verify_audit_chain

Auto-generated from the registered MCP tool descriptions and input schemas. Do not edit by hand — run pnpm docs:tools to regenerate.

Verify the hash chain of a persisted FileAuditStorage audit log directory (#2281 follow-up). Reads all audit-*.jsonl files, parses events, runs verifyChain() to detect tampering. Returns eventCount, fileCount, and one of three tamper signals (hash_mismatch, previous_hash_mismatch, missing_hash) if detected. Read-only.

Parameters

Parameter Type Required Constraints Description
logDir string yes minLength 1; maxLength 512 Filesystem path to the FileAuditStorage log directory. Must lie inside the nexus data dir, a repo-local .nexus-agents/, or the configured security.audit.logDir. Tool reads all audit-*.jsonl files in lexicographic order and verifies the combined chain.
filePrefix string no minLength 1; maxLength 64; default audit Filename prefix for audit log files (defaults to “audit”). Files matching ${filePrefix}-*.jsonl will be verified.