{"id":"338ebb7b-9866-4033-a7a7-7e8b3ba5db78","entityType":"agent","slug":"clawhub-gechengling-agent-governance-assistant","name":"Agent Governance Assistant","canonicalUrl":"https://www.xpersona.co/agent/clawhub-gechengling-agent-governance-assistant","canonicalPath":"/agent/clawhub-gechengling-agent-governance-assistant","generatedAt":"2026-10-11T07:41:16.331Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T05:29:10.913Z","emptyReason":null},"description":"UPDATED 2026: Covers China AI Agent governance regulations (generative AI regulations), MCP protocol governance implications, and enterprise AI audit frameworks. AI-powered enterprise AI agent governance framework — audit agent behavior, enforce security policies, ensure CBIRC/CFCA compliance, detect shadow AI, and generate governance reports. Built for IT risk managers, compliance officers, and enterprise AI leaders in financial institutions. Keywords: AI agent governance, enterprise AI, agent compliance, AI security policy, CBIRC, CFCA, shadow AI detection, agent audit, Microsoft Agent 365, Copilot Studio, China AI regulation, Agent治理, 企业AI, AI合规, 影子AI检测, AI审计, NFRA AI合规, AI治理.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s17ewqc4f2s6gpcbm88hy7fgvn85kg1g:agent-governance-assistant","sourceUrl":"https://clawhub.ai/gechengling/agent-governance-assistant","homepage":"https://clawhub.ai/gechengling/skills/agent-governance-assistant","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/gechengling/agent-governance-assistant","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/gechengling/skills/agent-governance-assistant","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":61,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Agent Governance Assistant technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T05:29:10.913Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T05:29:10.913Z","emptyReason":null},"stars":null,"forks":null,"downloads":1146,"packageName":null,"latestVersion":"5.0.1","tractionLabel":"1.1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T05:29:10.843Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T05:29:10.913Z","lastCrawledAt":"2026-10-11T05:29:10.843Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T05:29:10.843Z","lastVerifiedAt":null,"highlights":[{"version":"5.0.1","createdAt":"2026-09-18T05:23:02.275Z","changelog":"v5.0.1: 新增Phase1.5零信任Agent架构落地清单（六项控制点含验收证据）与Phase3.5治理成熟度L1-L5自评及定级举例；Agent台账表新增自主度/是否注册列，风险矩阵新增典型失控场景与必备控制列及分级判定举例；影子AI表新增检测来源/复检时限列及检测手段局限对照；审计报告新增成熟度章节与合规评分卡权重及算例；新增Example3影子AI专项排查与Example4高风险Agent上线前评审；最佳实践增至11条；动态更新至2026-09-18并新增G20监管路径分化","fileCount":3,"zipByteSize":12043},{"version":"5.0.0","createdAt":"2026-06-28T13:17:54.245Z","changelog":"Agent Governance Assistant 5.0.0 - Added June 2026 China and MCP AI governance policy updates, including new financial regulatory guidance and MCP protocol changes. - Updated “AI最新动态” and “企业AI治理最新趋势” sections with recent regulatory developments, protocol features (MCP 2.0, Secure MCP Tunnel, Google A2A interoperability), and key compliance focal points in financial services. - Improved coverage of high-risk AI scenarios per latest guidance: financial transactions, asset evaluation, credit approval, insurance claims, and risk management. - Refreshed regulatory references, dates, and workflow context throughout. - Removed outdated skill-card.md; all usage and feature information consolidated in SKILL.md.","fileCount":3,"zipByteSize":6969},{"version":"4.0.1","createdAt":"2026-05-25T03:34:12.502Z","changelog":"- Added a new \"AI技术最新动态\" (AI Technology Latest Updates) section summarizing key regulatory and industry governance trends as of 2026-05-25. - Highlighted MCP standard governance migration to the Linux Foundation and emphasized AAIF governance requirements. - Clarified the significance of explainability, fairness, and privacy in evolving enterprise AI governance. - No changes to workflows, policy templates, or audit/reporting instructions.","fileCount":3,"zipByteSize":6402},{"version":"4.0.0","createdAt":"2026-05-18T04:18:23.208Z","changelog":"Agent Governance Assistant 4.0.0 — Major Update for 2026 China AI Agent Regulation and Enterprise Audit Framework - Updated to include 2026 regulatory trends: China generative AI service management, MCP protocol governance, and requirements from CBIRC and CFCA. - Expanded workflows for comprehensive enterprise AI agent governance—inventory, risk classification, policy enforcement, and regulatory compliance. - Enhanced shadow AI detection, including new methods like UEBA-based behavior analysis. - Detailed templates and output examples for audit reporting, risk scoring, and compliance disclosure. - Improved focus on IT risk managers, compliance, and AI leaders within financial institutions. - Bilingual support for key triggers and workflows (English/Chinese).","fileCount":2,"zipByteSize":4976}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17ewqc4f2s6gpcbm88hy7fgvn85kg1g:agent-governance-assistant","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s17ewqc4f2s6gpcbm88hy7fgvn85kg1g:agent-governance-assistant` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/gechengling/agent-governance-assistant before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-gechengling-agent-governance-assistant/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-gechengling-agent-governance-assistant/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-gechengling-agent-governance-assistant/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-gechengling-agent-governance-assistant/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-gechengling-agent-governance-assistant/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-gechengling-agent-governance-assistant/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T07:41:16.330Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-gechengling-agent-governance-assistant/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-gechengling-agent-governance-assistant/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-gechengling-agent-governance-assistant/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-gechengling-agent-governance-assistant/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T05:29:10.913Z","emptyReason":null},"readme":"Skill: Agent Governance Assistant\n\nOwner: gechengling\n\nSummary: UPDATED 2026: Covers China AI Agent governance regulations (generative AI regulations), MCP protocol governance implications, and enterprise AI audit frameworks. AI-powered enterprise AI agent governance framework — audit agent behavior, enforce security policies, ensure CBIRC/CFCA compliance, detect shadow AI, and generate governance reports. Built for IT risk managers, compliance officers, and enterprise AI leaders in financial institutions. Keywords: AI agent governance, enterprise AI, agent compliance, AI security policy, CBIRC, CFCA, shadow AI detection, agent audit, Microsoft Agent 365, Copilot Studio, China AI regulation, Agent治理, 企业AI, AI合规, 影子AI检测, AI审计, NFRA AI合规, AI治理.\n\nTags: agent-governance-assistant:5.0.1, latest:5.0.1\n\nVersion history:\n\nv5.0.1 | 2026-09-18T05:23:02.275Z | user\n\nv5.0.1: 新增Phase1.5零信任Agent架构落地清单（六项控制点含验收证据）与Phase3.5治理成熟度L1-L5自评及定级举例；Agent台账表新增自主度/是否注册列，风险矩阵新增典型失控场景与必备控制列及分级判定举例；影子AI表新增检测来源/复检时限列及检测手段局限对照；审计报告新增成熟度章节与合规评分卡权重及算例；新增Example3影子AI专项排查与Example4高风险Agent上线前评审；最佳实践增至11条；动态更新至2026-09-18并新增G20监管路径分化\n\nv5.0.0 | 2026-06-28T13:17:54.245Z | auto\n\nAgent Governance Assistant 5.0.0\n\n- Added June 2026 China and MCP AI governance policy updates, including new financial regulatory guidance and MCP protocol changes.\n- Updated “AI最新动态” and “企业AI治理最新趋势” sections with recent regulatory developments, protocol features (MCP 2.0, Secure MCP Tunnel, Google A2A interoperability), and key compliance focal points in financial services.\n- Improved coverage of high-risk AI scenarios per latest guidance: financial transactions, asset evaluation, credit approval, insurance claims, and risk management.\n- Refreshed regulatory references, dates, and workflow context throughout.\n- Removed outdated skill-card.md; all usage and feature information consolidated in SKILL.md.\n\nv4.0.1 | 2026-05-25T03:34:12.502Z | auto\n\n- Added a new \"AI技术最新动态\" (AI Technology Latest Updates) section summarizing key regulatory and industry governance trends as of 2026-05-25.\n- Highlighted MCP standard governance migration to the Linux Foundation and emphasized AAIF governance requirements.\n- Clarified the significance of explainability, fairness, and privacy in evolving enterprise AI governance.\n- No changes to workflows, policy templates, or audit/reporting instructions.\n\nv4.0.0 | 2026-05-18T04:18:23.208Z | auto\n\nAgent Governance Assistant 4.0.0 — Major Update for 2026 China AI Agent Regulation and Enterprise Audit Framework\n\n- Updated to include 2026 regulatory trends: China generative AI service management, MCP protocol governance, and requirements from CBIRC and CFCA.\n- Expanded workflows for comprehensive enterprise AI agent governance—inventory, risk classification, policy enforcement, and regulatory compliance.\n- Enhanced shadow AI detection, including new methods like UEBA-based behavior analysis.\n- Detailed templates and output examples for audit reporting, risk scoring, and compliance disclosure.\n- Improved focus on IT risk managers, compliance, and AI leaders within financial institutions.\n- Bilingual support for key triggers and workflows (English/Chinese).\n\nArchive index:\n\nArchive v5.0.1: 3 files, 12043 bytes\n\nFiles: skill-card.md (2395b), SKILL.md (23146b), _meta.json (145b)\n\nFile v5.0.1:SKILL.md\n\n---\r\nname: \"Agent Governance Assistant\"\r\nslug: agent-gov\r\ndescription: \"UPDATED 2026: Covers China AI Agent governance regulations (generative AI regulations), MCP protocol governance implications, and enterprise AI audit frameworks. AI-powered enterprise AI agent governance framework — audit agent behavior, enforce security policies, ensure CBIRC/CFCA compliance, detect shadow AI, and generate governance reports. Built for IT risk managers, compliance officers, and enterprise AI leaders in financial institutions. Keywords: AI agent governance, enterprise AI, agent compliance, AI security policy, CBIRC, CFCA, shadow AI detection, agent audit, Microsoft Agent 365, Copilot Studio, China AI regulation, Agent治理, 企业AI, AI合规, 影子AI检测, AI审计, NFRA AI合规, AI治理.\"\r\nversion: \"5.0.1\"\r\n---\r\n\r\n# Agent Governance Assistant\r\n\r\n\r\n### AI Agent治理最新动态 [2026-09-18更新]\r\n\r\n| 动态类型 | 内容摘要 | 发布时间 | 影响范围 | 治理应对 |\r\n|---------|---------|---------|---------|---------|\r\n| 协议发布 | MCP 2.0正式发布：无状态协议革命，6个SEP驱动无状态化 | 2026-06 | Agent架构/部署模式重大变革 | 无状态化后更依赖外部审计日志，需补齐留痕 |\r\n| 协议发布 | MCP Apps：Server端渲染交互界面（SEP-1865），沙盒iframe安全运行 | 2026-06 | Agent UI/用户体验 | UI侧输出也需纳入内容合规审查 |\r\n| 协议发布 | Tasks扩展：长时运行任务支持，非阻塞式taskHandle | 2026-06 | Agent编排/工作流 | 长时任务的中间状态需可追溯、可中断 |\r\n| 安全更新 | OpenAI Secure MCP Tunnel：零入站端口企业级安全部署 | 2026-06 | 企业Agent安全 | 仍需配合出网管控与身份鉴别 |\r\n| 互操作 | Google A2A与MCP互操作性测试通过（6月12日联合宣布） | 2026-06 | 多Agent协作 | 跨Agent调用链的责任划分需事先约定 |\r\n| 安全更新 | MCP 2.0安全沙箱：权限声明/执行沙箱/审计日志/用户确认 | 2026-06 | Agent安全治理 | 对应零信任架构的四项控制点 |\r\n| **监管路径分化** | G20期间美方主张轻触式AI监管，与欧盟AI法案、中国分类分级治理形成三条不同路径（以官方最新发布为准） | 2026-09-02 | 跨境AI合规 | 跨国机构需按区域分别设定Agent上线门槛 |\r\n| **AI基建国家化** | AI基础设施被定位为国家级基础设施，主权算力与本土应用能力成为政策议题（以官方最新发布为准） | 2026-09-02 | 金融行业AI基建 | 金融机构的自建算力须同步满足数据不出境要求 |\r\n\r\n> **数据截止**: 2026-09-18 | 来源：MCP官方规范、Anthropic官方博客、OpenAI公告、G20公开报道\r\n> **声明**: 以上动态供参考，具体以官方最新发布为准\r\n\r\n## Overview\r\n\r\nA comprehensive AI-powered framework for governing enterprise AI agents — from audit trails and policy enforcement to regulatory compliance and risk reporting. As enterprise AI agents (Microsoft Agent 365, Copilot Studio, custom agents) proliferate, governance has become the #1 blocker to adoption. This skill bridges the gap between AI capability and enterprise control.\r\n\r\n## Title\r\n\r\n**Enterprise AI Agent Governance Framework** — Audit · Secure · Comply\r\n\r\n## Triggers\r\n\r\n- \"agent governance\" / \"AI agent管理\" / \"代理治理\"\r\n- \"enterprise AI compliance\" / \"企业AI合规\"\r\n- \"shadow AI detection\" / \"影子AI排查\"\r\n- \"AI policy enforcement\" / \"AI策略执行\"\r\n- \"agent audit trail\" / \"代理审计日志\"\r\n- \"Microsoft Agent 365 governance\" / \"Agent 365治理\"\r\n- \"AI risk report\" / \"AI风险报告\"\r\n- \"Copilot Studio compliance\" / \"Copilot合规\"\r\n- \"China AI regulation\" / \"中国AI监管\"\r\n- \"CBIRC AI guidance\" / \"银保监会AI指引\"\r\n\r\n---\r\n\r\n### 0. 2026 企业AI Agent治理最新趋势\r\n\r\n| 时间 | 动态 | 治理含义 | 落地动作 |\r\n|------|------|---------|---------|\r\n| **2025年7月** | 中国《生成式人工智能服务管理暂行办法》正式施行 | AI Agent服务纳入互联网信息服务管理，算法备案要求扩展至Agent | 建立Agent算法备案台账 |\r\n| **2025年11月** | MCP协议移交Linux Foundation | AI Agent工具集成标准化带来新的审计盲点，需纳入治理范围 | 把MCP工具调用纳入审计范围 |\r\n| **2026年1月** | NFRA召开2026年监管工作会议，AI治理列为重点 | 金融行业AI Agent应用监管框架加速制定 | 预留季度治理报告报送口径 |\r\n| **2026年** | Microsoft Agent 365/Copilot Studio企业大规模部署 | Agent行为审计、数据隔离、权限管控成为合规核心 | 按部门拆分权限矩阵 |\r\n| **2026年** | 影子AI检测升级：从API监控到行为分析 | 传统DLP监控不足，需引入UEBA（用户实体行为分析）技术 | 网络层API监控 + 行为基线双轨 |\r\n| **2026-09** | AI监管路径区域分化（美国轻触式 / 欧盟AI法案 / 中国分类分级） | 同一Agent在不同区域的可用性不同 | 按区域设定差异化上线门槛 |\r\n\r\n> **2026年核心治理挑战：** 企业AI Agent数量激增（从10个→100+），传统Agent Inventory已无法满足监管要求。建议采用\"零信任Agent架构\"——每个Agent独立身份认证、最小权限、数据隔离、完整审计日志。\r\n\r\n---\r\n\r\n\r\n### AI治理最新动态 [2026-09-18更新]\r\n\r\n| 动态类型 | 内容摘要 | 发布时间 | 影响范围 | 治理应对 |\r\n|---------|---------|---------|---------|---------|\r\n| 监管发布 | 金融监管总局《关于银行业保险业人工智能安全开发应用的指导意见》从七大方面提出32项意见，AI治理从指导意见走向刚性规章 | 2026-06-18 | 金融机构AI治理框架 | 对照32项意见逐条建立台账 |\r\n| 标准治理 | MCP 2026路线图将治理成熟度列为四大优先方向，Agent协议治理标准化加速 | 2026-06 | Agent治理与工具标准 | 采用L1–L5成熟度自评对齐 |\r\n| 合规重点 | 高风险AI应用场景明确：资金交易、资产评估、信贷审批、承保理赔、风险管理 | 2026-06-18 | AI应用合规审查 | 上述场景一律要求人工复核 |\r\n| **国际治理分化** | G20期间美方主张轻触式监管以保持创新速度，与欧盟AI法案、中国分类分级治理形成三条路径（以官方最新发布为准） | 2026-09-02 | 跨境合规与集团统一策略 | 跨国机构按区域设差异化门槛，底线取最严 |\r\n| **基础设施属性** | AI基础设施被作为国家级基础设施讨论，主权算力与本土应用能力成为政策议题（以官方最新发布为准） | 2026-09-02 | 金融机构AI基建 | 自建算力需同步满足数据不出境与安全要求 |\r\n\r\n> **数据截止**: 2026-09-18 | 来源：国家金融监督管理总局、G20公开报道、行业公开信息\r\n> **声明**: 以上动态供参考，具体以官方最新发布为准；\r\n> 涉及具体合规判定时，请以监管机构最新正式文件与机构法务意见为准。\r\n\r\n## Workflow\r\n\r\n### Phase 1 — Agent Inventory Discovery\r\n\r\n**Step 1.1: Scan for Active AI Agents**\r\n\r\nGenerate a structured inventory of all AI agents in the enterprise environment.\r\n\r\n**Input required:**\r\n- List of known AI platforms in use (e.g., Microsoft 365 Copilot, Salesforce Einstein, custom LangChain agents, RPA bots)\r\n- Department ownership mapping\r\n- API endpoints or integration points\r\n\r\n**Output: Agent Inventory Table**\r\n\r\n| Agent ID | Platform | Owner | Department | Capabilities | Data Access Level | Autonomy | Registered | Last Active |\r\n|----------|----------|-------|------------|--------------|-------------------|----------|-----------|------------|\r\n| AG-001 | Microsoft Agent 365 | IT Admin | Finance | Email drafting, meeting prep | Full mailbox | Advisory | Yes | 2026-05-07 |\r\n| AG-002 | Custom LangChain | Claims Lead | Claims | Document review, fraud flag | Claims data | Semi-auto | No | 2026-09-02 |\r\n| AG-003 | Copilot Studio | Sales Ops | Sales | Lead scoring | CRM data | Advisory | Yes | 2026-09-10 |\r\n\r\n> **Autonomy 取值建议**：Advisory（仅建议，人执行）/ Semi-auto（自动执行但可回退）/ Full-auto（自动执行且不可逆）。\r\n> **Registered 为 No 的 Agent 应优先处置**——未注册却在生产运行，是本阶段最常见的高风险项。\r\n> 上表 AG-002 即属于此类：未注册、半自动、且接触理赔数据，应列为 Critical 候选。\r\n\r\n**Step 1.2: Classify Agent Risk Level**\r\n\r\nAssign risk tier (Low / Medium / High / Critical) based on:\r\n- Data sensitivity (PII, financial, health, IP)\r\n- External interaction (internet, customers, third parties)\r\n- Autonomy level (advisory only → full automation)\r\n- Regulatory exposure (CBIRC, CFCA, personal information protection)\r\n\r\n**Risk Classification Matrix:**\r\n\r\n| Tier | Criteria | Example | Audit Frequency | 典型失控场景 | 必备控制 |\r\n|------|----------|---------|----------------|-------------|---------|\r\n| Critical | Customer-facing + financial data + high autonomy | AI underwriting agent | Weekly | 自动拒保且无人工复核入口 | 强制人工复核 + 全量留痕 + 可解释文档 |\r\n| High | Internal + sensitive data + medium autonomy | AI claims processor | Monthly | 理赔金额判定错误被直接执行 | 金额阈值触发人工复核 + 抽样质检 |\r\n| Medium | Internal + general data + advisory only | AI meeting summarizer | Quarterly | 会议纪要把敏感信息扩散给无关人员 | 输出范围限制 + 敏感词过滤 |\r\n| Low | Internal + no sensitive data | AI email categorizer | Bi-annual | 误分类导致重要邮件被漏看 | 定期准确率抽查 |\r\n\r\n**分级判定举例（本轮新增）**：\r\n\r\n| 场景 | 数据 | 面向 | 自主度 | 判定 | 理由 |\r\n|-----|-----|-----|-----|-----|-----|\r\n| 智能核保助手，自动给出核保结论 | 客户健康与财务数据 | 内部+间接面向客户 | Semi-auto | Critical | 涉及承保决策且含敏感个人信息 |\r\n| 理赔材料完整性预检 | 理赔影像件 | 内部 | Semi-auto | High | 敏感数据但可由人工回退 |\r\n| 会议纪要生成 | 内部会议内容 | 内部 | Advisory | Medium | 仅建议、无敏感数据外发 |\r\n| 邮件自动分类 | 邮件元数据 | 内部 | Full-auto | Low | 无敏感数据、后果可恢复 |\r\n\r\n---\r\n\r\n### Phase 1.5 — 零信任 Agent 架构落地清单（本轮新增）\r\n\r\n对应\"2026年核心治理挑战\"提出的零信任Agent架构，下表把四项原则拆成可验收的控制点。\r\n治理不能停在原则层，**每一项都要能拿出证据**。\r\n\r\n| 原则 | 控制点 | 具体措施 | 验收证据 |\r\n|-----|-----|-----|-----|\r\n| 独立身份认证 | Agent 有唯一身份 | 每个Agent分配独立服务主体，禁止共享账号 | Agent注册表 + 身份清单 |\r\n| 最小权限 | 按职能授予 | 数据范围、工具清单、操作类型分别授权 | 权限矩阵与审批记录 |\r\n| 数据隔离 | 跨部门不可见 | 按部门/业务域隔离数据访问，禁止越域读取 | 隔离策略配置截图 + 越权测试记录 |\r\n| 完整审计日志 | 全链路留痕 | 记录提示词、工具调用、输出与人工处置 | 日志样本 + 留存周期说明 |\r\n| 可中断（新增） | 长时任务可中止 | 长时运行任务支持随时中断与回滚 | 中断演练记录 |\r\n| 可解释（新增） | 决策可回溯 | 关键决策输出依据与模型版本 | 可解释性文档 |\r\n\r\n**Step 2.1: Define Governance Policies**\r\n\r\nGenerate tailored governance policies based on enterprise type and regulatory context.\r\n\r\n**For China Financial Institutions (CBIRC/CFCA):**\r\n```\r\nPOLICY: CFCA-AI-001 — Agent Data Minimization\r\nAll AI agents must process only minimum necessary personal data.\r\nAgents cannot retain PII beyond the transaction completion window.\r\nAnnual data audit required.\r\n\r\nPOLICY: CBIRC-AI-007 — Model Transparency\r\nAll AI-assisted decisions in underwriting/claims must provide\r\nhuman-override capability and explainability documentation.\r\n\r\nPOLICY: AI-ENTERPRISE-003 — Agent Registration\r\nAll production AI agents must be registered in the Enterprise\r\nAgent Registry with documented purpose, data scope, and owner.\r\nUnregistered agents are prohibited from accessing customer data.\r\n```\r\n\r\n**Step 2.2: Policy Compliance Checker**\r\n\r\nFor each registered agent, evaluate against all applicable policies.\r\n\r\n**Input:** Agent inventory + policy list\r\n**Output:** Compliance gap matrix with severity scores\r\n\r\n---\r\n\r\n### Phase 3 — Shadow AI Detection\r\n\r\n**Step 3.1: Identify Unauthorized Agent Usage**\r\n\r\nScan for signs of shadow AI — employees using personal AI tools on corporate data.\r\n\r\n**Detection indicators:**\r\n- Third-party AI API calls from corporate networks (non-approved domains)\r\n- AI tool usage logs in DLP (Data Loss Prevention) systems\r\n- Browser extensions accessing corporate APIs\r\n- Unsanctioned Zapier/Make/n8n workflows connecting to company data\r\n\r\n**Output:** Shadow AI Exposure Report\r\n\r\n| Finding | Risk Level | Data at Risk | Detection Source | Recommended Action | 复检时限 |\r\n|---------|-----------|-------------|-----------------|-------------------|---------|\r\n| Employee using free ChatGPT API for customer email drafting | CRITICAL | Customer PII + contract terms | 出网API监控（非白名单域名） | Immediate block + compliance training | 24小时内 |\r\n| Unsanctioned n8n workflow syncing CRM to personal AI tool | HIGH | Contact data + deal values | DLP + 集成平台审计 | Replace with approved integration | 7日内 |\r\n| 浏览器插件读取企业OA页面内容 | HIGH | 内部公文与审批信息 | 浏览器扩展清单核查 | 移除插件并加入禁用清单 | 7日内 |\r\n| 部门自建Agent未纳入注册表 | MEDIUM | 视其数据范围而定 | 定期资产盘点比对 | 补登记并补做风险评估 | 30日内 |\r\n\r\n**检测指标与对应手段（本轮新增维度）**：\r\n\r\n| 检测指标 | 适用手段 | 局限 |\r\n|---------|---------|-----|\r\n| 第三方AI API调用 | 出网流量监控 + 域名白名单 | 加密流量需配合证书策略 |\r\n| AI工具使用日志 | DLP系统 | 覆盖不到未安装客户端的设备 |\r\n| 浏览器扩展访问企业API | 终端管理 + 扩展清单核查 | 需终端管控能力 |\r\n| 未授权自动化工作流 | 集成平台审计日志 | 影子SaaS需单独发现 |\r\n| 行为异常（下载量突增等） | UEBA 行为基线 | 需历史数据积累，误报需调优 |\r\n\r\n---\r\n\r\n### Phase 3.5 — 治理成熟度自评（本轮新增）\r\n\r\n在出具审计报告前，先用五级模型给企业的Agent治理定级，避免\"报告很厚、水平很初\"的情况。\r\n\r\n| 级别 | 名称 | 特征 | 下一步 |\r\n|-----|-----|-----|-----|\r\n| L1 初始 | 无台账 | Agent数量不清、无人负责 | 立即做资产盘点 |\r\n| L2 可重复 | 有台账 | 已登记但无分级、无策略 | 建立风险分级与基础策略 |\r\n| L3 已定义 | 有策略 | 策略成文并覆盖主要Agent | 落地技术控制与审计日志 |\r\n| L4 已管理 | 可度量 | 有合规评分、定期复检 | 引入UEBA与自动化监控 |\r\n| L5 优化 | 持续改进 | 治理指标纳入考核、定期演练 | 红队演练与跨机构对标 |\r\n\r\n**举例（如何定级）**：某企业已完成12个Agent登记、有策略文档但无合规评分、无定期复检 → 判为 L3。\r\n其下一步应优先建设\"可度量\"能力（合规评分卡 + 季度复检），而不是直接上UEBA——\r\n**跳过L4直接上高级工具，往往因缺少基线数据而失效**。\r\n\r\n---\r\n\r\n### Phase 4 — Audit Trail & Reporting\r\n\r\n**Step 4.1: Generate Governance Audit Report**\r\n\r\nProduce a structured audit report for internal risk committees and external regulators.\r\n\r\n**Report Sections:**\r\n1. Executive Summary (1 page)\r\n2. Agent Inventory & Risk Classification\r\n3. Governance Maturity Level (L1–L5) — 本版新增\r\n4. Policy Compliance Scorecard\r\n5. Shadow AI Findings\r\n6. Open Risks & Remediation Roadmap\r\n7. Appendix: Agent Decision Logs (sample)\r\n\r\n**合规评分卡建议权重（本轮新增维度）**：\r\n\r\n| 评分项 | 权重 | 评分依据 |\r\n|-----|-----|-----|\r\n| Agent 注册覆盖率 | 20% | 已注册数 / 生产运行总数 |\r\n| 数据最小化落实 | 20% | 抽查Agent实际读取字段是否必要 |\r\n| 人工复核覆盖率 | 20% | 高风险决策中具备人工复核的比例 |\r\n| 审计日志完整性 | 15% | 提示词/工具调用/输出三类留痕是否齐全 |\r\n| 影子AI处置率 | 15% | 已处置发现项 / 总发现项 |\r\n| 复检及时性 | 10% | 按期完成复检的比例 |\r\n\r\n**举例**：某企业12个Agent中8个已注册（20分得13.3）、数据最小化抽查达标（20）、\r\n人工复核覆盖高风险决策的一半（20分得10）、日志仅记录输出（15分得5）、\r\n影子AI 3项中已处置1项（15分得5）、复检按期率约70%（10分得7），总分约 **60.3/100**，\r\n对应 L3 偏上、尚未达到 L4。\r\n\r\n**Step 4.2: Generate Regulatory Filing**\r\n\r\nFormat findings as a CBIRC/CFCA-compliant governance disclosure.\r\n\r\n---\r\n\r\n## Input / Output Examples\r\n\r\n### Example 1: Enterprise Agent Audit\r\n\r\n**Input:**\r\n```\r\nWe have 12 AI agents across Finance, Claims, and Sales departments.\r\nRecent CBIRC guidance requires quarterly AI governance reporting.\r\nWe discovered 3 employees using personal AI tools for work tasks.\r\n```\r\n\r\n**Output:**\r\n```\r\n## Phase 1: Agent Inventory\r\n[Structured table of 12 agents with risk tiers]\r\n\r\n## Phase 2: Policy Gap Analysis\r\n- 4 agents non-compliant with CFCA-AI-001 (data minimization)\r\n- 2 agents lack human-override capability (CBIRC-AI-007)\r\n- 6 agents unregistered (AI-ENTERPRISE-003 violation)\r\n\r\n## Phase 3: Shadow AI Findings\r\n[Shadow AI report with 3 findings]\r\n\r\n## Phase 4: Compliance Score — 58/100\r\nRecommended actions prioritized by risk.\r\n\r\n## Report ready for CBIRC Q2 submission.\r\n```\r\n\r\n### Example 2: Microsoft Agent 365 Governance Setup\r\n\r\n**Input:**\r\n```\r\nWe are deploying Microsoft Agent 365 across 200 users.\r\nIT needs to configure governance controls before go-live.\r\nFinance and Claims departments need different permission levels.\r\n```\r\n\r\n**Output:**\r\n```\r\n## Agent 365 Governance Configuration\r\n\r\n### Recommended Permission Matrix\r\n| Department | Agent Capabilities | Data Scope | Human-in-Loop | Audit Level |\r\n|------------|-------------------|------------|---------------|-------------|\r\n| Finance | Report generation, variance analysis | Financial data only | Required for >¥100K | Full |\r\n| Claims | Document review, fraud flag | Claims data | Required for >¥10K | Full |\r\n| Sales | Lead scoring, email drafting | CRM data | Advisory only | Standard |\r\n\r\n### Governance Policies to Enable\r\n1. Data Loss Prevention (DLP) rules for PII in agent prompts\r\n2. Agent activity logging to Sentinel/Log Analytics\r\n3. Approval workflows for high-stakes agent actions\r\n4. Monthly governance review dashboard\r\n\r\n### Shadow AI Pre-emption\r\nBlock list: [personal-ai-tool-1.com, ai-tool-free.xyz]\r\nAllow list: [Copilot, Agent 365, approved-vendor-ai.com]\r\n```\r\n\r\n### Example 3: 影子AI专项排查（本版新增）\r\n\r\n**Input:**\r\n```\r\n监管检查提出影子AI问题。我们只有网络层的出网日志，\r\n没有终端管控，也没有UEBA。怎么在两周内拿出一个可交付的排查结论？\r\n```\r\n\r\n**Output:**\r\n```\r\n## 排查策略（按可执行性排序）\r\n第1周：\r\n1. 出网日志按域名聚合，筛出已知AI服务域名与可疑新域名\r\n2. 拉取集成平台（Zapier/Make/n8n）审计日志，找连接企业数据的自动化流程\r\n3. 向各部门发放自查问卷 + 抽查20台终端的浏览器扩展清单\r\n\r\n第2周：\r\n4. 对发现项按\"数据敏感度 × 使用频率\"分级\r\n5. 出报告，明确每项的建议动作与复检时限\r\n6. 同时提出能力缺口：终端管控与UEBA建议列入下一年度预算\r\n\r\n## 交付物\r\n- 影子AI Exposure Report（含 Detection Source 与 复检时限 两列）\r\n- 能力缺口说明（说明本次排查的覆盖边界，避免过度承诺）\r\n```\r\n\r\n**要点**：只有网络层日志时，**必须显式说明覆盖边界**——未装终端管控的设备和\r\n加密流量中的调用可能未被发现。治理报告宁可写明局限，也不要给出\"已全面排查\"的结论。\r\n\r\n### Example 4: 高风险Agent上线前评审（本版新增）\r\n\r\n**Input:**\r\n```\r\n理赔部门要上线一个自动核赔Agent，金额在1万元以下可自动赔付。\r\n需要走什么治理流程？\r\n```\r\n\r\n**Output:**\r\n```\r\n## 风险定级：Critical\r\n理由：客户面向 + 理赔敏感数据 + 半自动执行\r\n\r\n## 上线前必过六关（对应零信任清单）\r\n1. 独立身份：分配独立服务主体，不与人工账号混用\r\n2. 最小权限：仅可读取理赔必要字段，禁止访问其他业务域\r\n3. 数据隔离：与其他部门数据域隔离\r\n4. 完整留痕：提示词、工具调用、判定依据、赔付结果全部记录\r\n5. 可中断：保留随时暂停自动赔付的开关\r\n6. 可解释：每笔自动赔付需输出判定依据与模型版本\r\n\r\n## 人工复核设计\r\n- 1万元以下自动赔付，但按不低于5%比例抽样人工复核\r\n- 出现同一被保险人短期内多次赔付等异常模式时，自动转为人工\r\n- 保留客户申诉与人工重开通道\r\n\r\n## 上线后\r\n- 前3个月按 Weekly 审计频率，稳定后可降为 Monthly\r\n```\r\n\r\n---\r\n\r\n## Notes & Best Practices\r\n\r\n1. **Start with inventory before policy.** You cannot govern what you cannot see.\r\n2. **China-specific:** For CBIRC/CFCA regulated entities, always include PIPL (个人信息保护法) compliance in the policy framework. Agents processing insurance claims data are subject to strict data minimization requirements.\r\n3. **Human-in-the-loop is non-negotiable** for any agent making or materially influencing financial decisions.\r\n4. **Shadow AI is the #1 undetected risk** — prioritize network-level API monitoring.\r\n5. **Update agent registry quarterly** — AI agent proliferation is fast; stale inventories create blind spots.\r\n6. **Leverage Microsoft Purview** for data classification feeding into agent governance policies.\r\n7. **Regulatory alignment:** Check current CBIRC AI guidance, CFCA fintech guidelines, and the generative AI regulation framework when generating policies.\r\n8. **先定级再选工具（本版新增）**：成熟度处于 L1–L2 的企业先做台账与分级，不要直接采购UEBA等高级工具；缺少基线数据会让高级工具失效。\r\n9. **写清覆盖边界（本版新增）**：任何排查与评估报告都要明确说明\"哪些没查到\"，治理报告的可信度来自坦诚的边界说明，而不是全覆盖的承诺。\r\n10. **人工复核要设计阈值而非口号（本版新增）**：把\"必须人工复核\"落成具体条件（金额、异常模式、客户申诉），否则执行时会被绕过。\r\n11. **长时任务必须可中断（本版新增）**：支持长时运行的Agent要保留随时暂停与回滚的开关，并定期做中断演练。\r\n\r\n---\r\n\r\n*Author: @gechengling | Skill: agent-governance-assistant | clawhub.ai/gechengling/agent-governance-assistant*\n\nFile v5.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn74e704j3ygjcygnpf02rdvd185js13\",\n  \"slug\": \"agent-governance-assistant\",\n  \"version\": \"5.0.1\",\n  \"publishedAt\": 1789708982275\n}\n\nFile v5.0.1:skill-card.md\n\n## Description:\n\nUPDATED 2026: Covers China AI Agent governance regulations, MCP protocol governance implications, and enterprise AI audit frameworks for auditing agent behavior, enforcing security policies, detecting shadow AI, and generating governance reports.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[gechengling](https://clawhub.ai/user/gechengling)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nIT risk managers, compliance officers, and enterprise AI leaders use this skill to inventory enterprise AI agents, classify risk, define governance controls, detect shadow AI, and draft audit or regulatory reporting materials.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Regulatory guidance may be outdated or incomplete for a specific jurisdiction or institution.\n\nMitigation: Verify current regulatory claims against official sources and internal legal or compliance review before relying on generated reports.\n\nRisk: Enterprise logs, DLP records, browser-extension inventories, or agent inventories may contain sensitive operational or personal data.\n\nMitigation: Only provide data that the user is authorized to review, and minimize or redact sensitive fields before using the skill.\n\nRisk: Governance outputs are templates and recommendations rather than proof that controls are operating effectively.\n\nMitigation: Require supporting evidence such as registry records, access matrices, audit log samples, approval records, and retest results before treating findings as closed.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/gechengling/skills/agent-governance-assistant)\n\n## Skill Output:\n\n**Output Type(s):** [guidance, markdown, configuration, text]\n\n**Output Format:** [Markdown with structured tables, checklists, policies, and report sections]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Produces governance templates and recommendations; regulatory claims should be verified against current official sources before use.]\n\n## Skill Version(s):\n\n5.0.1 (source: server release evidence and frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v5.0.0: 3 files, 6969 bytes\n\nFiles: skill-card.md (2043b), SKILL.md (12311b), _meta.json (145b)\n\nFile v5.0.0:SKILL.md\n\n---\r\r\nname: \"Agent Governance Assistant\"\r\r\nslug: agent-gov\r\r\ndescription: \"UPDATED 2026: Covers China AI Agent governance regulations (generative AI regulations), MCP protocol governance implications, and enterprise AI audit frameworks. AI-powered enterprise AI agent governance framework — audit agent behavior, enforce security policies, ensure CBIRC/CFCA compliance, detect shadow AI, and generate governance reports. Built for IT risk managers, compliance officers, and enterprise AI leaders in financial institutions. Keywords: AI agent governance, enterprise AI, agent compliance, AI security policy, CBIRC, CFCA, shadow AI detection, agent audit, Microsoft Agent 365, Copilot Studio, China AI regulation, Agent治理, 企业AI, AI合规, 影子AI检测, AI审计, NFRA AI合规, AI治理.\"\r\r\nversion: \"5.0.0\"\r\r\n---\r\r\n\r\r\n# Agent Governance Assistant\r\r\n\r\r\n\r\r\n### AI Agent治理最新动态 [2026-06-15更新]\r\r\n\r\r\n| 动态类型 | 内容摘要 | 发布时间 | 影响范围 |\r\r\n|---------|---------|---------|---------|\r\r\n| 协议发布 | MCP 2.0正式发布：无状态协议革命，6个SEP驱动无状态化 | 2026-06 | Agent架构/部署模式重大变革 |\r\r\n| 协议发布 | MCP Apps：Server端渲染交互界面（SEP-1865），沙盒iframe安全运行 | 2026-06 | Agent UI/用户体验 |\r\r\n| 协议发布 | Tasks扩展：长时运行任务支持，非阻塞式taskHandle | 2026-06 | Agent编排/工作流 |\r\r\n| 安全更新 | OpenAI Secure MCP Tunnel：零入站端口企业级安全部署 | 2026-06 | 企业Agent安全 |\r\r\n| 互操作 | Google A2A与MCP互操作性测试通过（6月12日联合宣布） | 2026-06 | 多Agent协作 |\r\r\n| 安全更新 | MCP 2.0安全沙箱：权限声明/执行沙箱/审计日志/用户确认 | 2026-06 | Agent安全治理 |\r\r\n\r\r\n> **数据截止**: 2026-06-15 | 来源：MCP官方规范、Anthropic官方博客、OpenAI公告\r\r\n> **声明**: 以上动态供参考，具体以官方最新发布为准\r\r\n\r\r\n## Overview\r\r\n\r\r\nA comprehensive AI-powered framework for governing enterprise AI agents — from audit trails and policy enforcement to regulatory compliance and risk reporting. As enterprise AI agents (Microsoft Agent 365, Copilot Studio, custom agents) proliferate, governance has become the #1 blocker to adoption. This skill bridges the gap between AI capability and enterprise control.\r\r\n\r\r\n## Title\r\r\n\r\r\n**Enterprise AI Agent Governance Framework** — Audit · Secure · Comply\r\r\n\r\r\n## Triggers\r\r\n\r\r\n- \"agent governance\" / \"AI agent管理\" / \"代理治理\"\r\r\n- \"enterprise AI compliance\" / \"企业AI合规\"\r\r\n- \"shadow AI detection\" / \"影子AI排查\"\r\r\n- \"AI policy enforcement\" / \"AI策略执行\"\r\r\n- \"agent audit trail\" / \"代理审计日志\"\r\r\n- \"Microsoft Agent 365 governance\" / \"Agent 365治理\"\r\r\n- \"AI risk report\" / \"AI风险报告\"\r\r\n- \"Copilot Studio compliance\" / \"Copilot合规\"\r\r\n- \"China AI regulation\" / \"中国AI监管\"\r\r\n- \"CBIRC AI guidance\" / \"银保监会AI指引\"\r\r\n\r\r\n---\r\r\n\r\r\n### 0. 2026 企业AI Agent治理最新趋势\r\r\n\r\r\n| 时间 | 动态 | 治理含义 |\r\r\n|------|------|---------|\r\r\n| **2025年7月** | 中国《生成式人工智能服务管理暂行办法》正式施行 | AI Agent服务纳入互联网信息服务管理，算法备案要求扩展至Agent |\r\r\n| **2025年11月** | MCP协议移交Linux Foundation | AI Agent工具集成标准化带来新的审计盲点，需纳入治理范围 |\r\r\n| **2026年1月** | NFRA召开2026年监管工作会议，AI治理列为重点 | 金融行业AI Agent应用监管框架加速制定 |\r\r\n| **2026年** | Microsoft Agent 365/Copilot Studio企业大规模部署 | Agent行为审计、数据隔离、权限管控成为合规核心 |\r\r\n| **2026年** | 影子AI检测升级：从API监控到行为分析 | 传统DLP监控不足，需引入UEBA（用户实体行为分析）技术 |\r\r\n\r\r\n> **2026年核心治理挑战：** 企业AI Agent数量激增（从10个→100+），传统Agent Inventory已无法满足监管要求。建议采用\"零信任Agent架构\"——每个Agent独立身份认证、最小权限、数据隔离、完整审计日志。\r\r\n\r\r\n---\r\r\n\r\r\n\r\n### AI治理最新动态 [2026-06-28更新]\r\n\r\n| 动态类型 | 内容摘要 | 发布时间 | 影响范围 |\r\n|---------|---------|---------|---------|\r\n| 监管发布 | 金融监管总局《关于银行业保险业人工智能安全开发应用的指导意见》从七大方面提出32项意见，AI治理从指导意见走向刚性规章 | 2026-06-18 | 金融机构AI治理框架 |\r\n| 标准治理 | MCP 2026路线图将'治理成熟度'列为四大优先方向，Agent协议治理标准化加速 | 2026-06 | Agent治理与工具标准 |\r\n| 合规重点 | 高风险AI应用场景明确：资金交易、资产评估、信贷审批、承保理赔、风险管理 | 2026-06-18 | AI应用合规审查 |\r\n\r\n> **数据截止**: 2026-06-28 | 来源：国家金融监督管理总局、行业公开信息\r\n> **声明**: 以上动态供参考，具体以官方最新发布为准\r\n\r\n## Workflow\r\r\n\r\r\n### Phase 1 — Agent Inventory Discovery\r\r\n\r\r\n**Step 1.1: Scan for Active AI Agents**\r\r\n\r\r\nGenerate a structured inventory of all AI agents in the enterprise environment.\r\r\n\r\r\n**Input required:**\r\r\n- List of known AI platforms in use (e.g., Microsoft 365 Copilot, Salesforce Einstein, custom LangChain agents, RPA bots)\r\r\n- Department ownership mapping\r\r\n- API endpoints or integration points\r\r\n\r\r\n**Output: Agent Inventory Table**\r\r\n\r\r\n| Agent ID | Platform | Owner | Department | Capabilities | Data Access Level | Last Active |\r\r\n|----------|----------|-------|------------|--------------|-------------------|------------|\r\r\n| AG-001 | Microsoft Agent 365 | IT Admin | Finance | Email drafting, meeting prep | Full mailbox | 2026-05-07 |\r\r\n\r\r\n**Step 1.2: Classify Agent Risk Level**\r\r\n\r\r\nAssign risk tier (Low / Medium / High / Critical) based on:\r\r\n- Data sensitivity (PII, financial, health, IP)\r\r\n- External interaction (internet, customers, third parties)\r\r\n- Autonomy level (advisory only → full automation)\r\r\n- Regulatory exposure (CBIRC, CFCA, personal information protection)\r\r\n\r\r\n**Risk Classification Matrix:**\r\r\n\r\r\n| Tier | Criteria | Example | Audit Frequency |\r\r\n|------|----------|---------|----------------|\r\r\n| Critical | Customer-facing + financial data + high autonomy | AI underwriting agent | Weekly |\r\r\n| High | Internal + sensitive data + medium autonomy | AI claims processor | Monthly |\r\r\n| Medium | Internal + general data + advisory only | AI meeting summarizer | Quarterly |\r\r\n| Low | Internal + no sensitive data | AI email categorizer | Bi-annual |\r\r\n\r\r\n---\r\r\n\r\r\n### Phase 2 — Policy Framework Design\r\r\n\r\r\n**Step 2.1: Define Governance Policies**\r\r\n\r\r\nGenerate tailored governance policies based on enterprise type and regulatory context.\r\r\n\r\r\n**For China Financial Institutions (CBIRC/CFCA):**\r\r\n```\r\r\nPOLICY: CFCA-AI-001 — Agent Data Minimization\r\r\nAll AI agents must process only minimum necessary personal data.\r\r\nAgents cannot retain PII beyond the transaction completion window.\r\r\nAnnual data audit required.\r\r\n\r\r\nPOLICY: CBIRC-AI-007 — Model Transparency\r\r\nAll AI-assisted decisions in underwriting/claims must provide\r\r\nhuman-override capability and explainability documentation.\r\r\n\r\r\nPOLICY: AI-ENTERPRISE-003 — Agent Registration\r\r\nAll production AI agents must be registered in the Enterprise\r\r\nAgent Registry with documented purpose, data scope, and owner.\r\r\nUnregistered agents are prohibited from accessing customer data.\r\r\n```\r\r\n\r\r\n**Step 2.2: Policy Compliance Checker**\r\r\n\r\r\nFor each registered agent, evaluate against all applicable policies.\r\r\n\r\r\n**Input:** Agent inventory + policy list\r\r\n**Output:** Compliance gap matrix with severity scores\r\r\n\r\r\n---\r\r\n\r\r\n### Phase 3 — Shadow AI Detection\r\r\n\r\r\n**Step 3.1: Identify Unauthorized Agent Usage**\r\r\n\r\r\nScan for signs of shadow AI — employees using personal AI tools on corporate data.\r\r\n\r\r\n**Detection indicators:**\r\r\n- Third-party AI API calls from corporate networks (non-approved domains)\r\r\n- AI tool usage logs in DLP (Data Loss Prevention) systems\r\r\n- Browser extensions accessing corporate APIs\r\r\n- Unsanctioned Zapier/Make/n8n workflows connecting to company data\r\r\n\r\r\n**Output:** Shadow AI Exposure Report\r\r\n\r\r\n| Finding | Risk Level | Data at Risk | Recommended Action |\r\r\n|---------|-----------|-------------|-------------------|\r\r\n| Employee using free ChatGPT API for customer email drafting | CRITICAL | Customer PII + contract terms | Immediate block + compliance training |\r\r\n| Unsanctioned n8n workflow syncing CRM to personal AI tool | HIGH | Contact data + deal values | Replace with approved integration |\r\r\n\r\r\n---\r\r\n\r\r\n### Phase 4 — Audit Trail & Reporting\r\r\n\r\r\n**Step 4.1: Generate Governance Audit Report**\r\r\n\r\r\nProduce a structured audit report for internal risk committees and external regulators.\r\r\n\r\r\n**Report Sections:**\r\r\n1. Executive Summary (1 page)\r\r\n2. Agent Inventory & Risk Classification\r\r\n3. Policy Compliance Scorecard\r\r\n4. Shadow AI Findings\r\r\n5. Open Risks & Remediation Roadmap\r\r\n6. Appendix: Agent Decision Logs (sample)\r\r\n\r\r\n**Step 4.2: Generate Regulatory Filing**\r\r\n\r\r\nFormat findings as a CBIRC/CFCA-compliant governance disclosure.\r\r\n\r\r\n---\r\r\n\r\r\n## Input / Output Examples\r\r\n\r\r\n### Example 1: Enterprise Agent Audit\r\r\n\r\r\n**Input:**\r\r\n```\r\r\nWe have 12 AI agents across Finance, Claims, and Sales departments.\r\r\nRecent CBIRC guidance requires quarterly AI governance reporting.\r\r\nWe discovered 3 employees using personal AI tools for work tasks.\r\r\n```\r\r\n\r\r\n**Output:**\r\r\n```\r\r\n## Phase 1: Agent Inventory\r\r\n[Structured table of 12 agents with risk tiers]\r\r\n\r\r\n## Phase 2: Policy Gap Analysis\r\r\n- 4 agents non-compliant with CFCA-AI-001 (data minimization)\r\r\n- 2 agents lack human-override capability (CBIRC-AI-007)\r\r\n- 6 agents unregistered (AI-ENTERPRISE-003 violation)\r\r\n\r\r\n## Phase 3: Shadow AI Findings\r\r\n[Shadow AI report with 3 findings]\r\r\n\r\r\n## Phase 4: Compliance Score — 58/100\r\r\nRecommended actions prioritized by risk.\r\r\n\r\r\n## Report ready for CBIRC Q2 submission.\r\r\n```\r\r\n\r\r\n### Example 2: Microsoft Agent 365 Governance Setup\r\r\n\r\r\n**Input:**\r\r\n```\r\r\nWe are deploying Microsoft Agent 365 across 200 users.\r\r\nIT needs to configure governance controls before go-live.\r\r\nFinance and Claims departments need different permission levels.\r\r\n```\r\r\n\r\r\n**Output:**\r\r\n```\r\r\n## Agent 365 Governance Configuration\r\r\n\r\r\n### Recommended Permission Matrix\r\r\n| Department | Agent Capabilities | Data Scope | Human-in-Loop | Audit Level |\r\r\n|------------|-------------------|------------|---------------|-------------|\r\r\n| Finance | Report generation, variance analysis | Financial data only | Required for >¥100K | Full |\r\r\n| Claims | Document review, fraud flag | Claims data | Required for >¥10K | Full |\r\r\n| Sales | Lead scoring, email drafting | CRM data | Advisory only | Standard |\r\r\n\r\r\n### Governance Policies to Enable\r\r\n1. Data Loss Prevention (DLP) rules for PII in agent prompts\r\r\n2. Agent activity logging to Sentinel/Log Analytics\r\r\n3. Approval workflows for high-stakes agent actions\r\r\n4. Monthly governance review dashboard\r\r\n\r\r\n### Shadow AI Pre-emption\r\r\nBlock list: [personal-ai-tool-1.com, ai-tool-free.xyz]\r\r\nAllow list: [Copilot, Agent 365, approved-vendor-ai.com]\r\r\n```\r\r\n\r\r\n---\r\r\n\r\r\n## Notes & Best Practices\r\r\n\r\r\n1. **Start with inventory before policy.** You cannot govern what you cannot see.\r\r\n2. **China-specific:** For CBIRC/CFCA regulated entities, always include PIPL (个人信息保护法) compliance in the policy framework. Agents processing insurance claims data are subject to strict data minimization requirements.\r\r\n3. **Human-in-the-loop is non-negotiable** for any agent making or materially influencing financial decisions.\r\r\n4. **Shadow AI is the #1 undetected risk** — prioritize network-level API monitoring.\r\r\n5. **Update agent registry quarterly** — AI agent proliferation is fast; stale inventories create blind spots.\r\r\n6. **Leverage Microsoft Purview** for data classification feeding into agent governance policies.\r\r\n7. **Regulatory alignment:** Check current CBIRC AI guidance, CFCA fintech guidelines, and the generative AI regulation framework when generating policies.\r\r\n\r\r\n---\r\r\n\r\r\n*Author: @gechengling | Skill: agent-governance-assistant | clawhub.ai/gechengling/agent-governance-assistant*\n\nFile v5.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn74e704j3ygjcygnpf02rdvd185js13\",\n  \"slug\": \"agent-governance-assistant\",\n  \"version\": \"5.0.0\",\n  \"publishedAt\": 1782652674245\n}\n\nFile v5.0.0:skill-card.md\n\n## Description:\n\nAgent Governance Assistant helps IT risk managers, compliance officers, and enterprise AI leaders audit AI agent behavior, design security and compliance policies, detect shadow AI, and prepare governance reports for enterprise and financial-sector use cases.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[gechengling](https://clawhub.ai/user/gechengling)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nIT risk managers, compliance officers, and enterprise AI leaders use this skill to inventory and classify AI agents, evaluate governance policy gaps, detect shadow AI exposure, and draft audit or compliance reporting for enterprise AI deployments.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Generated governance reports may contain stale or incorrect legal or regulatory claims.\n\nMitigation: Independently verify current laws, regulator guidance, and filing requirements before using outputs for compliance decisions.\n\nRisk: Prompts for enterprise AI audits may expose secrets, credentials, production API keys, or regulated personal data.\n\nMitigation: Provide only the minimum necessary information and remove raw secrets, credentials, production keys, and unnecessary regulated personal data before use.\n\n## Reference(s):\n\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, guidance, configuration]\n\n**Output Format:** [Markdown reports, tables, policy checklists, and governance recommendations]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include risk classifications, compliance gap matrices, shadow AI findings, audit report outlines, and regulatory filing drafts.]\n\n## Skill Version(s):\n\n5.0.0 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v4.0.1: 3 files, 6402 bytes\n\nFiles: skill-card.md (2224b), SKILL.md (10855b), _meta.json (145b)\n\nFile v4.0.1:SKILL.md\n\n---\r\nname: \"Agent Governance Assistant\"\r\nslug: agent-gov\r\ndescription: \"UPDATED 2026: Covers China AI Agent governance regulations (generative AI regulations), MCP protocol governance implications, and enterprise AI audit frameworks. AI-powered enterprise AI agent governance framework — audit agent behavior, enforce security policies, ensure CBIRC/CFCA compliance, detect shadow AI, and generate governance reports. Built for IT risk managers, compliance officers, and enterprise AI leaders in financial institutions. Keywords: AI agent governance, enterprise AI, agent compliance, AI security policy, CBIRC, CFCA, shadow AI detection, agent audit, Microsoft Agent 365, Copilot Studio, China AI regulation, Agent治理, 企业AI, AI合规, 影子AI检测, AI审计, NFRA AI合规, AI治理.\"\r\nversion: \"4.0.1\"\r\n---\r\n\r\n# Agent Governance Assistant\r\n\r\n\r\n### AI技术最新动态 [2026-05-25更新]\r\n\r\n| 动态类型 | 内容摘要 | 影响范围 |\r\n|---------|---------|---------|\r\n| AI技术 | 2026年MCP标准治理升级至Linux Foundation AAIF | Agent治理框架需纳入MCP标准化和AAIF治理要求 |\r\n| AI技术 | AI Agent治理框架持续演进，需关注权限控制和审计日志 | Agent治理框架需纳入MCP标准化和AAIF治理要求 |\r\n| AI技术 | 企业AI治理要求提升：可解释性、公平性、隐私保护合规 | Agent治理框架需纳入MCP标准化和AAIF治理要求 |\r\n\r\n> **数据截止**: 2026-05-25 | 来源：国家金融监督管理总局、安永Q1分析、行业公开信息\r\n> **声明**: 以上动态供参考，具体以官方最新发布为准\r\n\r\n## Overview\r\n\r\nA comprehensive AI-powered framework for governing enterprise AI agents — from audit trails and policy enforcement to regulatory compliance and risk reporting. As enterprise AI agents (Microsoft Agent 365, Copilot Studio, custom agents) proliferate, governance has become the #1 blocker to adoption. This skill bridges the gap between AI capability and enterprise control.\r\n\r\n## Title\r\n\r\n**Enterprise AI Agent Governance Framework** — Audit · Secure · Comply\r\n\r\n## Triggers\r\n\r\n- \"agent governance\" / \"AI agent管理\" / \"代理治理\"\r\n- \"enterprise AI compliance\" / \"企业AI合规\"\r\n- \"shadow AI detection\" / \"影子AI排查\"\r\n- \"AI policy enforcement\" / \"AI策略执行\"\r\n- \"agent audit trail\" / \"代理审计日志\"\r\n- \"Microsoft Agent 365 governance\" / \"Agent 365治理\"\r\n- \"AI risk report\" / \"AI风险报告\"\r\n- \"Copilot Studio compliance\" / \"Copilot合规\"\r\n- \"China AI regulation\" / \"中国AI监管\"\r\n- \"CBIRC AI guidance\" / \"银保监会AI指引\"\r\n\r\n---\r\n\r\n### 0. 2026 企业AI Agent治理最新趋势\r\n\r\n| 时间 | 动态 | 治理含义 |\r\n|------|------|---------|\r\n| **2025年7月** | 中国《生成式人工智能服务管理暂行办法》正式施行 | AI Agent服务纳入互联网信息服务管理，算法备案要求扩展至Agent |\r\n| **2025年11月** | MCP协议移交Linux Foundation | AI Agent工具集成标准化带来新的审计盲点，需纳入治理范围 |\r\n| **2026年1月** | NFRA召开2026年监管工作会议，AI治理列为重点 | 金融行业AI Agent应用监管框架加速制定 |\r\n| **2026年** | Microsoft Agent 365/Copilot Studio企业大规模部署 | Agent行为审计、数据隔离、权限管控成为合规核心 |\r\n| **2026年** | 影子AI检测升级：从API监控到行为分析 | 传统DLP监控不足，需引入UEBA（用户实体行为分析）技术 |\r\n\r\n> **2026年核心治理挑战：** 企业AI Agent数量激增（从10个→100+），传统Agent Inventory已无法满足监管要求。建议采用\"零信任Agent架构\"——每个Agent独立身份认证、最小权限、数据隔离、完整审计日志。\r\n\r\n---\r\n\r\n## Workflow\r\n\r\n### Phase 1 — Agent Inventory Discovery\r\n\r\n**Step 1.1: Scan for Active AI Agents**\r\n\r\nGenerate a structured inventory of all AI agents in the enterprise environment.\r\n\r\n**Input required:**\r\n- List of known AI platforms in use (e.g., Microsoft 365 Copilot, Salesforce Einstein, custom LangChain agents, RPA bots)\r\n- Department ownership mapping\r\n- API endpoints or integration points\r\n\r\n**Output: Agent Inventory Table**\r\n\r\n| Agent ID | Platform | Owner | Department | Capabilities | Data Access Level | Last Active |\r\n|----------|----------|-------|------------|--------------|-------------------|------------|\r\n| AG-001 | Microsoft Agent 365 | IT Admin | Finance | Email drafting, meeting prep | Full mailbox | 2026-05-07 |\r\n\r\n**Step 1.2: Classify Agent Risk Level**\r\n\r\nAssign risk tier (Low / Medium / High / Critical) based on:\r\n- Data sensitivity (PII, financial, health, IP)\r\n- External interaction (internet, customers, third parties)\r\n- Autonomy level (advisory only → full automation)\r\n- Regulatory exposure (CBIRC, CFCA, personal information protection)\r\n\r\n**Risk Classification Matrix:**\r\n\r\n| Tier | Criteria | Example | Audit Frequency |\r\n|------|----------|---------|----------------|\r\n| Critical | Customer-facing + financial data + high autonomy | AI underwriting agent | Weekly |\r\n| High | Internal + sensitive data + medium autonomy | AI claims processor | Monthly |\r\n| Medium | Internal + general data + advisory only | AI meeting summarizer | Quarterly |\r\n| Low | Internal + no sensitive data | AI email categorizer | Bi-annual |\r\n\r\n---\r\n\r\n### Phase 2 — Policy Framework Design\r\n\r\n**Step 2.1: Define Governance Policies**\r\n\r\nGenerate tailored governance policies based on enterprise type and regulatory context.\r\n\r\n**For China Financial Institutions (CBIRC/CFCA):**\r\n```\r\nPOLICY: CFCA-AI-001 — Agent Data Minimization\r\nAll AI agents must process only minimum necessary personal data.\r\nAgents cannot retain PII beyond the transaction completion window.\r\nAnnual data audit required.\r\n\r\nPOLICY: CBIRC-AI-007 — Model Transparency\r\nAll AI-assisted decisions in underwriting/claims must provide\r\nhuman-override capability and explainability documentation.\r\n\r\nPOLICY: AI-ENTERPRISE-003 — Agent Registration\r\nAll production AI agents must be registered in the Enterprise\r\nAgent Registry with documented purpose, data scope, and owner.\r\nUnregistered agents are prohibited from accessing customer data.\r\n```\r\n\r\n**Step 2.2: Policy Compliance Checker**\r\n\r\nFor each registered agent, evaluate against all applicable policies.\r\n\r\n**Input:** Agent inventory + policy list\r\n**Output:** Compliance gap matrix with severity scores\r\n\r\n---\r\n\r\n### Phase 3 — Shadow AI Detection\r\n\r\n**Step 3.1: Identify Unauthorized Agent Usage**\r\n\r\nScan for signs of shadow AI — employees using personal AI tools on corporate data.\r\n\r\n**Detection indicators:**\r\n- Third-party AI API calls from corporate networks (non-approved domains)\r\n- AI tool usage logs in DLP (Data Loss Prevention) systems\r\n- Browser extensions accessing corporate APIs\r\n- Unsanctioned Zapier/Make/n8n workflows connecting to company data\r\n\r\n**Output:** Shadow AI Exposure Report\r\n\r\n| Finding | Risk Level | Data at Risk | Recommended Action |\r\n|---------|-----------|-------------|-------------------|\r\n| Employee using free ChatGPT API for customer email drafting | CRITICAL | Customer PII + contract terms | Immediate block + compliance training |\r\n| Unsanctioned n8n workflow syncing CRM to personal AI tool | HIGH | Contact data + deal values | Replace with approved integration |\r\n\r\n---\r\n\r\n### Phase 4 — Audit Trail & Reporting\r\n\r\n**Step 4.1: Generate Governance Audit Report**\r\n\r\nProduce a structured audit report for internal risk committees and external regulators.\r\n\r\n**Report Sections:**\r\n1. Executive Summary (1 page)\r\n2. Agent Inventory & Risk Classification\r\n3. Policy Compliance Scorecard\r\n4. Shadow AI Findings\r\n5. Open Risks & Remediation Roadmap\r\n6. Appendix: Agent Decision Logs (sample)\r\n\r\n**Step 4.2: Generate Regulatory Filing**\r\n\r\nFormat findings as a CBIRC/CFCA-compliant governance disclosure.\r\n\r\n---\r\n\r\n## Input / Output Examples\r\n\r\n### Example 1: Enterprise Agent Audit\r\n\r\n**Input:**\r\n```\r\nWe have 12 AI agents across Finance, Claims, and Sales departments.\r\nRecent CBIRC guidance requires quarterly AI governance reporting.\r\nWe discovered 3 employees using personal AI tools for work tasks.\r\n```\r\n\r\n**Output:**\r\n```\r\n## Phase 1: Agent Inventory\r\n[Structured table of 12 agents with risk tiers]\r\n\r\n## Phase 2: Policy Gap Analysis\r\n- 4 agents non-compliant with CFCA-AI-001 (data minimization)\r\n- 2 agents lack human-override capability (CBIRC-AI-007)\r\n- 6 agents unregistered (AI-ENTERPRISE-003 violation)\r\n\r\n## Phase 3: Shadow AI Findings\r\n[Shadow AI report with 3 findings]\r\n\r\n## Phase 4: Compliance Score — 58/100\r\nRecommended actions prioritized by risk.\r\n\r\n## Report ready for CBIRC Q2 submission.\r\n```\r\n\r\n### Example 2: Microsoft Agent 365 Governance Setup\r\n\r\n**Input:**\r\n```\r\nWe are deploying Microsoft Agent 365 across 200 users.\r\nIT needs to configure governance controls before go-live.\r\nFinance and Claims departments need different permission levels.\r\n```\r\n\r\n**Output:**\r\n```\r\n## Agent 365 Governance Configuration\r\n\r\n### Recommended Permission Matrix\r\n| Department | Agent Capabilities | Data Scope | Human-in-Loop | Audit Level |\r\n|------------|-------------------|------------|---------------|-------------|\r\n| Finance | Report generation, variance analysis | Financial data only | Required for >¥100K | Full |\r\n| Claims | Document review, fraud flag | Claims data | Required for >¥10K | Full |\r\n| Sales | Lead scoring, email drafting | CRM data | Advisory only | Standard |\r\n\r\n### Governance Policies to Enable\r\n1. Data Loss Prevention (DLP) rules for PII in agent prompts\r\n2. Agent activity logging to Sentinel/Log Analytics\r\n3. Approval workflows for high-stakes agent actions\r\n4. Monthly governance review dashboard\r\n\r\n### Shadow AI Pre-emption\r\nBlock list: [personal-ai-tool-1.com, ai-tool-free.xyz]\r\nAllow list: [Copilot, Agent 365, approved-vendor-ai.com]\r\n```\r\n\r\n---\r\n\r\n## Notes & Best Practices\r\n\r\n1. **Start with inventory before policy.** You cannot govern what you cannot see.\r\n2. **China-specific:** For CBIRC/CFCA regulated entities, always include PIPL (个人信息保护法) compliance in the policy framework. Agents processing insurance claims data are subject to strict data minimization requirements.\r\n3. **Human-in-the-loop is non-negotiable** for any agent making or materially influencing financial decisions.\r\n4. **Shadow AI is the #1 undetected risk** — prioritize network-level API monitoring.\r\n5. **Update agent registry quarterly** — AI agent proliferation is fast; stale inventories create blind spots.\r\n6. **Leverage Microsoft Purview** for data classification feeding into agent governance policies.\r\n7. **Regulatory alignment:** Check current CBIRC AI guidance, CFCA fintech guidelines, and the generative AI regulation framework when generating policies.\r\n\r\n---\r\n\r\n*Author: @gechengling | Skill: agent-governance-assistant | clawhub.ai/gechengling/agent-governance-assistant*\n\nFile v4.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn74e704j3ygjcygnpf02rdvd185js13\",\n  \"slug\": \"agent-governance-assistant\",\n  \"version\": \"4.0.1\",\n  \"publishedAt\": 1779680052502\n}\n\nFile v4.0.1:skill-card.md\n\n## Description: <br>\nAgent Governance Assistant helps IT risk managers, compliance officers, and enterprise AI leaders inventory AI agents, classify risk, design governance policies, detect shadow AI, and prepare governance reports. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[gechengling](https://clawhub.ai/user/gechengling) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nIT risk managers, compliance officers, and enterprise AI leaders use this skill to structure AI agent inventories, compliance gap analysis, shadow AI findings, policy recommendations, and regulatory-style governance reports. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill may process sensitive enterprise compliance data such as inventories, logs, endpoint details, or findings. <br>\nMitigation: Only provide data the user is authorized to process, and avoid including unnecessary sensitive details in prompts or outputs. <br>\nRisk: Generated governance reports or regulatory-style filings may be incomplete or outdated for a specific jurisdiction or institution. <br>\nMitigation: Treat outputs as advisory drafts and verify current regulatory requirements with official sources or counsel before relying on them. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/gechengling/agent-governance-assistant) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Analysis, Markdown, Configuration, Guidance] <br>\n**Output Format:** [Markdown reports, tables, policy templates, and governance recommendations] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Advisory governance output; users should verify regulatory requirements with official sources or counsel before relying on reports or filings.] <br>\n\n## Skill Version(s): <br>\n4.0.1 (source: server release evidence and SKILL.md frontmatter) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v4.0.0: 2 files, 4976 bytes\n\nFiles: SKILL.md (10108b), _meta.json (145b)\n\nFile v4.0.0:SKILL.md\n\n---\r\nname: \"Agent Governance Assistant\"\r\nslug: agent-gov\r\ndescription: \"UPDATED 2026: Covers China AI Agent governance regulations (generative AI regulations), MCP protocol governance implications, and enterprise AI audit frameworks. AI-powered enterprise AI agent governance framework — audit agent behavior, enforce security policies, ensure CBIRC/CFCA compliance, detect shadow AI, and generate governance reports. Built for IT risk managers, compliance officers, and enterprise AI leaders in financial institutions. Keywords: AI agent governance, enterprise AI, agent compliance, AI security policy, CBIRC, CFCA, shadow AI detection, agent audit, Microsoft Agent 365, Copilot Studio, China AI regulation, Agent治理, 企业AI, AI合规, 影子AI检测, AI审计, NFRA AI合规, AI治理.\"\r\nversion: \"4.0.0\"\r\n---\r\n\r\n# Agent Governance Assistant\r\n\r\n## Overview\r\n\r\nA comprehensive AI-powered framework for governing enterprise AI agents — from audit trails and policy enforcement to regulatory compliance and risk reporting. As enterprise AI agents (Microsoft Agent 365, Copilot Studio, custom agents) proliferate, governance has become the #1 blocker to adoption. This skill bridges the gap between AI capability and enterprise control.\r\n\r\n## Title\r\n\r\n**Enterprise AI Agent Governance Framework** — Audit · Secure · Comply\r\n\r\n## Triggers\r\n\r\n- \"agent governance\" / \"AI agent管理\" / \"代理治理\"\r\n- \"enterprise AI compliance\" / \"企业AI合规\"\r\n- \"shadow AI detection\" / \"影子AI排查\"\r\n- \"AI policy enforcement\" / \"AI策略执行\"\r\n- \"agent audit trail\" / \"代理审计日志\"\r\n- \"Microsoft Agent 365 governance\" / \"Agent 365治理\"\r\n- \"AI risk report\" / \"AI风险报告\"\r\n- \"Copilot Studio compliance\" / \"Copilot合规\"\r\n- \"China AI regulation\" / \"中国AI监管\"\r\n- \"CBIRC AI guidance\" / \"银保监会AI指引\"\r\n\r\n---\r\n\r\n### 0. 2026 企业AI Agent治理最新趋势\r\n\r\n| 时间 | 动态 | 治理含义 |\r\n|------|------|---------|\r\n| **2025年7月** | 中国《生成式人工智能服务管理暂行办法》正式施行 | AI Agent服务纳入互联网信息服务管理，算法备案要求扩展至Agent |\r\n| **2025年11月** | MCP协议移交Linux Foundation | AI Agent工具集成标准化带来新的审计盲点，需纳入治理范围 |\r\n| **2026年1月** | NFRA召开2026年监管工作会议，AI治理列为重点 | 金融行业AI Agent应用监管框架加速制定 |\r\n| **2026年** | Microsoft Agent 365/Copilot Studio企业大规模部署 | Agent行为审计、数据隔离、权限管控成为合规核心 |\r\n| **2026年** | 影子AI检测升级：从API监控到行为分析 | 传统DLP监控不足，需引入UEBA（用户实体行为分析）技术 |\r\n\r\n> **2026年核心治理挑战：** 企业AI Agent数量激增（从10个→100+），传统Agent Inventory已无法满足监管要求。建议采用\"零信任Agent架构\"——每个Agent独立身份认证、最小权限、数据隔离、完整审计日志。\r\n\r\n---\r\n\r\n## Workflow\r\n\r\n### Phase 1 — Agent Inventory Discovery\r\n\r\n**Step 1.1: Scan for Active AI Agents**\r\n\r\nGenerate a structured inventory of all AI agents in the enterprise environment.\r\n\r\n**Input required:**\r\n- List of known AI platforms in use (e.g., Microsoft 365 Copilot, Salesforce Einstein, custom LangChain agents, RPA bots)\r\n- Department ownership mapping\r\n- API endpoints or integration points\r\n\r\n**Output: Agent Inventory Table**\r\n\r\n| Agent ID | Platform | Owner | Department | Capabilities | Data Access Level | Last Active |\r\n|----------|----------|-------|------------|--------------|-------------------|------------|\r\n| AG-001 | Microsoft Agent 365 | IT Admin | Finance | Email drafting, meeting prep | Full mailbox | 2026-05-07 |\r\n\r\n**Step 1.2: Classify Agent Risk Level**\r\n\r\nAssign risk tier (Low / Medium / High / Critical) based on:\r\n- Data sensitivity (PII, financial, health, IP)\r\n- External interaction (internet, customers, third parties)\r\n- Autonomy level (advisory only → full automation)\r\n- Regulatory exposure (CBIRC, CFCA, personal information protection)\r\n\r\n**Risk Classification Matrix:**\r\n\r\n| Tier | Criteria | Example | Audit Frequency |\r\n|------|----------|---------|----------------|\r\n| Critical | Customer-facing + financial data + high autonomy | AI underwriting agent | Weekly |\r\n| High | Internal + sensitive data + medium autonomy | AI claims processor | Monthly |\r\n| Medium | Internal + general data + advisory only | AI meeting summarizer | Quarterly |\r\n| Low | Internal + no sensitive data | AI email categorizer | Bi-annual |\r\n\r\n---\r\n\r\n### Phase 2 — Policy Framework Design\r\n\r\n**Step 2.1: Define Governance Policies**\r\n\r\nGenerate tailored governance policies based on enterprise type and regulatory context.\r\n\r\n**For China Financial Institutions (CBIRC/CFCA):**\r\n```\r\nPOLICY: CFCA-AI-001 — Agent Data Minimization\r\nAll AI agents must process only minimum necessary personal data.\r\nAgents cannot retain PII beyond the transaction completion window.\r\nAnnual data audit required.\r\n\r\nPOLICY: CBIRC-AI-007 — Model Transparency\r\nAll AI-assisted decisions in underwriting/claims must provide\r\nhuman-override capability and explainability documentation.\r\n\r\nPOLICY: AI-ENTERPRISE-003 — Agent Registration\r\nAll production AI agents must be registered in the Enterprise\r\nAgent Registry with documented purpose, data scope, and owner.\r\nUnregistered agents are prohibited from accessing customer data.\r\n```\r\n\r\n**Step 2.2: Policy Compliance Checker**\r\n\r\nFor each registered agent, evaluate against all applicable policies.\r\n\r\n**Input:** Agent inventory + policy list\r\n**Output:** Compliance gap matrix with severity scores\r\n\r\n---\r\n\r\n### Phase 3 — Shadow AI Detection\r\n\r\n**Step 3.1: Identify Unauthorized Agent Usage**\r\n\r\nScan for signs of shadow AI — employees using personal AI tools on corporate data.\r\n\r\n**Detection indicators:**\r\n- Third-party AI API calls from corporate networks (non-approved domains)\r\n- AI tool usage logs in DLP (Data Loss Prevention) systems\r\n- Browser extensions accessing corporate APIs\r\n- Unsanctioned Zapier/Make/n8n workflows connecting to company data\r\n\r\n**Output:** Shadow AI Exposure Report\r\n\r\n| Finding | Risk Level | Data at Risk | Recommended Action |\r\n|---------|-----------|-------------|-------------------|\r\n| Employee using free ChatGPT API for customer email drafting | CRITICAL | Customer PII + contract terms | Immediate block + compliance training |\r\n| Unsanctioned n8n workflow syncing CRM to personal AI tool | HIGH | Contact data + deal values | Replace with approved integration |\r\n\r\n---\r\n\r\n### Phase 4 — Audit Trail & Reporting\r\n\r\n**Step 4.1: Generate Governance Audit Report**\r\n\r\nProduce a structured audit report for internal risk committees and external regulators.\r\n\r\n**Report Sections:**\r\n1. Executive Summary (1 page)\r\n2. Agent Inventory & Risk Classification\r\n3. Policy Compliance Scorecard\r\n4. Shadow AI Findings\r\n5. Open Risks & Remediation Roadmap\r\n6. Appendix: Agent Decision Logs (sample)\r\n\r\n**Step 4.2: Generate Regulatory Filing**\r\n\r\nFormat findings as a CBIRC/CFCA-compliant governance disclosure.\r\n\r\n---\r\n\r\n## Input / Output Examples\r\n\r\n### Example 1: Enterprise Agent Audit\r\n\r\n**Input:**\r\n```\r\nWe have 12 AI agents across Finance, Claims, and Sales departments.\r\nRecent CBIRC guidance requires quarterly AI governance reporting.\r\nWe discovered 3 employees using personal AI tools for work tasks.\r\n```\r\n\r\n**Output:**\r\n```\r\n## Phase 1: Agent Inventory\r\n[Structured table of 12 agents with risk tiers]\r\n\r\n## Phase 2: Policy Gap Analysis\r\n- 4 agents non-compliant with CFCA-AI-001 (data minimization)\r\n- 2 agents lack human-override capability (CBIRC-AI-007)\r\n- 6 agents unregistered (AI-ENTERPRISE-003 violation)\r\n\r\n## Phase 3: Shadow AI Findings\r\n[Shadow AI report with 3 findings]\r\n\r\n## Phase 4: Compliance Score — 58/100\r\nRecommended actions prioritized by risk.\r\n\r\n## Report ready for CBIRC Q2 submission.\r\n```\r\n\r\n### Example 2: Microsoft Agent 365 Governance Setup\r\n\r\n**Input:**\r\n```\r\nWe are deploying Microsoft Agent 365 across 200 users.\r\nIT needs to configure governance controls before go-live.\r\nFinance and Claims departments need different permission levels.\r\n```\r\n\r\n**Output:**\r\n```\r\n## Agent 365 Governance Configuration\r\n\r\n### Recommended Permission Matrix\r\n| Department | Agent Capabilities | Data Scope | Human-in-Loop | Audit Level |\r\n|------------|-------------------|------------|---------------|-------------|\r\n| Finance | Report generation, variance analysis | Financial data only | Required for >¥100K | Full |\r\n| Claims | Document review, fraud flag | Claims data | Required for >¥10K | Full |\r\n| Sales | Lead scoring, email drafting | CRM data | Advisory only | Standard |\r\n\r\n### Governance Policies to Enable\r\n1. Data Loss Prevention (DLP) rules for PII in agent prompts\r\n2. Agent activity logging to Sentinel/Log Analytics\r\n3. Approval workflows for high-stakes agent actions\r\n4. Monthly governance review dashboard\r\n\r\n### Shadow AI Pre-emption\r\nBlock list: [personal-ai-tool-1.com, ai-tool-free.xyz]\r\nAllow list: [Copilot, Agent 365, approved-vendor-ai.com]\r\n```\r\n\r\n---\r\n\r\n## Notes & Best Practices\r\n\r\n1. **Start with inventory before policy.** You cannot govern what you cannot see.\r\n2. **China-specific:** For CBIRC/CFCA regulated entities, always include PIPL (个人信息保护法) compliance in the policy framework. Agents processing insurance claims data are subject to strict data minimization requirements.\r\n3. **Human-in-the-loop is non-negotiable** for any agent making or materially influencing financial decisions.\r\n4. **Shadow AI is the #1 undetected risk** — prioritize network-level API monitoring.\r\n5. **Update agent registry quarterly** — AI agent proliferation is fast; stale inventories create blind spots.\r\n6. **Leverage Microsoft Purview** for data classification feeding into agent governance policies.\r\n7. **Regulatory alignment:** Check current CBIRC AI guidance, CFCA fintech guidelines, and the generative AI regulation framework when generating policies.\r\n\r\n---\r\n\r\n*Author: @gechengling | Skill: agent-governance-assistant | clawhub.ai/gechengling/agent-governance-assistant*\n\nFile v4.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn74e704j3ygjcygnpf02rdvd185js13\",\n  \"slug\": \"agent-governance-assistant\",\n  \"version\": \"4.0.0\",\n  \"publishedAt\": 1779077903208\n}","readmeExcerpt":"Skill: Agent Governance Assistant Owner: gechengling Summary: UPDATED 2026: Covers China AI Agent governance regulations (generative AI regulations), MCP protocol governance implications, and enterprise AI audit frameworks. AI-powered enterprise AI agent governance framework — audit agent behavior, enforce security policies, ensure CBIRC/CFCA compliance, detect shadow AI, and generate governance reports. Built for IT","codeSnippets":[],"executableExamples":[],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\r\nname: \"Agent Governance Assistant\"\r\nslug: agent-gov\r\ndescription: \"UPDATED 2026: Covers China AI Agent governance regulations (generative AI regulations), MCP protocol governance implications, and enterprise AI audit frameworks. AI-powered enterprise AI agent governance framework — audit agent behavior, enforce security policies, ensure CBIRC/CFCA compliance, detect shadow AI, and generate governance reports. Built for IT risk managers, compliance officers, and enterprise AI leaders in financial institutions. Keywords: AI agent governance, enterprise AI, agent compliance, AI security policy, CBIRC, CFCA, shadow AI detection, agent audit, Microsoft Agent 365, Copilot Studio, China AI regulation, Agent治理, 企业AI, AI合规, 影子AI检测, AI审计, NFRA AI合规, AI治理.\"\r\nversion: \"5.0.1\"\r\n---\r\n\r\n# Agent Governance Assistant\r\n\r\n\r\n### AI Agent治理最新动态 [2026-09-18更新]\r\n\r\n| 动态类型 | 内容摘要 | 发布时间 | 影响范围 | 治理应对 |\r\n|---------|---------|---------|---------|---------|\r\n| 协议发布 | MCP 2.0正式发布：无状态协议革命，6个SEP驱动无状态化 | 2026-06 | Agent架构/部署模式重大变革 | 无状态化后更依赖外部审计日志，需补齐留痕 |\r\n| 协议发布 | MCP Apps：Server端渲染交互界面（SEP-1865），沙盒iframe安全运行 | 2026-06 | Agent UI/用户体验 | UI侧输出也需纳入内容合规审查 |\r\n| 协议发布 | Tasks扩展：长时运行任务支持，非阻塞式taskHandle | 2026-06 | Agent编排/工作流 | 长时任务的中间状态需可追溯、可中断 |\r\n| 安全更新 | OpenAI Secure MCP Tunnel：零入站端口企业级安全部署 | 2026-06 | 企业Agent安全 | 仍需配合出网管控与身份鉴别 |\r\n| 互操作 | Google A2A与MCP互操作性测试通过（6月12日联合宣布） | 2026-06 | 多Agent协作 | 跨Agent调用链的责任划分需事先约定 |\r\n| 安全更新 | MCP 2.0安全沙箱：权限声明/执行沙箱/审计日志/用户确认 | 2026-06 | Agent安全治理 | 对应零信任架构的四项控制点 |\r\n| **监管路径分化** | G20期间美方主张轻触式AI监管，与欧盟AI法案、中国分类分级治理形成三条不同路径（以官方最新发布为准） | 2026-09-02 | 跨境AI合规 | 跨国机构需按区域分别设定Agent上线门槛 |\r\n| **AI基建国家化** | AI基础设施被定位为国家级基础设施，主权算力与本土应用能力成为政策议题（以官方最新发布为准） | 2026-09-02 | 金融行业AI基建 | 金融机构的自建算力须同步满足数据不出境要求 |\r\n\r\n> **数据截止**: 2026-09-18 | 来源：MCP官方规范、Anthropic官方博客、OpenAI公告、G20公开报道\r\n> **声明**: 以上动态供参考，具体以官方最新发布为准\r\n\r\n## Overview\r\n\r\nA comprehensive AI-powered framework for governing enterprise AI agents — from audit trails and policy enforcement to regulatory compliance and risk reporting. As enterprise AI agents (Microsoft Agent 365, Copilot Studio, custom agents) proliferate, governance has become the #1 blocker to adoption. This skill bridges the gap between AI capability and enterprise control.\r\n\r\n## Title\r\n\r\n**Enterprise AI Agent Governance Framework** — Audit · Secure · Comply\r\n\r\n## Triggers\r\n\r\n- \"agent governance\" / \"AI agent管理\" / \"代理治理\"\r\n- \"enterprise AI compliance\" / \"企业AI合规\"\r\n- \"shadow AI detection\" / \"影子AI排查\"\r\n- \"AI policy enforcement\" / \"AI策略执行\"\r\n- \"agent audit trail\" / \"代理审计日志\"\r\n- \"Microsoft Agent 365 governance\" / \"Agent 365治理\"\r\n- \"AI risk report\" / \"AI风险报告\"\r\n- \"Copilot Studio compliance\" / \"Copilot合规\"\r\n- \"China AI regulation\" / \"中国AI监管\"\r\n- \"CBIRC AI guidance\" / \"银保监会AI指引\"\r\n\r\n---\r\n\r\n### 0. 2026 企业AI Agent治理最新趋势\r\n\r\n| 时间 | 动态 | 治理含义 | 落地动作 |\r\n|------|------|---------|---------|\r\n| **2025年7月** | 中国《生成式人工智能服务管理暂行办法》正式施行 | AI Agent服务纳入互联网信息服务管理，算法备案要求扩展至Agent | 建立Agent算法备案台账 |\r\n| **2025年11月** | MCP协议移交Linux Foundation | AI Agent工具集成标准化带来新的审计盲点，需纳入治理范围 | 把MCP工"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn74e704j3ygjcygnpf02rdvd185js13\",\n  \"slug\": \"agent-governance-assistant\",\n  \"version\": \"5.0.1\",\n  \"publishedAt\": 1789708982275\n}"},{"path":"skill-card.md","content":"## Description:\n\nUPDATED 2026: Covers China AI Agent governance regulations, MCP protocol governance implications, and enterprise AI audit frameworks for auditing agent behavior, enforcing security policies, detecting shadow AI, and generating governance reports.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[gechengling](https://clawhub.ai/user/gechengling)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nIT risk managers, compliance officers, and enterprise AI leaders use this skill to inventory enterprise AI agents, classify risk, define governance controls, detect shadow AI, and draft audit or regulatory reporting materials.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Regulatory guidance may be outdated or incomplete for a specific jurisdiction or institution.\n\nMitigation: Verify current regulatory claims against official sources and internal legal or compliance review before relying on generated reports.\n\nRisk: Enterprise logs, DLP records, browser-extension inventories, or agent inventories may contain sensitive operational or personal data.\n\nMitigation: Only provide data that the user is authorized to review, and minimize or redact sensitive fields before using the skill.\n\nRisk: Governance outputs are templates and recommendations rather than proof that controls are operating effectively.\n\nMitigation: Require supporting evidence such as registry records, access matrices, audit log samples, approval records, and retest results before treating findings as closed.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/gechengling/skills/agent-governance-assistant)\n\n## Skill Output:\n\n**Output Type(s):** [guidance, markdown, configuration, text]\n\n**Output Format:** [Markdown with structured tables, checklists, policies, and report sections]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Produces governance templates and recommendations; regulatory claims should be verified against current official sources before use.]\n\n## Skill Version(s):\n\n5.0.1 (source: server release evidence and frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1311,"uniquenessScore":44,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T05:29:10.913Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T05:29:10.913Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T07:41:16.331Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}