Audit Trail for Openclaw

A forensic-ready governance skill providing an immutable, hash-chained log of every agent action for complete accountability.

arhadnane
v1.0.0
Apr 4, 2026
0
654
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install audit-trail

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install audit-trail using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Audit Trail?

The Audit Trail skill serves as a critical governance and security layer for autonomous agents. It provides a tamper-evident record of every operation performed, ranging from tool executions and file modifications to configuration changes and communication logs. By establishing a verifiable chain of custody, it ensures that every action taken by the agent is transparent and attributable.

Built for high-stakes environments using Openclaw Skills, this tool leverages cryptographic hash chaining to guarantee data integrity. Each log entry is linked to the previous one via a SHA-256 hash, making any unauthorized modification immediately detectable. This makes the skill indispensable for developers and organizations that prioritize forensic investigation, regulatory compliance, and system accountability.

Audit Trail Use Cases

  • Conducting forensic investigations into agent failures or unexpected logic paths.
  • Meeting regulatory compliance requirements in fintech, healthcare, or legal sectors.
  • Tracking resource usage and duration across complex multi-skill workflows.
  • Auditing configuration changes to maintain stable and secure agent environments.

How Audit Trail Works

  1. An always-on hook intercepts every internal and external agent action, including tool usage and memory I/O.
  2. The system generates a structured JSONL entry containing precise metadata, including microsecond timestamps and session IDs.
  3. Sensitive data and secrets are automatically redacted from the arguments before the entry is finalized.
  4. A SHA-256 hash is generated for the entry, incorporating the hash of the preceding record to form an immutable chain.
  5. The log is appended to a daily file in the protected security directory, which is monitored for integrity via automated verification scripts.

Audit Trail Setup

To deploy the Audit Trail within your Openclaw Skills environment, ensure the security directory is properly provisioned and the governance hook is active. Use the following commands to initialize and verify your trail:

# Create the dedicated security directory structure
mkdir -p .security/audit-trail/

# Verify the integrity of the existing log chain
jq -r '.hash' .security/audit-trail/*.jsonl | sha256sum --check

Audit Trail Data Schema & Taxonomy

The skill organizes logs using a JSONL (JSON Lines) format to ensure they are append-only and queryable. Data is categorized as follows:

Field Type Description
id string Unique sequential action identifier.
ts ISO 8601 Microsecond-accurate timestamp.
type enum Category of action (e.g., tool_use, memory_write, error).
outcome enum Result status: success, failure, timeout, or blocked.
prev_hash string SHA-256 hash of the previous log entry.
hash string SHA-256 hash of the current entry including the prev_hash.

Storage is managed via a hierarchical retention policy where active logs remain raw for 7 days before being compressed into .gz archives.

Audit Trail Advanced Features

  • Immutable hash-chained architecture preventing silent log tampering.
  • Automated secret redaction powered by agent-firewall pattern matching.
  • Support for complex forensic queries using standard jq syntax.
  • Multi-stage retention policy for balancing storage costs and data accessibility.
  • Real-time critical alerting upon detection of broken log integrity chains.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*