Acquiredl

Loxodonta — Security skill for Claude Code

Security community

A tamper-evident security record for AI agents.

How to install Loxodonta

This entry records only its repository, not the path inside it, so there is no exact command to give. Open Acquiredl/loxodonta and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Loxodonta does

A tamper-evident security record for AI agents. Every tool call leaves a hash-chained receipt, and one command tells you whether anyone, the agent included, rewrote them. A flight recorder the agent cannot quietly edit. Stdlib-only Python, zero dependencies.

Alternatives in Security

  • FastAPI Review — Review a FastAPI application for architecture, async correctness, dependency injection, Pydantic schemas, secu 243.5k ★
  • Defense In Depth — Implement multi-layered testing and security best practices 98.1k ★
  • Google Workspace Alert Center — Manage security alerts 21.6k ★

README

![loxodonta](docs/images/wordmark.svg)

**A tamper-evident security record for AI agents.**

[![tests](https://github.com/Acquiredl/loxodonta/actions/workflows/tests.yml/badge.svg?branch=main)](https://github.com/Acquiredl/loxodonta/actions/workflows/tests.yml) [![python 3.9+](https://img.shields.io/badge/python-3.9%2B-blue)](https://www.python.org/downloads/) [![no dependencies](https://img.shields.io/badge/dependencies-none-brightgreen)](#install) [![license MIT](https://img.shields.io/badge/license-MIT-lightgrey)](LICENSE)

Every tool call your AI coding agent makes leaves a receipt, and one command tells you whether anyone, the agent included, rewrote them afterwards. A flight recorder, kept where the agent cannot quietly edit it.

It is for anyone who lets Claude Code, Codex CLI or the OpenAI Agents SDK loose on real code, and for whoever has to believe the record afterwards: the reviewer, the incident responder, the person handed the evidence.

Python 3.9 or newer, standard library only: download from the [releases page](https://github.com/Acquiredl/loxodonta/releases) and run `python loxodonta.py install-hook`.

![A terminal recording: init, two receipts logged, verify says VALID, one word of entry 1 rewritten with sed, verify says BROKEN at entry 1.](docs/images/tamper-demo.gif)

The problem

What is a log worth when the system it records can also edit it?

An AI agent runs commands, reads files, fetches pages and changes code. A session that reads a prompt injection can act on it and then rewrite its own log to hide that it did. An ordinary log only says what the logging system holds now.

loxodonta assumes the writer of the record may be compromised, or following someone else's instructions ([ADR-0002](adrs/0002-writer-as-adversary.md)). It does not make the agent trustworthy and it does not stop it acting. It keeps a record of what the agent did that shows when it was changed, and gives you ways to keep evi