SkillAgentSearch skills...

auditkit

Tamper-evident audit log for B2B SaaS: hash-chained, anchored to Sigstore Rekor and OpenTimestamps, verifiable offline. Claude MCP connector included.

Install / Use

claude mcp add AuditKitDev -- npx -y github:AuditKitDev/auditkit

If the server publishes to npm under a different name, use that package instead — check the repo README.

About this skill
🔌

MCP Server

Model Context Protocol server

Quality Score

76/100

Supported Platforms

Claude Code
Claude Desktop

Our assessment of auditkit

auditkit scores 76/100 on our quality scale, 551st of 602 Data & Analytics skills we index.

Its MCP Server is 3.1 KB long, split into 7 sections with 4 code examples: a solid amount of guidance for an agent.

It has 3 GitHub stars, so there is little community track record yet; judge it on its content.

Substance
26/30
Structure
18/20
Description
15/15
Adoption
3/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated yesterday, so auditkit is actively maintained.
  • No license is declared. By default that means all rights are reserved: you can read it, but reusing or redistributing it is not clearly permitted. Ask the author before building on it commercially.
  • Its trust signals score 80/100, with 2 cautions from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

Safety scan

No issues found

Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful.

AI review by kimi-k2.7-code on 2026-10-08. Automated pattern scan on 2026-10-08. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.

auditkit compared with similar skills

All 4 of these similar skills score higher than auditkit; compare them before choosing.

SkillScoreStarsUpdatedFormat
auditkit (this skill)by AuditKitDev7631d agoMCP Server
claude-memby thedotmack10097.7k1d agoCLAUDE.md
Agent-Reachby Panniantong10093.2ktodayCLAUDE.md
headroomby headroomlabs-ai10074.6ktodayCLAUDE.md
CowAgentby zhayujie10047.3ktodayCLAUDE.md

Frequently asked questions

How do I install auditkit?
Run claude mcp add AuditKitDev -- npx -y github:AuditKitDev/auditkit. The install tabs above show the steps for each supported agent.
Which AI agents does auditkit work with?
It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
Is auditkit safe to use?
Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful. It declares no license and scores 80/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is auditkit still maintained?
The repository was last updated yesterday, so auditkit is actively maintained.

AuditKit

Tamper-evident audit log for B2B SaaS. Events are hash-chained per tenant, signed, batched into Merkle trees, and the roots are published to two public logs AuditKit does not control: Sigstore Rekor and OpenTimestamps. An export can be verified offline, with AuditKit's servers switched off, by @auditkit/verify.

Live: https://api.auditkit.dev (API, dashboard and docs). AuditKit audits itself; the platform's own chain is public at https://api.auditkit.dev/audit.

What is in this repository

| Package | What it is | |---|---| | packages/core | RFC 8785 canonicalization, hash chain, RFC 6962 Merkle trees, the Anchor contract and the export format. | | packages/server | The service: REST /v1, passwordless dashboard API, MCP server at /mcp with an OAuth 2.1 authorization server, anchor loop, SQLite storage (one file per project). | | packages/anchor-rekor, packages/anchor-ots | Anchor implementations with offline verification. | | packages/verify | auditkit-verify <export.jsonl>: rebuilds every hash and root and checks the public-log receipts without contacting AuditKit. | | packages/sdk | TypeScript SDK. packages/sdk-python is the Python SDK (auditkit-sdk on PyPI, import auditkit_sdk). | | packages/web | The static site and dashboard (Astro). | | deploy/ | Dockerfile, compose file, nginx site and deploy script for a single VPS. | | docs/ | Contract docs, research, the claims ledger (docs/claims.md: every claim on the site mapped to the code or source that proves it), QA and review reports. |

Run it locally

pnpm install
pnpm -r --filter '!@auditkit/web' build
AUDITKIT_DATA=./data AUDITKIT_ANCHORS=none pnpm --filter @auditkit/server start   # admin key lands in ./data/first-admin-key.txt
pnpm --filter @auditkit/web dev                                                   # site on :4321, proxies to :3001

AUDITKIT_ANCHORS=rekor,ots publishes real anchors; both public logs are free and need no account.

Log an event

import { AuditKit } from "@auditkit/sdk";
const audit = new AuditKit({ apiKey: process.env.AUDITKIT_API_KEY, baseUrl: "https://api.auditkit.dev" });
const receipt = await audit.log({ tenant: "acme", actor: "u_17", action: "invoice.delete", target: "inv_42", payload: { amount: 10 } });

Export and verify offline:

curl -H "Authorization: Bearer $AUDITKIT_API_KEY" "https://api.auditkit.dev/v1/export?tenant=acme" > acme.jsonl
node packages/verify/dist/cli.js acme.jsonl      # VALID / VALID_UNANCHORED / INVALID, exit 0 / 2 / 1

Connect it to Claude

Claude.ai → Settings → Connectors → Add custom connector → https://api.auditkit.dev/mcp, sign in with your email, pick the project. Claude Code: claude mcp add --transport http auditkit https://api.auditkit.dev/mcp.

Tests

pnpm -r --filter '!@auditkit/web' test
cd packages/sdk-python && python -m pytest
pnpm --filter @auditkit/server smoke:prod        # customer-path smoke test against a running instance (needs AUDITKIT_API_KEY)

License

AGPL-3.0-only. See LICENSE.

Related Skills

View on GitHub
GitHub Stars3
CategoryData
Updated1d ago
Forks0

Languages

TypeScript

Trust signals

80/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

1 medium1 low