Audit Trail Verifier — Security agent for Claude Code
Create an immutable evidence chain linking requirements, code, tests, scans, and releases.
How to install Audit Trail Verifier
Installs to ~/.claude/agents/paulduvall-claude-code-audit-trail-verifier.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/PaulDuvall/claude-code/HEAD/subagents/audit-trail-verifier.md -o ~/.claude/agents/paulduvall-claude-code-audit-trail-verifier.md Restart Claude Code, or start a new session, for it to be picked up.
What Audit Trail Verifier does
name: audit-trail-verifier description: Create an immutable evidence chain linking requirements, code, tests, scans, and releases. version: 1.0.0 author: Claude Dev Toolkit Team tags: [compliance, security, release] tools: Read, Write, Grep, Glob created: 2025-08-19 modified: 2026-04-03
Goal
- Prove every change was built, tested, scanned, and released correctly.
Inputs
- docs/traceability.md, test reports, security reports, sbom/, releases/
Rules
- Evidence must be linkable and times
Alternatives in Security
- Token Auditor — Scans ui/src/ for hardcoded visual values, duplicate components, and shadcn replacement candidates; produces d 79.4k ★
- Security Requirement Extraction — Transform threat analysis into actionable security requirements 31.9k ★
- Vault Librarian — Run vault maintenance: detect orphan notes, find broken wikilinks, validate frontmatter completeness, flag sta 4.6k ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Spgr Agent Compliance
Determines which regulatory frameworks apply, classifies data by sensitivity, and sets retention and audit-tra
Devsecops Reviewer
Infrastructure and CI/CD security reviewer — scans Terraform, Dockerfiles, Kubernetes manifests, GitHub Action
Osf Gap Audit
Requirements gap audit worker. Extracts a capability checklist from a spec file or list, inventories the codeb
Test Coverage Analyst
Proactively invoked when the user asks to "generate tests", "add test coverage", "find untested code", or "aud
Bounded Implementer
Use proactively for one bounded, low-risk implementation with explicit file ownership and a deterministic veri
Compliance Scanner
Scans codebase for CMMC control evidence. Searches auth, TLS, RBAC, logging, session management, and other sec
Related Skills
Check Traceability
Verify links from use cases and requirements to design, code, tests, and releases
Audit Trail
Reconstruct the spec→plan→tasks→PRs→deploy 5-tuple for any commit. Compliance/audit use. Uses commit trailers
Jiahao
Dual-profile prompt-as-mental-model harness for LLM agents — advisory generator profile in the working agent,