compliance-aiops
Use this skill whenever the user needs compliance evidence from the audit trails their governed AIops agents already write — mapping AI-agent infra-ops activity to HIPAA §164.312, PCI-DSS v4.0, SOC 2 TSC, or GDPR controls, producing a change-approval report, a gap analysis, an exceptions/anomaly report, or a hash-chain-sealed, tamper-evident evidence bundle. Always use this skill for "compliance evidence", "HIPAA / PCI-DSS / SOC 2 / GDPR evidence", "audit trail report", "coverage for control X", "which controls are we short on / gap analysis", "who approved this change / change-management evidence", "denied or errored ops / anomaly evidence", "seal / sign an evidence bundle", "prove this bundle wasn't altered", or "detect deleted audit rows". Do NOT use to scan or operate infrastructure and do NOT treat it as a GRC platform — it reads the local audit databases the OTHER AIops-tools write and converts them to evidence; for platform operations use those other AIops-tools. Evidence, not certification. Reads sibling audit trails read-only; no external API, no network, no platform credentials. Fully offline and deterministic.
Rank
62
Safety
84
Downloads
1.6k
Updated
Oct 10, 2026
Version
0.11.3
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.6K downloadsadoption · observed Oct 10, 2026
- Latest release
- 0.11.3release · observed Sep 15, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:compliance-aiops- Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:compliance-aiops` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/compliance-aiops before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-zw008-compliance-aiops/snapshot"
Documentation
CLAWHUB
149,415 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: compliance-aiops
slug: compliance-aiops
displayName: "Compliance AIops"
summary: "Compliance evidence from AIops audit trails: HIPAA/PCI/SOC2/GDPR, OSCAL export, 19 tools."
license: MIT
homepage: https://github.com/AIops-tools/Compliance-AIops
tags: [aiops, mcp, governance, compliance]
description: >
Use this skill whenever the user needs compliance evidence from the audit trails their governed AIops agents already write — mapping AI-agent infra-ops activity to HIPAA §164.312, PCI-DSS v4.0, SOC 2 TSC, or GDPR controls, producing a change-approval report, a gap analysis, an exceptions/anomaly report, or a hash-chain-sealed, tamper-evident evidence bundle.
Always use this skill for "compliance evidence", "HIPAA / PCI-DSS / SOC 2 / GDPR evidence", "audit trail report", "coverage for control X", "which controls are we short on / gap analysis", "who approved this change / change-management evidence", "denied or errored ops / anomaly evidence", "seal / sign an evidence bundle", "prove this bundle wasn't altered", or "detect deleted audit rows".
Do NOT use to scan or operate infrastructure and do NOT treat it as a GRC platform — it reads the local audit databases the OTHER AIops-tools write and converts them to evidence; for platform operations use those other AIops-tools.
Evidence, not certification. Reads sibling audit trails read-only; no external API, no network, no platform credentials. Fully offline and deterministic.
installer:
kind: uv
package: compliance-aiops
argument-hint: "[framework (hipaa|pci_dss|soc2|gdpr|iso27001|djcp_l3) or describe your evidence task]"
allowed-tools:
- Bash
metadata: {"openclaw":{"requires":{"anyBins":["compliance-aiops","uvx"]},"optional":{"env":["COMPLIANCE_AIOPS_CONFIG","COMPLIANCE_AIOPS_MASTER_PASSWORD"]},"homepage":"https://github.com/AIops-tools/Compliance-AIops","emoji":"📋","os":["macos","linux"]}}
compatibility: >
Standalone compliance-evidence tooling. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.
Data source: the LOCAL audit databases the other governed AIops tools already write, discovered by glob at ~/.*-aiops/audit.db (one shared audit_log schema). These are read READ-ONLY. There is NO external API, NO network, and NO platform credentials.
The only optional secret is a bundle-signing key, stored ENCRYPTED in ~/.compliance-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk, unlocked by a master password from COMPLIANCE_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). If you never sign bundles you need no secret at all.
Outputs: evidence bundles written to ~/.compliance-aiops/bundles/ (the only files written). All tool calls are themselves audited to a local SQLite DB under ~/.compliance-aiops/ (relocatable via COMPLIANCE_AIOPS_HOME). Write tools (generate_evidence_bundle, export_bundle: low risk; sign_bundle: _meta.json
{
"ownerId": "kn7b067awq2s97bn3d7p5qfhw5827pxc",
"slug": "compliance-aiops",
"version": "0.11.3",
"publishedAt": 1789451503021
}references/agent-guardrails.md
# Agent guardrails — running compliance-aiops with a smaller / local model compliance-aiops is a **meta-tool**: it reads the audit databases the other AIops tools write, and turns them into framework-mapped evidence. That makes the failure mode here different from an infrastructure tool. A wrong answer does not break a cluster — it produces a **confident, false compliance claim**, which is worse, because it looks like a finding. If you drive these tools with a local model (Llama, Qwen, Mistral … via Goose, Ollama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably better results with a short system prompt. This page gives you one, and — more importantly — tells you which guardrails you **no longer need to write**, because the tool now enforces them itself. ## Authorization is not this tool's job — decide it where it belongs Whether a bundle should be produced or signed is your decision, or the account's. The tool does not gate it — there is no read-only switch and no approval prompt to configure. The two right places to control it: - **The account it runs as.** The tool only ever writes under `~/.compliance-aiops/`, and opens every source `audit.db` strictly read-only — so ordinary filesystem permissions bound what it can do. A write then fails at the OS, which is the only place the permission actually lives. - **Your agent's system prompt.** If you want a query-only session, tell the model not to call the bundle-writing tools (they are clearly tagged `[WRITE]`). What the tool *does* guarantee is that you can always see what happened: ## What the tool enforces — do not waste prompt budget on these | You might be tempted to prompt | Why you don't need to | |---|---| | "Never modify the audit trail" | The tool has no capability to write to any source `audit.db` — it opens them read-only. Nothing in the tool surface can alter the evidence it reports on. | | "Don't get stuck retrying" | The runaway guard trips a circuit breaker if the same call is hammered in a tight loop — a stuck agent is stopped rather than left to burn calls and time. | | "Don't invent an approver or a reason" | A field the audit row did not record comes back as `null`, never as `""`. "No approver was recorded" and "the approver field was blank" stay distinguishable — which is exactly the distinction a change-approval finding turns on. | | "Tell me if you only saw part of the trail" | Every report carries `scanLimit` and `scanTruncated`, and every capped list carries `returned` / `limit` / `truncated`. Truncation is measured — one row past the cap is fetched — never inferred from a count landing on a round number. | | "Check the evidence hasn't been tampered with" | `verify_source_chain` hash-chains a source's current events and reports row-id gaps; `verify_bundle` re-derives a sealed bundle's chain and reports the first broken link plus signature validity. You do not need to ask the model to reason about integrity — ask it to run the check. | |
references/capabilities.md
# compliance-aiops capabilities > Evidence, not certification. 19 MCP tools (14 read, 3 write, 2 undo). Data > source: the local `audit_log` trails governed AIops tools write, discovered via > `~/.*-aiops/audit.db` and read **read-only**. No external API, no network, no > platform credentials. `since` / `until` accept ISO-8601 timestamps. ## Read / analysis tools (12) ### Audit reads | Tool | Inputs | Returns | |------|--------|---------| | `list_audit_sources` | — | discovered sources: `name`, `path`, `tool`, `readable`, `rowCount` | | `query_audit_events` | `source?`, `skill?`, `tool?`, `status?`, `risk_level?`, `approved?`, `selector?`, `since?`, `until?`, `limit=100` | matched events (cross-tool), normalised audit rows | | `activity_timeline` | `since?`, `until?`, `bucket="day"` (`hour`\|`day`) | event counts per time bucket | ### Framework mapping | Tool | Inputs | Returns | |------|--------|---------| | `list_frameworks` | — | frameworks + control counts (`hipaa`, `pci_dss`, `soc2`, `gdpr`, `iso27001`, `djcp_l3`) | | `coverage_summary` | `framework`, `since?`, `until?` | per-control `covered`/`weak`/`uncovered`, evidence counts, strength labels | | `control_evidence` | `framework`, `control_id`, `since?`, `until?`, `sample_size=20` | evidence rows + population size + the reproducible query for ONE control | | `gap_analysis` | `framework`, `since?`, `until?` | controls with no/weak evidence + honest `strong`/`partial` caveat + remediation hint | ### Assurance reports | Tool | Inputs | Returns | |------|--------|---------| | `approval_report` | `since?`, `until?`, `high_only=True` | high-risk write ops + who approved + rationale (CC8.1 / PCI 7-8 / HIPAA §312(a) artifact) | | `exceptions_report` | `since?`, `until?` | denied / error / budget_exceeded ops — enforcement + anomaly evidence | ### Integrity | Tool | Inputs | Returns | |------|--------|---------| | `verify_source_chain` | `source`, `since?`, `until?` | chain head + row-id gap detection (flags deletions) for one source | | `verify_bundle` | `bundle_path` | verifies chain + seal head + optional signature; `ok` + any mismatch detail | | `list_bundles` | — | bundles under `~/.compliance-aiops/bundles/` | | `oscal_assessment_results` | `bundle_path` | the bundle as a NIST **OSCAL 1.2.3** Assessment Results document, returned inline with a `summary` (satisfied / not-satisfied / **satisfiedOnPartialEvidence** / scanTruncated) and an explicit `limitations` list. Deterministic: v5 UUIDs derived from the chain head, so re-export is byte-identical | | `bundle_schedule_hint` | `framework`, `cron="0 2 * * 1"`, `period="7d"`, `sign=False` | ready-to-paste 5-field cron line + non-interactive command for periodic sealing; **writes nothing, no daemon** | ## Write / artifact tools (3 — no external mutation) | Tool | Risk | Inputs | Returns / effect | |------|:---:|--------|------------------| | `generate_evidence_bundle` | **medium** | `framework`, `period_start?`, `period_end?`, `out_pat
references/cli-reference.md
# compliance-aiops CLI reference
> Evidence, not certification. Reads the local audit trails governed
> AIops tools write (`~/.*-aiops/audit.db`) read-only. No external API, no
> network, no platform credentials. The CLI is a convenience subset; the full
> 19-tool surface is available over MCP.
## Setup & diagnostics
```bash
compliance-aiops init # discover sibling audit DBs, set org name, optional signing key
compliance-aiops doctor # which sibling audit DBs are present/readable
compliance-aiops overview # audit sources + per-framework covered/total counts
compliance-aiops mcp # start the MCP server (stdio transport)
```
## Reports (read-only)
```bash
compliance-aiops report sources # discovered audit sources + row counts
compliance-aiops report coverage <framework> # per-control coverage (hipaa|pci_dss|soc2|gdpr)
compliance-aiops report gaps <framework> # controls with no/weak evidence + honest caveat
compliance-aiops report approvals # high-risk write ops + approver + rationale
compliance-aiops report exceptions # denied / error / budget_exceeded ops
```
## Bundles (evidence artifacts)
```bash
compliance-aiops bundle generate <framework> [--since <iso>] [--until <iso>] [--period <7d|24h|2w|last-7-days>] [--sign]
# hash-chain-sealed bundle → ~/.compliance-aiops/bundles/
compliance-aiops bundle verify <path> # re-verify chain + seal head (+ signature)
compliance-aiops bundle list # list generated bundles
compliance-aiops bundle export <path> --format <markdown|csv|json>
compliance-aiops bundle schedule <framework> [--cron "0 2 * * 1"] [--period 7d] [--sign]
# print a ready-to-paste cron line; WRITES NOTHING, no daemon
```
## Secrets (optional bundle-signing key, encrypted ~/.compliance-aiops/secrets.enc)
Only needed if you sign bundles; there are no platform credentials.
```bash
compliance-aiops secret set <name> [--value <key>] # store signing key (hidden prompt if no --value)
compliance-aiops secret list # names only — values never shown
compliance-aiops secret rm <name>
compliance-aiops secret migrate # import a legacy plaintext key
compliance-aiops secret rotate-password # re-encrypt under a new master password
```
## Notes
- `<framework>` is one of `hipaa`, `pci_dss`, `soc2`, `gdpr`, `iso27001`, `djcp_l3`.
- `--since` / `--until` bound the evidence period (ISO-8601). The hash chain is
over evidence records only, so the same `(framework, period, sources)`
reproduces the same `chainHead`.
- `--period` is a convenience relative window (`7d` / `24h` / `2w` /
`last-7-days`) resolved to a since/until pair ending "now"; used only when
`--since` / `--until` are not given. `bundle schedulAionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/zw008/skills/compliance-aiops",
"sourceUrl": "https://clawhub.ai/zw008/skills/compliance-aiops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T05:36:48.313Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-compliance-aiops/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-compliance-aiops/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T05:36:48.313Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.6K downloads",
"href": "https://clawhub.ai/zw008/compliance-aiops",
"sourceUrl": "https://clawhub.ai/zw008/compliance-aiops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T05:36:48.313Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.11.3",
"href": "https://clawhub.ai/zw008/compliance-aiops",
"sourceUrl": "https://clawhub.ai/zw008/compliance-aiops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-15T05:51:43.021Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-compliance-aiops/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-compliance-aiops/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.11.3",
"description": "- Removed the documentation file skill-card.md from the project. - No changes to code or functionality; this update affects documentation only.",
"href": "https://clawhub.ai/zw008/compliance-aiops",
"sourceUrl": "https://clawhub.ai/zw008/compliance-aiops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-15T05:51:43.021Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
