JSPM

@builtbyecho/trustlog

0.2.1
  • ESM via JSPM
  • ES Module Entrypoint
  • Export Map
  • Keywords
  • License
  • Repository URL
  • TypeScript Types
  • README
  • Created
  • Published
  • Downloads 11
  • Score
    100M100P100Q72231F
  • License MIT

Human-readable receipts for agent work.

Package Exports

    This package does not declare an exports field, so the exports above have been automatically detected and optimized by JSPM instead. If any package subpath is missing, it is recommended to post an issue to the original package (@builtbyecho/trustlog) to support the "exports" field. If that is not possible, create a JSPM override to customize the exports field for this package.

    Readme

    Trust Log

    Human-readable receipts for agent work.

    Don’t ask humans to blindly trust agents. Give them a Trust Log.

    Trust Log wraps commands and produces clean Markdown + JSON receipts with:

    • command, duration, exit code, and working directory
    • git branch/commit/status scoped to the current project
    • changed file list and diff stats when available
    • secret redaction for common API keys/tokens
    • <think>...</think> / reasoning-block stripping
    • risk flags for destructive commands, external actions, failures, redactions, and file changes
    • receipt verification with trustlog verify so CI/agents can reject receipts that still contain likely secrets or thinking blocks
    • redacted command argv storage (the raw command is represented by a SHA-256 hash, not leaked in plaintext)

    Install

    npm install -g @builtbyecho/trustlog

    Local development:

    npm link

    Usage

    trustlog run -- npm test
    trustlog run -- node script.js
    trustlog summarize .trustlog/latest.json
    trustlog verify .trustlog/latest.json

    Receipts are written to .trustlog/ by default:

    • timestamped .json
    • timestamped .md
    • latest.json
    • latest.md

    Verify Receipts

    Use trustlog verify before attaching receipts to pull requests, tickets, or chat handoffs:

    trustlog verify .trustlog/latest.json

    Verification checks the receipt schema, required fields, command hash, redacted command argv, output previews, and that visible receipt content does not still contain obvious secrets or thinking/reasoning-looking blocks.

    Why

    AI agents are useful, but people get nervous when they cannot tell what happened. Trust Log gives humans a simple receipt: what ran, what changed, what looked risky, and what was redacted — without exposing private chain-of-thought.

    Monetization Direction

    Trust Log should stay local-first and useful for free. Paid cloud features can add hosted receipts, team audit history, private share links, API ingestion, and compliance retention. See docs/stripe-integration-reference.md.

    Agent Skills

    This package includes OpenClaw/Claude-style skills under skills/:

    • skills/trustlog — teach agents to create, summarize, and verify Trust Log receipts.
    • skills/agent-work-receipts — meta workflow combining repo-agent-brief, agent-runlog, trustlog, and add-ci --dry-run.