Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    mcp audit trail generator

    1

    Design compliance-ready audit trail schemas for MCP servers mapped to SOC 2 and ISO 27001 controls.

    $12

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned
    mcp audit trail generator

    mcp audit trail generator

    Example session with this skill installed

    I need an audit trail schema for my MCP server to satisfy SOC 2 CC7.2. We currently only log to stdout via the standard TypeScript SDK logger.

    • Read your context and instructions
    • Compiled the mcp audit trail
    • Generated the document

    I have analyzed your current logging state. Standard stdout logging in the MCP SDK is typically request-scoped and lacks the durable, structured fields required for CC7.2 anomaly analysis.

    MCP Audit-Trail Schema Design

    FieldTypeSource / DerivationCompliance Correlation
    timestampISO8601Server-side clock at invocation startISO A.8.15 (Date/Time)
    caller_idStringVerified session/auth token (not client-provided)SOC 2 CC6.1; ISO A.8.15 (User-ID)
    tool_nameStringcallTool request name parameterISO A.8.15 (Event Type)
    argumentsJSONRedacted/Allowlisted per tool definitionInternal Accountability
    outcomeEnumSuccess/Error code + exception classSOC 2 CC7.2 (Anomaly Raw Material)
    session_idUUIDTransport-layer correlation IDISO A.8.15 (Network Address/Origin)

    Implementation Strategy (TypeScript)

    // Middleware wrapper for MCP tool handlers
    async function withAuditLogging(name: string, args: any, handler: Function) {
      const startTime = new Date().toISOString();
      const caller = getVerifiedCaller(); // From session context
      
      try {
        const result = await handler(args);
        await logToPersistentStore({
          timestamp: startTime,
          caller_id: caller,
          tool_name: name,
          arguments: redactArgs(name, args),
          outcome: 'SUCCESS',
          duration_ms: Date.now() - new Date(startTime).getTime()
        });
        return result;
      } catch (error) {
        await logToPersistentStore({
          timestamp: startTime,
          caller_id: caller,
          tool_name: name,
          arguments: redactArgs(name, args),
          outcome: `ERROR: ${error.constructor.name}`
        });
        throw error;
      }
    }
    

    Next steps

    1. Define a redactArgs allowlist for your specific tools to prevent PII leakage.
    2. Select a persistent storage backend (e.g., CloudWatch, ELK, or a dedicated SQL table).
    3. Document your retention period based on your SOC 2 observation window.

    mcp-audit-trail-generator.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Map MCP tool logs to SOC 2 CC7.2 and ISO 27001 Annex A.8.15 requirements.Design per-tool redaction strategies to keep PII and secrets out of logs.Identify gaps in existing MCP server logging versus auditor expectations.Create implementation-ready schema definitions for MCP logging middleware.

    About this skill

    The Model Context Protocol (MCP) spec lacks a durable invocation-logging standard, leaving teams exposed during SOC 2 or ISO 27001 audits. This skill designs a compliance-grade audit-trail schema that maps tool calls to specific regulatory controls. It bridges the gap between raw tool execution and the structured records auditors require.

    What it does

    • Schema design defines a structured field set (who, what, when, origin, payload, outcome) for tool invocations.
    • Compliance mapping correlates specific log fields to SOC 2 CC7.2/CC6 and ISO 27001 Annex A.8.15.
    • Payload redaction establishes per-tool allowlists and hashing strategies to prevent logging secrets or PII.
    • Gap analysis audits existing MCP server logs against the target schema to identify missing data points.
    • Retention documentation drafts policy language based on actual business drivers rather than arbitrary mandates.

    How it works

    1. Inventory the current logging state of your MCP servers, including output destinations and captured fields.
    2. Audit the existing logs against the target schema to report gaps in caller identity or outcome tracking.
    3. Generate the field-by-field schema, mapping each element to its primary or secondary compliance source.
    4. Configure redaction rules for every tool exposed by the server to handle sensitive arguments safely.

    Frameworks & tools

    Model Context Protocol (MCP), SOC 2 (Trust Services Criteria), ISO 27001, and implementation snippets for MCP SDKs (TypeScript/Python).

    Why this beats prompting it yourself

    Generic prompts often suggest logging raw tool arguments, which creates a security risk by leaking API keys or PII into log files. This skill enforces a redaction-first design and uses precise, sourced correlations to compliance frameworks instead of vague regulatory claims.

    Use cases

    • Designing the logging middleware for a new production-grade MCP server.
    • Preparing for a SOC 2 Type II audit where MCP tool usage is in scope.
    • Hardening an existing MCP deployment against PII leakage in debug logs.
    • Documenting log retention policies for cyber-insurance or contractual requirements.

    Known limitations

    Does not generate actual evidence artifacts or perform runtime log enforcement. Cannot issue formal compliance verdicts. Not for finding code-level security vulnerabilities.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 1 day ago

    • Passed all security checks, Safe to install

    Listed1 day ago

    What's inside

    Frequently Asked Questions