Loxodonta — Security skill for Claude Code
A tamper-evident security record for AI agents.
How to install Loxodonta
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open Acquiredl/loxodonta and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Loxodonta does
A tamper-evident security record for AI agents. Every tool call leaves a hash-chained receipt, and one command tells you whether anyone, the agent included, rewrote them. A flight recorder the agent cannot quietly edit. Stdlib-only Python, zero dependencies.
Alternatives in Security
- FastAPI Review — Review a FastAPI application for architecture, async correctness, dependency injection, Pydantic schemas, secu 243.5k ★
- Defense In Depth — Implement multi-layered testing and security best practices 98.1k ★
- Google Workspace Alert Center — Manage security alerts 21.6k ★
README

**A tamper-evident security record for AI agents.**
[](https://github.com/Acquiredl/loxodonta/actions/workflows/tests.yml) [](https://www.python.org/downloads/) [](#install) [](LICENSE)
Every tool call your AI coding agent makes leaves a receipt, and one command tells you whether anyone, the agent included, rewrote them afterwards. A flight recorder, kept where the agent cannot quietly edit it.
It is for anyone who lets Claude Code, Codex CLI or the OpenAI Agents SDK loose on real code, and for whoever has to believe the record afterwards: the reviewer, the incident responder, the person handed the evidence.
Python 3.9 or newer, standard library only: download from the [releases page](https://github.com/Acquiredl/loxodonta/releases) and run `python loxodonta.py install-hook`.

The problem
What is a log worth when the system it records can also edit it?
An AI agent runs commands, reads files, fetches pages and changes code. A session that reads a prompt injection can act on it and then rewrite its own log to hide that it did. An ordinary log only says what the logging system holds now.
loxodonta assumes the writer of the record may be compromised, or following someone else's instructions ([ADR-0002](adrs/0002-writer-as-adversary.md)). It does not make the agent trustworthy and it does not stop it acting. It keeps a record of what the agent did that shows when it was changed, and gives you ways to keep evi
Related Skills
Sanctuary Framework
Open-source security for AI agents: kernel-enforced egress control on macOS and Linux, keys only the operator
Openmoat
Security for AI coding agents. One policy controls what Claude Code, Codex and Cursor can run, read, write and
Secure Plugin Installer
Audit and gate third-party Claude Code plugins / OpenClaw skills before enabling them: capability enumeration,
Trustgate
Deterministic policy enforcement and a tamper-evident audit log for AI agents. Decides what your agent may act
Fable Five
Five skills written by Claude Fable 5 before it leaves your plan: pre-ship security check, project setup, plan
Jev Skill Router
Jev-powered skill router & security auditor for any AI agent (Codex, Claude Code, OpenCode, Hermes): ONE cheap
Related Agents
Edit Planner
Produces camera-config.json from moments.json + alignment.json. Call this after record and narrate succeed and
AWS Inference Exposure
Determine who can invoke Bedrock model endpoints in an AWS account, what a hijacked one reaches and whether ab
Recorder Agent
Spec recording worker for spec-driven development spawned by speq-record orchestrator. Merges plan deltas into