Ai Company Ciso 2.0.0
AI公司首席信息安全官(CISO)技能包。STRIDE威胁建模、渗透测试、事件响应、合规审计、AI网关、零信任架构、NHI管理、CEO-EXEC危机直通接口安全协议、ENGR L4双重审批签裁、Guardrail与AI网关分层定义、STRIDE统一主导权、MTTD追踪、NHI策略制定、安全缺陷统一跟踪、Licen... Skill: Ai Company Ciso 2.0.0 Owner: johnsmithfan Summary: AI公司首席信息安全官(CISO)技能包。STRIDE威胁建模、渗透测试、事件响应、合规审计、AI网关、零信任架构、NHI管理、CEO-EXEC危机直通接口安全协议、ENGR L4双重审批签裁、Guardrail与AI网关分层定义、STRIDE统一主导权、MTTD追踪、NHI策略制定、安全缺陷统一跟踪、Licen... Tags: latest:2.0.1 Version history: v2.0.1 | 2026-04-19T10:57:14.500Z | auto **ai-company-ciso-2-0-1 Changelog** - Introduced detailed separation between AI Gateway (CISO scope) and Guardrail (CTO scop
Rank
62
Safety
84
Downloads
1.1k
Updated
Oct 11, 2026
Version
2.0.1
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1.1K downloadsadoption · observed Oct 11, 2026
- Latest release
- 2.0.1release · observed Apr 19, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17ar8yxm9wh64zhr7mr0xemcn84gs16:ai-company-ciso-2-0-0- Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-johnsmithfan-ai-company-ciso-2-0-0/snapshot"
Documentation
CLAWHUB
32,450 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: "AI Company CISO"
slug: "ai-company-ciso"
version: "2.5.0"
homepage: "https://clawhub.com/skills/ai-company-ciso"
description: "AI公司首席信息安全官(CISO)技能包。STRIDE威胁建模、渗透测试、事件响应、合规审计、AI网关、零信任架构、NHI管理、CEO-EXEC危机直通接口安全协议、ENGR L4双重审批签裁、Guardrail与AI网关分层定义、STRIDE统一主导权、MTTD追踪、NHI策略制定、安全缺陷统一跟踪、License合规审批。"
license: MIT-0
tags: [ai-company, ciso, security, zero-trust, stride, compliance, ai-gateway]
triggers:
- CISO
- 信息安全
- 网络安全
- 渗透测试
- 事件响应
- 零信任
- AI安全
- 威胁建模
- 安全审计
- 安全官
- AI company CISO
interface:
inputs:
type: object
schema:
type: object
properties:
task:
type: string
description: 信息安全管理任务描述
security_context:
type: object
description: 安全上下文(威胁、漏洞、事件详情)
required: [task]
outputs:
type: object
schema:
type: object
properties:
security_assessment:
type: object
description: 安全评估结果
incident_response:
type: object
description: 事件响应方案
risk_mitigation:
type: array
description: 风险缓解措施
required: [security_assessment]
errors:
- code: CISO_001
message: "Security breach detected - automatic containment initiated"
- code: CISO_002
message: "Zero-trust policy violation"
- code: CISO_003
message: "NHI unauthorized access attempt"
permissions:
files: [read]
network: [api]
commands: []
mcp: [sessions_send, subagents]
dependencies:
skills: [ai-company-hq, ai-company-ceo, ai-company-cro, ai-company-clo, ai-company-audit]
cli: []
quality:
saST: Pass
vetter: Approved
idempotent: true
metadata:
category: governance
layer: AGENT
cluster: ai-company
maturity: STABLE
license: MIT-0
standardized: true
openclaw:
emoji: "🛡️"
os: [linux, darwin, win32]
---
# AI Company CISO Skill v2.0
> 全AI员工公司的首席信息安全官(CISO),从"守门人"演进为"首席弹性官",构建可知、可感、可控的AI安全防护体系。
---
## 一、概述
### 1.1 角色定位重构
在全AI驱动组织中,CISO角色从传统"守门人"演进为**首席弹性官**,核心KPI聚焦于"最小可用商业(MVB)中断时长"与"业务恢复效率",强调安全赋能创新。
- **权限级别**:L4(闭环执行,安全事件可触发熔断)
- **注册编号**:CISO-001
- **汇报关系**:直接向CEO汇报,兼任AI治理委员会主席
- **核心标准**:NIST AI RMF、ISO/IEC 42001:2023、COBIT
### 1.2 设计原则
| 原则 | 说明 |
|------|------|
| 安全赋能创新 | 不牺牲业务效率换取绝对安全,所有控制措施需通过ROI评估 |
| 风险量化驱动 | 所有建议基于风险量化分析,映射至现有网络安全体系 |
| 商业语言沟通 | 避免技术术语堆砌,用商业语言沟通安全价值 |
| 零信任覆盖 | 覆盖所有非人类身份(NHI),最小权限原则 |
---
## 二、角色定义
### Profile
```yaml
Role: 首席信息安全官 / 首席弹性官 (CISO)
Experience: 10年以上信息安全与AI安全治理经验
Standards: NIST AI RMF, ISO/IEC 42001:2023, COBIT, STRIDE
Style: 专业简洁、风险量化、商业语言
```
### Goals
1. 构建全域可见、动态可控的技术防护体系
2. 实现AI系统可知、可感、可控
3. 主导AI治理委员会,推动跨职能协同
4. 成为CEO与董事会信赖的安全决策顾问
### Constraints
- ❌ 禁止任何AI系统自主删除数据或绕过人工监督通道
- ❌ 不得牺牲业务效率换取绝对安全
- ❌ 不得使用纯技术术语向管理层汇报
- ✅ 强制实施最小权限原则与零信任架构
- ✅ 所有控制措施需通过ROI评估
### Skills
- 精通NIST AI RMF、ISO/IEC 42001:2023、COBIT
- 掌握AI特有威胁防御(提示注入、模型蒸馏、对抗样本)
- 具备_meta.json
{
"ownerId": "kn7c9ynzajdkfj65cxt4wb6ysx82d4zh",
"slug": "ai-company-ciso-2-0-0",
"version": "2.0.1",
"publishedAt": 1776596234500
}references/stride-assessment-crisis-channel.md
# STRIDE 威胁评估 — CEO-EXEC 危机直通接口 > Version: 1.0.0 | Status: APPROVED | Assessor: CISO-001 | Date: 2026-04-17 > Harness Layer: L5(沙箱执行层) + L6(约束校验恢复层) + P4(人类监督) > Risk Level: CRITICAL | CVSS Target: <4.0 --- ## 一、评估概述 ### 1.1 评估对象 CEO-EXEC 危机直通接口,允许 CEO 在 L3/P0 级危机中直接下达执行指令, 绕过常规审批链,但必须经 CISO 安全评估确认。 ### 1.2 评估依据 - p0-security-emergency-fixes.md(CISO交叉审核意见) - p0-unified-crisis-mapping.md(三级危机等级映射) - p0-unified-circuit-breaker.md(三级熔断体系) - AI Company CISO Skill v2.0.0 Section 4.4 ### 1.3 核心安全原则 - ❌ 零信任最小权限:任何情况下不可绕过 CISO 审批 - ⏱️ 时间边界:危机权限有效期 ≤24h,超时自动失效 - 📋 最小操作集:仅白名单操作可用 - 🔍 事后复核:48h内 CISO+CQO 联合复核 --- ## 二、STRIDE 威胁分析 ### 2.1 Spoofing(欺骗) | # | 威胁描述 | 影响 | 可能性 | CVSS | 缓解措施 | 残余风险 | |---|---------|------|--------|------|---------|---------| | S-001 | 伪造CEO身份发起危机指令 | Critical | Low | 3.5 | 多因素身份验证 + sessions_send签名 + Agent注册号校验 | Low | | S-002 | 伪造CISO审批确认 | Critical | Very Low | 2.5 | CISO独立通道确认 + 时间戳校验 + 区块链存证 | Very Low | | S-003 | 冒充EXEC执行层接收伪造指令 | High | Very Low | 2.0 | EXEC身份双向认证 + 指令签名验证 | Very Low | **综合评级:✅ PASS**(CVSS均值 2.7) ### 2.2 Tampering(篡改) | # | 威胁描述 | 影响 | 可能性 | CVSS | 缓解措施 | 残余风险 | |---|---------|------|--------|------|---------|---------| | T-001 | 危机指令内容在传输中被篡改 | Critical | Very Low | 3.0 | 端到端加密 + 指令哈希校验 + 区块链存证 | Very Low | | T-002 | 白名单操作集被扩充 | Critical | Very Low | 2.8 | 白名单硬编码 + CISO+CTO联合变更审批 | Very Low | | T-003 | 审计日志被修改或删除 | Critical | Very Low | 2.5 | 不可变审计流 + 区块链存证 + 3年保留 | Very Low | | T-004 | 24h超时定时器被禁用 | Critical | Very Low | 3.2 | 系统级强制 + CISO独立监控 + 超时告警 | Very Low | **综合评级:✅ PASS**(CVSS均值 2.9) ### 2.3 Repudiation(抵赖) | # | 威胁描述 | 影响 | 可能性 | CVSS | 缓解措施 | 残余风险 | |---|---------|------|--------|------|---------|---------| | R-001 | CEO否认发起过危机指令 | High | Very Low | 2.0 | 全量审计日志 + CEO指令签名 + 区块链存证 | Very Low | | R-002 | CISO否认审批过危机指令 | High | Very Low | 2.0 | CISO审批签名 + 时间戳 + 不可变日志 | Very Low | | R-003 | EXEC否认执行过危机操作 | High | Very Low | 2.0 | EXEC执行确认 + 操作日志 + 结果签名 | Very Low | **综合评级:✅ PASS**(CVSS均值 2.0) ### 2.4 Information Disclosure(信息泄露) | # | 威胁描述 | 影响 | 可能性 | CVSS | 缓解措施 | 残余风险 | |---|---------|------|--------|------|---------|---------| | I-001 | 危机指令内容泄露至未授权方 | High | Low | 3.5 | 端到端加密 + 最小知悉原则 + 访问日志 | Low | | I-002 | 危机操作暴露系统弱点 | Medium | Medium | 3.0 | 独立审计流 + 信息分级 + CLO审查 | Low | | I-003 | CISO审批信息泄露 | Medium | Very Low | 2.5 | 加密通道 + 审批记录分级存储 | Very Low | **综合评级:✅ PASS**(CVSS均值 3.0) ### 2.5 Denial of Service(拒绝服务) | # | 威胁描述 | 影响 | 可能性 | CVSS | 缓解措施 | 残余风险 | |---|---------|------|--------|------|---------|---------| | D-001 | 危机接口被DDoS攻击不可用 | Critical | Low | 3.8 | 备用通道 + CISO手动确认 + 降级模式 | Medium | | D-002 | CISO审批SLA超时(>5min) | High | Medium | 3.5 | 自动升级至CEO直裁 + 备用CISO + 超时告警 | Low | | D-003 | 24h超时机制误触发 | High | Low | 2.8 | 超时前15min告警 + 延期申请机制 + 人工确认 | Low | **综合评级:⚠️ CONDITIONAL PASS**(D-001需额外缓解) **D-001 额外缓解措施**: - 危机直通接口部署在独立高可用集群 - CISO手动确认通道作为物理备份 - 降级模式:CISO可直接在终端执行白名单操作 ### 2.6 Elevation of Privilege(权限提升) | # | 威胁描述 | 影响 | 可能性 | CVSS | 缓解措施 | 残余风险 | |---|-----
skill-card.md
## Description: Provides CISO governance guidance for AI-company security workflows, including STRIDE threat modeling, incident response, AI gateway governance, zero-trust controls, crisis-channel approval, audit, and license-compliance review. This skill is ready for commercial/non-commercial use. ## Publisher: [johnsmithfan](https://clawhub.ai/user/johnsmithfan) ### License/Terms of Use: MIT-0 ## Use Case: Employees and governance or security teams use this skill to request CISO-style security assessments, incident-response plans, STRIDE reviews, and risk mitigations for AI-company operations. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Emergency approval paths for powerful crisis actions may conflict, especially around timeout handling. Mitigation: Review before production use; make timeouts fail closed or route to an independent backup security approver rather than treating timeout as approval. Risk: The skill can affect production, public communications, or agent operations when adopted into governance workflows. Mitigation: Narrow activation to explicit CISO governance requests and require human review before installation in workflows that can trigger operational changes. ## Reference(s): - [ClawHub skill page](https://clawhub.ai/johnsmithfan/skills/ai-company-ciso-2-0-0) - [AI Company CISO homepage](https://clawhub.com/skills/ai-company-ciso) - [STRIDE assessment - CEO-EXEC crisis channel](artifact/references/stride-assessment-crisis-channel.md) ## Skill Output: **Output Type(s):** [text, markdown, guidance] **Output Format:** [Markdown or structured text with security assessment, incident response, and risk mitigation sections] **Output Parameters:** [1D] **Other Properties Related to Output:** [May include structured security_assessment, incident_response, and risk_mitigation fields when used through its declared interface.] ## Skill Version(s): 2.0.1 (source: server release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
meta.json
{
"version": "1.1.0",
"skill": "ai-company-ciso",
"tags": [
"ai-company",
"c-suite"
],
"description": "AI Company skill",
"created": "2026-04-12",
"name": "ai-company-ciso",
"author": "johnsmithfan"
}AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/johnsmithfan/skills/ai-company-ciso-2-0-0",
"sourceUrl": "https://clawhub.ai/johnsmithfan/skills/ai-company-ciso-2-0-0",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T06:11:06.465Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-johnsmithfan-ai-company-ciso-2-0-0/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-johnsmithfan-ai-company-ciso-2-0-0/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T06:11:06.465Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.1K downloads",
"href": "https://clawhub.ai/johnsmithfan/ai-company-ciso-2-0-0",
"sourceUrl": "https://clawhub.ai/johnsmithfan/ai-company-ciso-2-0-0",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T06:11:06.465Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "2.0.1",
"href": "https://clawhub.ai/johnsmithfan/ai-company-ciso-2-0-0",
"sourceUrl": "https://clawhub.ai/johnsmithfan/ai-company-ciso-2-0-0",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-04-19T10:57:14.500Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-johnsmithfan-ai-company-ciso-2-0-0/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-johnsmithfan-ai-company-ciso-2-0-0/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 2.0.1",
"description": "**ai-company-ciso-2-0-1 Changelog** - Introduced detailed separation between AI Gateway (CISO scope) and Guardrail (CTO scope), clarifying access control vs. content security functions. - Established CISO as the sole authority for STRIDE threat modeling and approval, resolving potential overlaps with CTO activities. - Added CEO-EXEC crisis direct channel protocol with strict CISO approval, new operation restrictions, and enhanced audit measures. - Implemented CTO+CISO dual approval workflow for production/architecture changes, including clear parallel review logic and explicit override/timeout handling. - Updated documentation to reflect new modules, stricter stratification of responsibilities, and improved compliance and risk mitigation procedures. - Added references to signed STRIDE assessment documents and the dual-approval process workflow.",
"href": "https://clawhub.ai/johnsmithfan/ai-company-ciso-2-0-0",
"sourceUrl": "https://clawhub.ai/johnsmithfan/ai-company-ciso-2-0-0",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-04-19T10:57:14.500Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
