- Home
- Skills
- DevOps & Cloud
- evidence packets
evidence packets
Generate defensible, hashed evidence packets for infrastructure changes and audit trails.
$9
Works with the AI tools you already use
evidence packets
Example session with this skill installed
Generate an evidence packet for updating the Nginx configuration to enable TLS 1.3 on the production load balancer.
- Read your context and instructions
- Compiled the evidence packets
I have initiated the evidence packet for the TLS 1.3 upgrade. All pre-state captures are complete, the configuration has been applied, and independent verification confirms the protocol is active.
Evidence Packet: evidence/20231027-nginx-tls-upgrade/
| File | Description | Status |
|---|---|---|
00-node-identity.txt | Host: lb-prod-01, IP: 10.0.0.5, Date: 2023-10-27T14:00Z | Captured |
03-ruleset-before.raw.txt | Output of nginx -T showing TLS 1.2 only | Captured |
05-action-update.txt | sed command to update config + systemctl reload nginx | Success |
08-steady-state.txt | journalctl -u nginx showing no worker crashes after 60s | Verified |
11-independent-readback.txt | Output of openssl s_client -connect localhost:443 -tls1_3 | Verified |
12-gate-evidence.txt | Checklist: TLS 1.3 handshake successful, TLS 1.1 rejected | Passed |
MANIFEST.sha256 | SHA256 hashes for all 7 generated artifacts | Validated |
Next steps
- Review the
11-independent-readback.txtfile to confirm the handshake details. - Commit the
evidence/20231027-nginx-tls-upgrade/directory to the infrastructure repository. - Archive the legacy TLS 1.2 configuration snippets stored in the pre-state logs.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Manual infrastructure changes often lack the audit trail required for compliance, troubleshooting, or peer review. This skill generates structured evidence packets that prove exactly what changed, why it happened, and how it was verified.
What it does
- State snapshots captures raw system state before and after execution to prevent "works on my machine" ambiguity.
- Audit logging records exact shell commands alongside full stdout/stderr output without paraphrasing.
- Independent verification validates changes using a secondary tool or path to confirm the primary tool reported correctly.
- Integrity hashing generates a SHA256 manifest of all artifacts to ensure the audit trail remains immutable.
- Redaction handling automatically scrubs sensitive credentials from captured logs while preserving the trace context.
How it works
- Define criteria by setting success gates before any infrastructure commands are executed.
- Capture pre-state using raw tool outputs to document the environment preconditions.
- Execute and log the migration or configuration change in a strictly numbered sequence.
- Run readback via a different access path to provide objective proof of the new state.
- Finalize manifest by hashing all files into a signed
MANIFEST.sha256file within the evidence directory.
Frameworks & tools
Works with any CLI-based infrastructure tool including terraform, kubectl, iptables, systemd, and standard Linux networking/storage utilities.
Why this beats prompting it yourself
Generic prompts often summarize output or skip the "before" state, making them useless for audits. This skill enforces a strict, numbered file structure and mandatory independent readback that satisfies technical due diligence requirements.
Use cases
- Firewall updates to prove a specific port was opened and verify it via external scan.
- Cloud migrations to document resource capacity before moving workloads.
- Permission changes to audit IAM or filesystem access levels for compliance reviews.
- Service deployments to track the delta between a broken and working configuration.
Known limitations
Does not automatically mask custom proprietary secret formats; manual redaction markers may be needed for non-standard environment variables. Requires filesystem write access for the evidence directory.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 3 days ago
- Passed all security checks, Safe to install