New:Microsoft Teams Notifications Are Now Available in Socket.Learn more →
Get Started

agentproofs

Package Overview
Dependencies
Maintainers
1
Versions
7
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

agentproofs

Signed, hash-chained proof logs for AI agent tool executions and auditable events. MCP-native. Local-first.

Source
npmnpm
Version
0.1.0
Version published
Weekly downloads
8
166.67%
Maintainers
1
Weekly downloads
 
Created
Source

agentproofs

Signed, hash-chained proof logs for AI agent tool executions and auditable events. MCP-native. Local-first.

What it does

Every captured agent event gets a cryptographically signed proof appended to a hash-chained log. The chain is append-only — any modification, insertion, or deletion breaks the chain and is immediately detectable.

Proof 1: { event: "tool_started: Bash", hash: abc, sig: ... }
    | prev_hash: abc
Proof 2: { event: "tool_completed: Bash", hash: def, sig: ... }
    | prev_hash: def
Proof 3: { event: "decision: use JWT", hash: ghi, sig: ... }

Quick start

# Initialize
npx agentproofs init

# Install Claude Code auto-capture hooks
npx agentproofs install-hooks

# Use Claude Code normally — every tool call is auto-captured

# Verify chain integrity
npx agentproofs verify

# See recent activity
npx agentproofs tail

# Search proofs
npx agentproofs query --tool Bash --from 2026-04-01

# Export for audit
npx agentproofs export --sign

How it works

  • Ed25519 keypair generated on first run — your agent's cryptographic identity
  • Every tool call captured via Claude Code hooks (PreToolUse + PostToolUse)
  • Each proof is hashed (SHA-256) and signed (Ed25519), linking to the previous proof's hash
  • Tamper detection — modify, delete, or insert any entry and the chain breaks
  • Privacy by default — only hashes of input/output are stored, not content

MCP Server

agentproofs runs as an MCP server with 4 tools and 3 resources:

Tools:

  • proof_log — Log an agent event
  • proof_verify — Verify chain integrity
  • proof_query — Search proofs
  • proof_export — Export for audit

Resources:

  • proofs://chain — Chain status and health
  • proofs://stats — Statistics by agent, tool, namespace
  • proofs://latest — Last 20 proof entries

Add to your MCP config:

{
  "mcpServers": {
    "agentproofs": {
      "command": "npx",
      "args": ["agentproofs"]
    }
  }
}

CLI

npx agentproofs [command] [options]
CommandDescription
(default)Start MCP server
initInitialize data directory and keys
install-hooksInstall Claude Code auto-capture hooks
verifyVerify chain integrity
statsShow chain statistics
tailShow latest proofs
querySearch proofs
show <id>Show single proof detail
exportExport proofs for audit
pubkeyPrint public key
keysList keys
segmentsList chain segments

Examples

# Verify the entire chain
npx agentproofs verify
# > Chain valid: 847 proofs verified
# > Trust level: L0 (local, key integrity assumed)

# Last 10 events
npx agentproofs tail -n 10

# All Bash commands this week
npx agentproofs query --tool Bash --from 2026-04-01

# Failed actions only
npx agentproofs query --failed

# Export signed JSONL
npx agentproofs export --sign

# Export as CSV
npx agentproofs export --format csv

# Share your public key
npx agentproofs pubkey
# > ed25519:MCowBQYDK2Vw...

Event types

agentproofs captures 18 event types:

EventWhen
session_startedAgent session begins
session_endedAgent session ends
tool_startedBefore tool execution
tool_completedTool finished successfully
tool_failedTool returned error
tool_deniedUser denied tool permission
decisionAgent made explicit decision
delegation_startedAgent delegated to sub-agent
delegation_completedSub-agent returned
approval_requestedAgent asked user for approval
approval_grantedUser approved
approval_deniedUser denied
policy_violationAction blocked by policy
checkpoint_createdChain checkpoint recorded
key_rotatedSigning key changed
daemon_startedDaemon process started
daemon_stoppedDaemon process stopping
errorUnexpected error

Privacy

DataStored?How
Tool nameYesPlain text
Input contentNoOnly SHA-256 hash
Output contentNoOnly SHA-256 hash
SummariesOptionalOpt-in per event
Working directoryYesPlain text
TimestampYesISO 8601 UTC
Agent/session IDYesPlain text

To prove what happened without revealing content:

  • Show the proof entry (with input_hash)
  • Auditor computes SHA-256 of the claimed input
  • Hashes match = proven that this input was used

Threat model

Be honest about what this protects against:

ThreatProtected?Notes
Post-hoc tampering (no key access)YesHash chain breaks
Entry deletionYesSequence gaps detected
Entry insertionYesHash linkage breaks
Forged proofs (external)YesSignature check fails
Host compromise with key accessNo (v1)Attacker can rewrite + re-sign
Events never capturedNoCan't prove what wasn't logged

Trust level L0 (v1): Tamper-evident on host, assuming key integrity. Suitable for personal audit trails and team accountability.

Future versions add external anchoring (L1), hardware-backed keys (L2), and federated witnesses (L3).

Architecture

Single-writer daemon ensures no race conditions:

Hook/SDK  -->  Unix socket  -->  Daemon (single writer)  -->  JSONL segments
                                  |-- assign sequence
                                  |-- compute hash
                                  |-- sign (Ed25519)
                                  |-- append + fsync

Storage:

~/.agentproofs/
  segments/         # Append-only JSONL proof chain
  manifests/        # Signed segment digests
  keys/             # Ed25519 keypair
  checkpoints/      # External anchors (v2)
  exports/          # Audit exports

EU AI Act

agentproofs is designed to support the logging and traceability obligations under EU AI Act Articles 12 and 19, where applicable. It is not a compliance certification — compliance depends on risk classification of your specific use case.

Configuration

All via environment variables:

VariableDefaultDescription
AGENTPROOFS_DATA_DIR~/.agentproofs/Base data directory
AGENTPROOFS_AGENT_IDclaude-codeAgent identifier
AGENTPROOFS_NAMESPACEdefaultDefault namespace
AGENTPROOFS_REDACTION_LEVEL0Privacy level (0-3)
AGENTPROOFS_SEGMENT_SIZE10000Max proofs per segment

Development

# Install
npm install

# Test
npm test

# Build
npm run build

# Type check
npm run typecheck

License

MIT

Keywords

ai

FAQs

Package last updated on 06 Apr 2026

Related posts