export format. |
| packages/server | The service: REST /v1, passwordless dashboard API, MCP server at /mcp with an OAuth 2.1 authorization server, anchor loop, SQLite storage (one file per project). |
| packages/anchor-rekor, packages/anchor-ots | Anchor implementations with offline verification. |
| packages/verify | auditkit-verify <export.jsonl>: rebuilds every hash and root and checks the public-log receipts without contacting AuditKit. |
| packages/sdk | TypeScript SDK. packages/sdk-python is the Python SDK (auditkit-sdk on PyPI, import auditkit_sdk). |
| packages/web | The static site and dashboard (Astro). |
| deploy/ | Dockerfile, compose file, nginx site and deploy script for a single VPS. |
| docs/ | Contract docs, research, the claims ledger (docs/claims.md: every claim on the site mapped to the code or source that proves it), QA and review reports. |
Run it locally
pnpm install
pnpm -r --filter '!@auditkit/web' build
AUDITKIT_DATA=./data AUDITKIT_ANCHORS=none pnpm --filter @auditkit/server start # admin key lands in ./data/first-admin-key.txt
pnpm --filter @auditkit/web dev # site on :4321, proxies to :3001
AUDITKIT_ANCHORS=rekor,ots publishes real anchors; both public logs are free and need no account.
Log an event
import { AuditKit } from "@auditkit/sdk";
const audit = new AuditKit({ apiKey: process.env.AUDITKIT_API_KEY, baseUrl: "https://api.auditkit.dev" });
const receipt = await audit.log({ tenant: "acme", actor: "u_17", action: "invoice.delete", target: "inv_42", payload: { amount: 10 } });
Export and verify offline:
curl -H "Authorization: Bearer $AUDITKIT_API_KEY" "https://api.auditkit.dev/v1/export?tenant=acme" > acme.jsonl
node packages/verify/dist/cli.js acme.jsonl # VALID / VALID_UNANCHORED / INVALID, exit 0 / 2 / 1
Connect it to Claude
Claude.ai → Settings → Connectors → Add custom connector → https://api.auditkit.dev/mcp, sign in with your email, pick the project. Claude Code: claude mcp add --transport http auditkit https://api.auditkit.dev/mcp.
Tests
pnpm -r --filter '!@auditkit/web' test
cd packages/sdk-python && python -m pytest
pnpm --filter @auditkit/server smoke:prod # customer-path smoke test against a running instance (needs AUDITKIT_API_KEY)
License
AGPL-3.0-only. See LICENSE.
Related Skills
claude-mem
97.7kPersistent Context Across Sessions for Every Agent – Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions. Works with Claude Code, OpenClaw, Codex, Gemini, Hermes, Copilot, OpenCode + More
Agent-Reach
93.2kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.6kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
CowAgent
47.3kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
