Cryptographic audit trail for AI agents — sign, chain-verify and export every decision. GDPR / HIPAA / EU AI Act ready. Free & open source.
The server provides 4 cryptographic audit tools with reasonable descriptions and schemas, but lacks critical details for LLM reliability. Descriptions are domain-specific and mention compliance requirements (GDPR, HIPAA, EU AI Act), which is helpful context. However, parameter descriptions are sparse or missing in critical areas (e.g., piqrypt_verify_chain's 'events' param lacks specifics on expected structure), and output schemas are entirely undocumented. Tool names follow verb_noun pattern correctly (stamp, verify, export, search), but error handling guidance is absent, the code throws generic errors without recovery hints. Security and composition are reasonable (tools do single things, chain operations via hash/event references), but the server lacks validation examples, input constraints (e.g., agent_id format, timestamp bounds), and per-parameter type enforcement beyond basic JSON Schema.
Export the complete agent audit trail to a portable JSON archive. Set certified=true to request a PiQrypt CA signature for legal admissibility (eIDAS Art.26). The export is self-contained and verifiable without PiQrypt installed.
Search the agent's cryptographic event history by type, time range, or session. Returns signed events with chain metadata. Use to reconstruct what an agent did during a specific period.
Create a tamper-proof cryptographic record of an agent decision. Signs the event with Ed25519, links it to the previous event in a hash chain (AISS v2.0). Call this after every significant agent action. Required for GDPR Art.22, EU AI Act Art.13, HIPAA audit trail, SEC/FINRA trading compliance.
Verify that an agent's decision history is intact and untampered. Detects modified events, missing events, hash chain breaks, and forks. Call before trusting any historical agent output.
Output schemas completely undocumented. No definition of what piqrypt_stamp_event, piqrypt_verify_chain, piqrypt_export_audit, or piqrypt_search_events return. LLMs cannot predict the structure of responses, complicating downstream tool composition and response parsing.
Parameter 'events' in piqrypt_verify_chain has minimal description ('Array of PiQrypt events to verify'). No specification of required fields within each event object, expected format, or schema validation. LLMs will guess at structure, likely passing malformed data.
No input validation or error recovery guidance in tool implementations. callPythonBridge throws generic errors ('PiQrypt bridge error: <stderr>'). No actionable error messages telling the LLM what to do next (e.g., 'Agent ID not found. Valid IDs: ...' or 'Invalid timestamp range.')
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 57 | 2026-07-28+ | v2 |
| 2026-03-09 | D | 53 | - | v1 |
Parameter 'agent_id' lacks format constraints. No specification of valid characters, length, or examples. LLMs may pass invalid IDs without guidance. Constraint description should state format rules (e.g., '2-64 alphanumeric chars, underscore allowed').
Numeric parameters 'from_timestamp', 'to_timestamp', and 'limit' in piqrypt_search_events lack bounds. Description says 'Unix UTC seconds' and 'Maximum number of results' with default 100, but no explicit min/max constraints in schema. Unbounded timestamps can cause API misuse.
piqrypt_verify_chain returns early exit if required 'events' array is omitted, but schema lists required: ['events']. However, the items schema is generic object with no required fields, structure validation is delegated entirely to the Python backend. Type safety is minimal.
piqrypt_export_audit's 'certified' parameter description mentions 'requires Pro license' but does not explain the consequence of passing certified=true without a license. Will the tool error gracefully, or silently downgrade? Ambiguous behavior.
Tool descriptions mention compliance standards (GDPR Art.22, EU AI Act, HIPAA, FINRA) but do not link to the actual audit output structure or explain how returned data maps to compliance requirements. LLMs cannot verify compliance from the tool alone.