Agent Execution Receipts
Use this skill when the user asks who or what ran a command, whether an agent action reached a provider, or which agent-originated changes lack provider attribution.
Procedure
- Open the Cerebro Agent Receipts app or read
receipts.ndjsonfrom the configured receipt directory. - Verify each receipt signature and the append-only digest chain before using it as evidence.
- Import a CloudTrail
LookupEventsresponse when provider observations are available. - Report one of three states without collapsing them:
Local evidence only: a signed local receipt exists.Candidate correlation: one provider event has a one-to-one evidence match, but no trusted binding.Provider bound: an authenticated provider event passes the configured account, dedicated role, action ID, action, and time checks.
- Start from the provider-event population and identify every provider mutation without a completed one-to-one action match.
Never treat a process name, user agent, startedBy value, local transcript, session-wide identifier, or user-imported JSON as provider-bound attribution.