verify_audit_chain
Auto-generated from the registered MCP tool descriptions and input schemas. Do not edit by hand — run
pnpm docs:toolsto regenerate.
Verify the hash chain of a persisted FileAuditStorage audit log directory (#2281 follow-up). Reads all audit-*.jsonl files, parses events, runs verifyChain() to detect tampering. Returns eventCount, fileCount, and one of three tamper signals (hash_mismatch, previous_hash_mismatch, missing_hash) if detected. Read-only.
Parameters
| Parameter | Type | Required | Constraints | Description |
|---|---|---|---|---|
logDir |
string | yes | minLength 1; maxLength 512 | Filesystem path to the FileAuditStorage log directory. Must lie inside the nexus data dir, a repo-local .nexus-agents/, or the configured security.audit.logDir. Tool reads all audit-*.jsonl files in lexicographic order and verifies the combined chain. |
filePrefix |
string | no | minLength 1; maxLength 64; default audit | Filename prefix for audit log files (defaults to “audit”). Files matching ${filePrefix}-*.jsonl will be verified. |