Agent skill

Audit Logging

Audit logging is a critical security and compliance practice that records system events, user actions, and data access patterns. This skill provides comprehensive patterns for implementing audit loggi

Stars 163
Forks 31

Install this agent skill to your Project

npx add-skill https://github.com/majiayu000/claude-skill-registry/tree/main/skills/other/other/audit-logging-amnadtaowsoam-cerebraskills

SKILL.md

Audit Logging

Skill Profile

(Select at least one profile to enable specific modules)

  • DevOps
  • Backend
  • Frontend
  • AI-RAG
  • Security Critical

Overview

Audit logging is a critical security and compliance practice that records system events, user actions, and data access patterns. This skill provides comprehensive patterns for implementing audit logging systems that meet various compliance frameworks including GDPR, HIPAA, PCI DSS, SOX, and ISO 27001.

Why This Matters

Audit logging is essential for:

  • Compliance: Meeting regulatory requirements for data protection and security
  • Security: Detecting and investigating security incidents
  • Accountability: Tracking who did what, when, and how
  • Forensics: Providing evidence for investigations
  • Risk Management: Identifying patterns of suspicious activity

Core Concepts & Rules

1. Core Principles

  • Follow established patterns and conventions
  • Maintain consistency across codebase
  • Document decisions and trade-offs

2. Implementation Guidelines

  • Start with the simplest viable solution
  • Iterate based on feedback and requirements
  • Test thoroughly before deployment

Inputs / Outputs / Contracts

  • Inputs:
    • <e.g., env vars, request payload, file paths, schema>
  • Entry Conditions:
    • <Pre-requisites: e.g., Repo initialized, DB running, specific branch checked out>
  • Outputs:
    • <e.g., artifacts (PR diff, docs, tests, dashboard JSON)>
  • Artifacts Required (Deliverables):
    • <e.g., Code Diff, Unit Tests, Migration Script, API Docs>
  • Acceptance Evidence:
    • <e.g., Test Report (screenshot/log), Benchmark Result, Security Scan Report>
  • Success Criteria:
    • <e.g., p95 < 300ms, coverage ≥ 80%>

Skill Composition

  • Depends on: None
  • Compatible with: None
  • Conflicts with: None
  • Related Skills: None

Quick Start / Implementation Example

  1. Review requirements and constraints
  2. Set up development environment
  3. Implement core functionality following patterns
  4. Write tests for critical paths
  5. Run tests and fix issues
  6. Document any deviations or decisions
python
# Example implementation following best practices
def example_function():
    # Your implementation here
    pass

Assumptions

  • System has access to persistent storage for logs
  • Time synchronization is available across services
  • User identification is available for logged events

Compatibility

  • PostgreSQL 12+
  • Node.js 14+
  • Elasticsearch 7+ (for log aggregation)
  • Any web framework (Express, Fastify, etc.)

Test Scenario Matrix

Scenario Input Expected Output Priority
Log authentication event User login data Audit log entry created P0
Query audit trail User ID, date range All events for user P0
Export logs Query, format JSON/CSV export P1
Check compliance Framework name Compliance report P0
Apply retention Days threshold Old logs archived P1
Verify immutability Log chain Integrity verified P0

Technical Guardrails & Security Threat Model

1. Security & Privacy (Threat Model)

  • Top Threats: Injection attacks, authentication bypass, data exposure
  • Data Handling: Sanitize all user inputs to prevent Injection attacks. Never log raw PII
  • Secrets Management: No hardcoded API keys. Use Env Vars/Secrets Manager
  • Authorization: Validate user permissions before state changes

2. Performance & Resources

  • Execution Efficiency: Consider time complexity for algorithms
  • Memory Management: Use streams/pagination for large data
  • Resource Cleanup: Close DB connections/file handlers in finally blocks

3. Architecture & Scalability

  • Design Pattern: Follow SOLID principles, use Dependency Injection
  • Modularity: Decouple logic from UI/Frameworks

4. Observability & Reliability

  • Logging Standards: Structured JSON, include trace IDs request_id
  • Metrics: Track error_rate, latency, queue_depth
  • Error Handling: Standardized error codes, no bare except
  • Observability Artifacts:
    • Log Fields: timestamp, level, message, request_id
    • Metrics: request_count, error_count, response_time
    • Dashboards/Alerts: High Error Rate > 5%

Agent Directives & Error Recovery

(ข้อกำหนดสำหรับ AI Agent ในการคิดและแก้ปัญหาเมื่อเกิดข้อผิดพลาด)

  • Thinking Process: Analyze root cause before fixing. Do not brute-force.
  • Fallback Strategy: Stop after 3 failed test attempts. Output root cause and ask for human intervention/clarification.
  • Self-Review: Check against Guardrails & Anti-patterns before finalizing.
  • Output Constraints: Output ONLY the modified code block. Do not explain unless asked.

Definition of Done (DoD) Checklist

  • Tests passed + coverage met
  • Lint/Typecheck passed
  • Logging/Metrics/Trace implemented
  • Security checks passed
  • Documentation/Changelog updated
  • Accessibility/Performance requirements met (if frontend)

Anti-patterns

  • Logging Everything: Only log what's required for compliance
  • Synchronous Logging: Use async logging to avoid performance impact
  • Storing PII in Logs: Mask or hash sensitive data
  • No Retention Policy: Implement automated retention
  • Ignoring Failed Logs: Monitor and alert on failures

Reference Links & Examples

  • Internal documentation and examples
  • Official documentation and best practices
  • Community resources and discussions

Versioning & Changelog

  • Version: 1.0.0
  • Changelog:
    • 2026-02-22: Initial version with complete template structure

Expand your agent's capabilities with these related and highly-rated skills.

Didn't find tool you were looking for?

Be as detailed as possible for better results