{"id":"16653dcb-f994-422e-89c6-b930415177a9","entityType":"agent","slug":"clawhub-zw008-compliance-aiops","name":"compliance-aiops","canonicalUrl":"https://www.xpersona.co/agent/clawhub-zw008-compliance-aiops","canonicalPath":"/agent/clawhub-zw008-compliance-aiops","generatedAt":"2026-10-10T10:45:04.220Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T05:36:48.313Z","emptyReason":null},"description":"Use this skill whenever the user needs compliance evidence from the audit trails their governed AIops agents already write — mapping AI-agent infra-ops activity to HIPAA §164.312, PCI-DSS v4.0, SOC 2 TSC, or GDPR controls, producing a change-approval report, a gap analysis, an exceptions/anomaly report, or a hash-chain-sealed, tamper-evident evidence bundle. Always use this skill for \"compliance evidence\", \"HIPAA / PCI-DSS / SOC 2 / GDPR evidence\", \"audit trail report\", \"coverage for control X\", \"which controls are we short on / gap analysis\", \"who approved this change / change-management evidence\", \"denied or errored ops / anomaly evidence\", \"seal / sign an evidence bundle\", \"prove this bundle wasn't altered\", or \"detect deleted audit rows\". Do NOT use to scan or operate infrastructure and do NOT treat it as a GRC platform — it reads the local audit databases the OTHER AIops-tools write and converts them to evidence; for platform operations use those other AIops-tools. Evidence, not certification. Reads sibling audit trails read-only; no external API, no network, no platform credentials. Fully offline and deterministic.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:compliance-aiops","sourceUrl":"https://clawhub.ai/zw008/compliance-aiops","homepage":"https://clawhub.ai/zw008/skills/compliance-aiops","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/zw008/compliance-aiops","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/zw008/skills/compliance-aiops","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":64,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"compliance-aiops technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T05:36:48.313Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T05:36:48.313Z","emptyReason":null},"stars":null,"forks":null,"downloads":1649,"packageName":null,"latestVersion":"0.11.3","tractionLabel":"1.6K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T05:36:48.312Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T05:36:48.313Z","lastCrawledAt":"2026-10-10T05:36:48.312Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T05:36:48.312Z","lastVerifiedAt":null,"highlights":[{"version":"0.11.3","createdAt":"2026-09-15T05:51:43.021Z","changelog":"- Removed the documentation file skill-card.md from the project. - No changes to code or functionality; this update affects documentation only.","fileCount":7,"zipByteSize":17610},{"version":"0.11.2","createdAt":"2026-09-12T14:06:35.426Z","changelog":"## compliance-aiops v0.11.2 – Changelog - Updated OpenClaw plugin install instructions in documentation (SKILL.md). - Replaced plugin install reference from `clawhub:@aiops-tools/compliance-aiops` to `clawhub:@zw008/compliance-aiops`. - Removed the skill-card.md file. - No changes to core functionality; documentation and install process clarified.","fileCount":7,"zipByteSize":17493},{"version":"0.11.1","createdAt":"2026-09-12T09:59:10.143Z","changelog":"## compliance-aiops v0.11.1 changelog - SKILL.md updated with new OpenClaw plugin installation instructions and MCP server requirements. - Added usage notes for OpenClaw integration. - skill-card.md file removed.","fileCount":7,"zipByteSize":17609},{"version":"0.11.0","createdAt":"2026-09-12T00:47:51.821Z","changelog":"## compliance-aiops 0.11.0 - Updated metadata requirements: now uses `anyBins` for binaries and clarifies optional environment variables. - Removed the obsolete `skill-card.md` file. - Minor metadata field adjustments for clarity and compatibility. - No changes to functional documentation or core usage instructions.","fileCount":7,"zipByteSize":17400},{"version":"0.10.0","createdAt":"2026-08-13T00:28:08.006Z","changelog":"### v0.10.0 Summary: Adds OSCAL export and a new integrity tool. - Added OSCAL assessment results export tool (`oscal_assessment_results`), bringing total to 19 MCP tools. - Updated framework support and documentation to include OSCAL export capability. - Removed `skill-card.md` file. - Documentation and CLI references updated to reflect new tool and features.","fileCount":7,"zipByteSize":17430},{"version":"0.9.0","createdAt":"2026-08-10T06:50:07.485Z","changelog":"## compliance-aiops 0.9.0 – Changelog - Removed the skill-card.md file. - No changes to core functionality or usage. - Documentation and skill content remain unchanged.","fileCount":7,"zipByteSize":17299},{"version":"0.8.0","createdAt":"2026-08-03T05:52:04.025Z","changelog":"- Removed the skill-card.md file. - No code or functionality changes; documentation file only.","fileCount":7,"zipByteSize":17288},{"version":"0.7.0","createdAt":"2026-08-02T09:38:16.765Z","changelog":"## compliance-aiops v0.7.0 - Removed the file `skill-card.md` from the project. - No changes to functionality or supported features. - Documentation and core skill files remain unchanged.","fileCount":7,"zipByteSize":17194}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:compliance-aiops","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:compliance-aiops` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/compliance-aiops before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-compliance-aiops/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-compliance-aiops/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-compliance-aiops/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-zw008-compliance-aiops/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-zw008-compliance-aiops/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-zw008-compliance-aiops/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T10:45:04.216Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-compliance-aiops/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-compliance-aiops/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-compliance-aiops/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-compliance-aiops/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T05:36:48.313Z","emptyReason":null},"readme":"Skill: compliance-aiops\n\nOwner: zw008\n\nSummary: Use this skill whenever the user needs compliance evidence from the audit trails their governed AIops agents already write — mapping AI-agent infra-ops activity to HIPAA §164.312, PCI-DSS v4.0, SOC 2 TSC, or GDPR controls, producing a change-approval report, a gap analysis, an exceptions/anomaly report, or a hash-chain-sealed, tamper-evident evidence bundle. Always use this skill for \"compliance evidence\", \"HIPAA / PCI-DSS / SOC 2 / GDPR evidence\", \"audit trail report\", \"coverage for control X\", \"which controls are we short on / gap analysis\", \"who approved this change / change-management evidence\", \"denied or errored ops / anomaly evidence\", \"seal / sign an evidence bundle\", \"prove this bundle wasn't altered\", or \"detect deleted audit rows\". Do NOT use to scan or operate infrastructure and do NOT treat it as a GRC platform — it reads the local audit databases the OTHER AIops-tools write and converts them to evidence; for platform operations use those other AIops-tools. Evidence, not certification. Reads sibling audit trails read-only; no external API, no network, no platform credentials. Fully offline and deterministic.\n\nTags: agent-skills:0.1.0, ai-ops:0.1.0, audit:0.1.0, compliance:0.1.0, latest:0.11.3, mcp:0.1.0\n\nVersion history:\n\nv0.11.3 | 2026-09-15T05:51:43.021Z | auto\n\n- Removed the documentation file skill-card.md from the project.\n- No changes to code or functionality; this update affects documentation only.\n\nv0.11.2 | 2026-09-12T14:06:35.426Z | auto\n\n## compliance-aiops v0.11.2 – Changelog\n\n- Updated OpenClaw plugin install instructions in documentation (SKILL.md).\n- Replaced plugin install reference from `clawhub:@aiops-tools/compliance-aiops` to `clawhub:@zw008/compliance-aiops`.\n- Removed the skill-card.md file.\n- No changes to core functionality; documentation and install process clarified.\n\nv0.11.1 | 2026-09-12T09:59:10.143Z | auto\n\n## compliance-aiops v0.11.1 changelog\n\n- SKILL.md updated with new OpenClaw plugin installation instructions and MCP server requirements.\n- Added usage notes for OpenClaw integration.\n- skill-card.md file removed.\n\nv0.11.0 | 2026-09-12T00:47:51.821Z | auto\n\n## compliance-aiops 0.11.0\n\n- Updated metadata requirements: now uses `anyBins` for binaries and clarifies optional environment variables.\n- Removed the obsolete `skill-card.md` file.\n- Minor metadata field adjustments for clarity and compatibility.\n- No changes to functional documentation or core usage instructions.\n\nv0.10.0 | 2026-08-13T00:28:08.006Z | auto\n\n### v0.10.0 Summary: Adds OSCAL export and a new integrity tool.\n\n- Added OSCAL assessment results export tool (`oscal_assessment_results`), bringing total to 19 MCP tools.\n- Updated framework support and documentation to include OSCAL export capability.\n- Removed `skill-card.md` file.\n- Documentation and CLI references updated to reflect new tool and features.\n\nv0.9.0 | 2026-08-10T06:50:07.485Z | auto\n\n## compliance-aiops 0.9.0 – Changelog\n\n- Removed the skill-card.md file.\n- No changes to core functionality or usage.\n- Documentation and skill content remain unchanged.\n\nv0.8.0 | 2026-08-03T05:52:04.025Z | auto\n\n- Removed the skill-card.md file.\n- No code or functionality changes; documentation file only.\n\nv0.7.0 | 2026-08-02T09:38:16.765Z | auto\n\n## compliance-aiops v0.7.0\n\n- Removed the file `skill-card.md` from the project.\n- No changes to functionality or supported features.\n- Documentation and core skill files remain unchanged.\n\nv0.6.0 | 2026-07-21T09:40:23.074Z | auto\n\ncompliance-aiops 0.6.0\n\n- Updated documentation in SKILL.md and references/agent-guardrails.md.\n- Removed skill-card.md file.\n- No changes to the core functionality or interface; this release is a documentation and content update.\n\nv0.5.0 | 2026-07-20T11:14:30.599Z | auto\n\ncompliance-aiops v0.5.0\n\n- Removed the skill-card.md file.\n- No changes to core functionality or configuration.\n- No new features or fixes in this release.\n\nv0.4.0 | 2026-07-19T03:50:36.504Z | auto\n\n**compliance-aiops v0.4.0**\n\n- Added new agent guardrails documentation.\n- Introduced undo capabilities with `undo_list` and `undo_apply` tools (total tools increased to 18).\n- Expanded and clarified skill description, summary, and metadata.\n- Removed deprecated skill-card and updated all documentation references.\n- Strengthened offline integrity and determinism claims in compatibility and overview.\n\nv0.3.0 | 2026-07-17T05:55:57.071Z | auto\n\ncompliance-aiops 0.3.0\n\n- Added new frameworks support: ISO/IEC 27001:2022 (Annex A) and DJCP 等保2.0 (GB/T 22239-2019 三级).\n- Expanded argument hint to include iso27001 and djcp_l3.\n- Introduced the new bundle_schedule_hint tool for integrity/report generation.\n- Updated documentation for frameworks, controls, and supported tool list.\n- Removed obsolete skill-card.md file for better maintainability.\n\nv0.2.0 | 2026-07-13T13:08:59.600Z | auto\n\n- Removed redundant file skill-card.md for streamlined documentation and maintenance.\n- Clarified and updated main documentation in SKILL.md without functional changes.\n- No changes to features, APIs, or tool behavior.\n- Documentation now lives solely within SKILL.md.\n\nv0.1.0 | 2026-07-12T09:35:45.655Z | auto\n\nInitial release of compliance-aiops (preview) — standalone compliance evidence tooling for AIops audit trails.\n\n- Reads local AIops audit logs and maps agent ops to HIPAA, PCI-DSS v4.0, SOC 2 TSC, or GDPR controls.\n- Produces change approval, gap analysis, anomaly, and tamper-evident evidence bundle reports.\n- Fully offline: no external API, no network, no platform credentials; reads sibling audit databases only.\n- Evidence bundles are sealed with hash-chains and optionally signed with encrypted keys.\n- Not a GRC platform and does not scan or operate infrastructure.\n- 15 MCP tools included for audit reading, reporting, mapping controls, and bundle integrity verification.\n\nArchive index:\n\nArchive v0.11.3: 7 files, 17610 bytes\n\nFiles: references/agent-guardrails.md (7993b), references/capabilities.md (4440b), references/cli-reference.md (3342b), references/setup-guide.md (3370b), skill-card.md (2972b), SKILL.md (14887b), _meta.json (136b)\n\nFile v0.11.3:SKILL.md\n\n---\nname: compliance-aiops\nslug: compliance-aiops\ndisplayName: \"Compliance AIops\"\nsummary: \"Compliance evidence from AIops audit trails: HIPAA/PCI/SOC2/GDPR, OSCAL export, 19 tools.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/Compliance-AIops\ntags: [aiops, mcp, governance, compliance]\ndescription: >\n  Use this skill whenever the user needs compliance evidence from the audit trails their governed AIops agents already write — mapping AI-agent infra-ops activity to HIPAA §164.312, PCI-DSS v4.0, SOC 2 TSC, or GDPR controls, producing a change-approval report, a gap analysis, an exceptions/anomaly report, or a hash-chain-sealed, tamper-evident evidence bundle.\n  Always use this skill for \"compliance evidence\", \"HIPAA / PCI-DSS / SOC 2 / GDPR evidence\", \"audit trail report\", \"coverage for control X\", \"which controls are we short on / gap analysis\", \"who approved this change / change-management evidence\", \"denied or errored ops / anomaly evidence\", \"seal / sign an evidence bundle\", \"prove this bundle wasn't altered\", or \"detect deleted audit rows\".\n  Do NOT use to scan or operate infrastructure and do NOT treat it as a GRC platform — it reads the local audit databases the OTHER AIops-tools write and converts them to evidence; for platform operations use those other AIops-tools.\n  Evidence, not certification. Reads sibling audit trails read-only; no external API, no network, no platform credentials. Fully offline and deterministic.\ninstaller:\n  kind: uv\n  package: compliance-aiops\nargument-hint: \"[framework (hipaa|pci_dss|soc2|gdpr|iso27001|djcp_l3) or describe your evidence task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"compliance-aiops\",\"uvx\"]},\"optional\":{\"env\":[\"COMPLIANCE_AIOPS_CONFIG\",\"COMPLIANCE_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/Compliance-AIops\",\"emoji\":\"📋\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone compliance-evidence tooling. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.\n  Data source: the LOCAL audit databases the other governed AIops tools already write, discovered by glob at ~/.*-aiops/audit.db (one shared audit_log schema). These are read READ-ONLY. There is NO external API, NO network, and NO platform credentials.\n  The only optional secret is a bundle-signing key, stored ENCRYPTED in ~/.compliance-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk, unlocked by a master password from COMPLIANCE_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). If you never sign bundles you need no secret at all.\n  Outputs: evidence bundles written to ~/.compliance-aiops/bundles/ (the only files written). All tool calls are themselves audited to a local SQLite DB under ~/.compliance-aiops/ (relocatable via COMPLIANCE_AIOPS_HOME). Write tools (generate_evidence_bundle, export_bundle: low risk; sign_bundle: medium) pass through the @governed_tool decorator but perform NO external mutation.\n  Integrity: bundles are hash-chain-sealed (SHA-256 over ordered records; reproducible chainHead) with an optional HMAC signature. Tamper-EVIDENT, not tamper-PROOF — the source audit.db remains the system of record.\n  Webhooks: none — no outbound network calls at all.\n  Transitive dependencies: the MCP SDK and cryptography (Fernet). No post-install scripts or background services.\n  Evidence, not certification. Fully offline and deterministic; the integrity claims are covered by deterministic offline tests (see docs/VERIFICATION.md). OSCAL export is a v0.2 roadmap item (v0.1 emits JSON/Markdown/CSV).\n---\n\n# Compliance AIops\n\n> **Disclaimer**: Community-maintained open-source project, **not affiliated with, endorsed by, or sponsored by any framework body or GRC vendor.** HIPAA, PCI-DSS, SOC 2, GDPR and OSCAL are referenced descriptively; trademarks belong to their owners. Source at [github.com/AIops-tools/Compliance-AIops](https://github.com/AIops-tools/Compliance-AIops) under the MIT license.\n\nGoverned **compliance-evidence** tooling — **19 MCP tools**. It **reads the audit\ntrails your governed AIops agents already write** (`~/.<tool>-aiops/audit.db`, one\nshared `audit_log` schema, discovered via `~/.*-aiops/audit.db`) **read-only**,\nand turns that activity into **framework-mapped, hash-chain-sealed compliance\nevidence**. It does **not** scan infrastructure and does **not** replace a GRC\nplatform.\n\n> **Standalone**: the governance harness is bundled (`compliance_aiops.governance`).\n> **Not a platform wrapper** — no external API, no network, no platform\n> credentials. **Evidence, not certification**; fully offline and deterministic.\n\n## What This Skill Does\n\n| Group | Tools | Count | Read/Write |\n|-------|-------|:-----:|:----------:|\n| **Audit reads** | `list_audit_sources`, `query_audit_events`, `activity_timeline` | 3 | read |\n| **Framework mapping** | `list_frameworks`, `coverage_summary`, `control_evidence`, `gap_analysis` | 4 | read |\n| **Assurance reports** | `approval_report`, `exceptions_report` | 2 | read |\n| **Integrity** | `verify_source_chain`, `verify_bundle`, `list_bundles`, `bundle_schedule_hint`, `oscal_assessment_results` | 5 | read |\n| **Artifacts** | `generate_evidence_bundle` (low), `export_bundle` (low), `sign_bundle` (medium) | 3 | write (no external mutation) |\n| **Undo** | `undo_list`, `undo_apply` | 2 | undo |\n\n## Frameworks & sample controls\n\n| Framework | Sample controls (strength) |\n|-----------|----------------------------|\n| **HIPAA** §164.312 | 164.312(b) Audit controls (strong), 164.312(a)(1) Access control (strong), 164.312(c)(1) Integrity (strong) |\n| **PCI-DSS v4.0** | 10.2 Audit log content (strong), 10.3 Protect audit logs (strong), 7-8 Least privilege / authn (partial) |\n| **SOC 2 TSC** | CC6.1 Logical access (strong), CC7.2 Monitoring (strong), CC8.1 Change management (strong) |\n| **GDPR** | Art.30 Records of processing (partial), Art.32 Security of processing (strong) |\n| **ISO/IEC 27001:2022** (Annex A) | A.5.15 Access control (strong), A.5.16 Identity mgmt (strong), A.5.18 Access rights (partial), A.8.2 Privileged access (partial), A.8.15 Logging (strong), A.8.16 Monitoring (strong), A.8.32 Change management (strong) |\n| **等保2.0 (DJCP L3)** GB/T 22239-2019 三级 | 8.1.5.4 安全审计 (strong), 8.1.4.2 访问控制 (partial), 8.1.5 安全管理中心/集中审计 (strong) |\n\nAudit trails prove *operating effectiveness* strongly but *control design /\nconfiguration* only partially — each control is labelled `strong` or `partial`,\nand `gap_analysis` surfaces the caveat rather than overclaiming.\n\n## Quick Install\n\n```bash\nuv tool install compliance-aiops\ncompliance-aiops init       # discover sibling ~/.*-aiops/audit.db, set org name, optional signing key\ncompliance-aiops doctor     # which sibling audit DBs are present/readable\n```\n\nOr as an OpenClaw plugin, which installs this skill and its MCP server together:\n\n```bash\nopenclaw plugins install clawhub:@zw008/compliance-aiops\nopenclaw skills info compliance-aiops          # expect: Visible to model: yes\n```\n\nNeeds `uvx` on `PATH`: the MCP server is fetched with uv, pinned to this release.\n\n## When to Use This Skill\n\n- Map AI-agent infra-ops activity to a framework's controls (`coverage_summary`)\n- Pull the evidence rows + population for one control (`control_evidence`)\n- Find controls with no or weak evidence, with the honest caveat (`gap_analysis`)\n- Produce a change-approval artifact — who approved which high-risk write and why\n  (`approval_report`)\n- Produce enforcement / anomaly evidence — denied / errored / budget-tripped ops\n  (`exceptions_report`)\n- Seal a tamper-evident evidence bundle (`generate_evidence_bundle`,\n  `sign_bundle`) and later prove it wasn't altered (`verify_bundle`)\n- Detect deleted / missing audit rows in a source trail (`verify_source_chain`)\n\n**Do NOT use** to scan or operate infrastructure, or as a GRC platform. It reads\nthe audit DBs the *other* AIops-tools write; for platform operations use those\nother AIops-tools.\n\n## Related Skills — Skill Routing\n\n| If the user wants… | Use |\n|--------------------|-----|\n| Compliance evidence from existing AIops audit trails | **compliance-aiops** (this skill) |\n| To actually operate a platform (VMs, storage, clusters, network, …) | the relevant platform **AIops-tools** skill |\n| OT / industrial edge (Modbus, OPC-UA, PLC) | the **industrial-aiops** line |\n| A full GRC platform / policy management | out of scope — this is evidence, not GRC |\n\n## Common Workflows\n\n### 1. \"The SOC 2 auditor wants Q3 change-approval evidence by Friday\"\n\n1. `compliance-aiops doctor` → confirm the source audit trails are discoverable\n   and readable before you promise a delivery date\n2. `compliance-aiops report sources` (MCP: `list_audit_sources`) → which sibling\n   audit trails were found, and the event count and date range in each. If a\n   source you expected is missing, the bundle would be silently incomplete —\n   fix discovery first\n3. `compliance-aiops report coverage soc2` → confirm CC8.1 is actually covered by\n   the evidence you have, before generating anything\n4. `compliance-aiops report approvals` → the high-risk write operations with\n   their named approver and rationale — this is the population CC8.1 is asking\n   about\n5. `compliance-aiops bundle generate soc2 --since 2026-07-01 --until 2026-10-01 --sign`\n   → a hash-chain-sealed bundle under `~/.compliance-aiops/bundles/`\n6. `compliance-aiops bundle export <path> --format markdown` → the\n   auditor-facing report (also `json` / `csv`)\n7. **Failure branch**: if `report coverage` shows CC8.1 thin, **do not generate\n   anyway and hope** — run workflow 2 first and hand the auditor the honest gap\n   statement. A bundle asserts what the audit trail contains; it cannot\n   manufacture evidence that was never recorded.\n\n### 2. \"Which controls are we actually short on?\" (gap analysis)\n\n1. `compliance-aiops report sources` → establish the evidence base and its date\n   coverage; a gap caused by a *missing source* is a different problem from a\n   gap caused by *missing activity*\n2. `compliance-aiops report gaps hipaa` (also `pci_dss`, `soc2`, `gdpr`) →\n   controls with no or weak evidence, each with an honest caveat and a\n   remediation suggestion\n3. `compliance-aiops report exceptions` → the operations that ran **without** an\n   approver or rationale — usually the fastest-to-fix category of gap\n4. Drill into one control's population with `control_evidence` (MCP) to see the\n   **reproducible query** behind the coverage number, so the figure can be\n   defended rather than merely quoted\n5. `compliance-aiops report coverage <framework>` again after remediation to\n   confirm the gap actually closed\n6. **Failure branch**: if `list_frameworks` does not carry the framework or\n   control the auditor named, say so — this tool maps to HIPAA / PCI-DSS /\n   SOC 2 / GDPR and does not silently substitute a near-miss control.\n\n### 3. Prove a delivered bundle was not altered\n\n1. `compliance-aiops bundle list` → locate the bundle and its recorded\n   `chainHead`\n2. `compliance-aiops bundle verify <path>` → re-derives the hash chain, compares\n   it to the seal's `chainHead`, and checks the optional signature\n3. Because the chain is computed over evidence records only, the **same**\n   (framework, period, sources) reproduces the **same** `chainHead` — regenerate\n   and compare to prove reproducibility\n4. Record the `chainHead` **out-of-band** (ticket, email to the auditor, WORM\n   store) at delivery time; that out-of-band copy is what makes later\n   verification meaningful\n5. `verify_source_chain` (MCP) on each source → returns the source chain head and\n   flags **row-id gaps**, a sign that rows were deleted from that `audit.db`\n6. **Failure branch**: a `chainHead` mismatch or a row-id gap means the evidence\n   is **not** trustworthy — escalate, and treat the source `audit.db` as the\n   system of record. Do not re-seal a fresh bundle to make the mismatch go away;\n   the tool is **tamper-evident, not tamper-proof**, and its whole value is that\n   it reports this rather than papering over it.\n\n### 4. 定期封存 — schedule periodic sealed bundles (no daemon)\n\nThis tool ships **no scheduler**; it emits a cron line for you to install.\n\n1. `compliance-aiops report sources` → confirm the sources you want sealed are\n   discoverable from the account cron will run as (a common failure: cron sees a\n   different `$HOME`)\n2. `compliance-aiops bundle schedule soc2 --cron \"0 2 * * 1\" --period 7d --sign`\n   (MCP: `bundle_schedule_hint`) → returns a `cronLine` plus the exact\n   non-interactive command. **It writes nothing.**\n3. Paste the `cronLine` into `crontab -e`, e.g.\n   `0 2 * * 1 compliance-aiops bundle generate soc2 --period 7d --sign`\n4. Export `COMPLIANCE_AIOPS_MASTER_PASSWORD` in the cron environment so the\n   signing key unlocks non-interactively — never inline the real password in the\n   crontab\n5. After the first scheduled run, `compliance-aiops bundle list` and\n   `bundle verify` the newest bundle to confirm the unattended path really works\n6. **Failure branch**: if the cron run produces no bundle, the usual causes are\n   an unset master password (signing cannot unlock) or `COMPLIANCE_AIOPS_HOME`\n   not being set in cron's environment, so sources resolve elsewhere. Verify by\n   running the emitted command by hand with a clean environment before trusting\n   the schedule.\n\n## Governance & Safety\n\nThe skill reads audit trails and writes evidence bundles and records what it\ndoes; it does **not** decide whether producing or signing a bundle is permitted.\nThat is your agent's judgement, or the filesystem permissions of the account it\nruns as. There is no read-only switch, policy file, or approval gate.\n\n- **Audit is the guarantee, and it is not bypassable.** Every operation — MCP and CLI alike — is logged to `~/.compliance-aiops/audit.db` (relocatable via `COMPLIANCE_AIOPS_HOME`): params, result, status, duration, and the risk tier. The CLI writes the same row the MCP path does.\n- The source audit trails are opened **read-only**; the tool never mutates them. The only files written are bundles under `~/.compliance-aiops/bundles/`.\n- `COMPLIANCE_AUDIT_APPROVED_BY` / `COMPLIANCE_AUDIT_RATIONALE` are optional annotations recorded on the audit row (who/why); they are never required and never block.\n- **Tamper-EVIDENT, not tamper-PROOF** — the source `audit.db` remains the system\n  of record.\n\n## References\n\n- `references/capabilities.md` — full tool → inputs → returns reference\n- `references/cli-reference.md` — CLI command reference\n- `references/setup-guide.md` — source discovery, org name, optional signing key, integrity notes\n\nFile v0.11.3:_meta.json\n\n{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"compliance-aiops\",\n  \"version\": \"0.11.3\",\n  \"publishedAt\": 1789451503021\n}\n\nFile v0.11.3:references/agent-guardrails.md\n\n# Agent guardrails — running compliance-aiops with a smaller / local model\n\ncompliance-aiops is a **meta-tool**: it reads the audit databases the other\nAIops tools write, and turns them into framework-mapped evidence. That makes the\nfailure mode here different from an infrastructure tool. A wrong answer does not\nbreak a cluster — it produces a **confident, false compliance claim**, which is\nworse, because it looks like a finding.\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\n## Authorization is not this tool's job — decide it where it belongs\n\nWhether a bundle should be produced or signed is your decision, or the account's.\nThe tool does not gate it — there is no read-only switch and no approval prompt\nto configure. The two right places to control it:\n\n- **The account it runs as.** The tool only ever writes under\n  `~/.compliance-aiops/`, and opens every source `audit.db` strictly read-only —\n  so ordinary filesystem permissions bound what it can do. A write then fails at\n  the OS, which is the only place the permission actually lives.\n- **Your agent's system prompt.** If you want a query-only session, tell the\n  model not to call the bundle-writing tools (they are clearly tagged `[WRITE]`).\n\nWhat the tool *does* guarantee is that you can always see what happened:\n\n## What the tool enforces — do not waste prompt budget on these\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Never modify the audit trail\" | The tool has no capability to write to any source `audit.db` — it opens them read-only. Nothing in the tool surface can alter the evidence it reports on. |\n| \"Don't get stuck retrying\" | The runaway guard trips a circuit breaker if the same call is hammered in a tight loop — a stuck agent is stopped rather than left to burn calls and time. |\n| \"Don't invent an approver or a reason\" | A field the audit row did not record comes back as `null`, never as `\"\"`. \"No approver was recorded\" and \"the approver field was blank\" stay distinguishable — which is exactly the distinction a change-approval finding turns on. |\n| \"Tell me if you only saw part of the trail\" | Every report carries `scanLimit` and `scanTruncated`, and every capped list carries `returned` / `limit` / `truncated`. Truncation is measured — one row past the cap is fetched — never inferred from a count landing on a round number. |\n| \"Check the evidence hasn't been tampered with\" | `verify_source_chain` hash-chains a source's current events and reports row-id gaps; `verify_bundle` re-derives a sealed bundle's chain and reports the first broken link plus signature validity. You do not need to ask the model to reason about integrity — ask it to run the check. |\n| \"Be honest about what an audit log can prove\" | Every control carries a `strength` and a `caveat`, and gap findings carry the design-vs-operating note. Coverage is only claimed where the trail actually contains the evidence. |\n| \"Log everything you do, over both MCP and the CLI\" | Every call is audited to `~/.compliance-aiops/audit.db` regardless of what the model says it did — and the CLI writes the same row the MCP path does, so there is no unaudited entry point. |\n\n## What still needs a prompt\n\nThese are model-behaviour problems the harness cannot fix from the outside.\nCopy this into your agent's system prompt:\n\n```text\nYou operate compliance-aiops, which reads the audit trails other AIops tools\nproduce and maps them to framework controls (HIPAA, PCI-DSS, SOC2, GDPR).\n\nTOOL USE\n- Before answering any question about compliance posture, coverage, or a\n  specific control, you MUST call a tool. Never answer from memory, and never\n  from your training knowledge of what a framework requires.\n- Actually invoke the tool. Do not describe the call you would make, and do not\n  emit an example JSON response in place of calling it.\n- If a tool call fails, report the real error verbatim. An unreadable audit\n  source means unknown coverage, not zero findings and not full coverage.\n\nEVIDENCE INTEGRITY — the part that matters most here\n- NEVER state or imply that an organisation \"is compliant\", \"passes\", or \"is\n  certified\". This tool produces evidence about operations recorded in an audit\n  trail. Certification is a judgement made by a qualified assessor over a much\n  wider scope. Say what the evidence shows; never issue a verdict.\n- If a result has scanTruncated or truncated set to true, the population you saw\n  is a slice. Say so explicitly and do not compute or quote a coverage\n  percentage, a total, or a \"no violations found\" statement from it.\n- Quote counts and control ids exactly as returned. Never round, extrapolate,\n  or fill a gap in the trail with an assumption about what probably happened.\n- A null approver means no approver was recorded — report that as the finding\n  it is. Do not soften it, and do not guess who approved.\n- Report every control's caveat and strength alongside its coverage. A control\n  marked PARTIAL is not covered; it is partly evidenced by operational logs and\n  needs design/configuration evidence from a GRC system.\n- An absence of evidence for a control means the trail contains nothing matching\n  it. That is not proof the control failed, and not proof it passed. Say which\n  one the data supports: neither.\n\nSCOPE\n- Separate observation from interpretation. State what the tools returned, then\n  any interpretation, clearly marked as such.\n- A hash chain is tamper-EVIDENT, not tamper-PROOF. An \"intact\" verdict means\n  the records match a previously recorded head — it does not prove nothing was\n  ever deleted before that head was taken. Row-id gaps are the signal for that,\n  and they are reported separately.\n- Do not confuse the source tools' identifiers with each other: a `source` is an\n  AIops tool's audit database, a `skill` is the tool that logged the row, and a\n  `tool` is the individual operation. They are three different columns.\n```\n\n## Recommended setup for a local model\n\nKeep the agent query-only until you trust the setup — the tool already opens\nevery source trail read-only, and the only thing it can write is a bundle under\n`~/.compliance-aiops/`:\n\n```bash\ncompliance-aiops doctor\n```\n\nOptionally annotate the audit trail with who is operating and why — recorded on\nevery row, never required:\n\n```bash\nexport COMPLIANCE_AUDIT_APPROVED_BY=\"your.name@example.com\"\nexport COMPLIANCE_AUDIT_RATIONALE=\"Q3 SOC2 evidence collection\"\n```\n\n## If your model still struggles\n\nSome behaviours are model-capacity limits rather than prompt problems:\n\n- **The model editorialises into a verdict.** This is the characteristic failure\n  of smaller models on this tool. Ask for the numbers first (\"what does\n  coverage_summary return for soc2?\") and only then for a summary, rather than\n  asking \"are we SOC2 compliant?\" — the second phrasing invites a verdict the\n  data cannot support.\n- **Multi-tool workflows time out or drift.** Lead with `posture_overview` — it\n  folds source availability and per-framework coverage into one call.\n- **The model ignores later tool results in a long context.** Ask about one\n  control at a time with `control_evidence` rather than pulling a whole\n  framework's population.\n- **The model describes calls instead of making them.** This is usually a\n  runtime/tool-calling-format mismatch, not a prompt problem — check that your\n  client advertises the tools in the format your model was trained on.\n\nFeedback on running this with a specific local model is genuinely useful —\nopen an issue at\n[github.com/AIops-tools/Compliance-AIops](https://github.com/AIops-tools/Compliance-AIops/issues)\nwith the model, runtime, and what went wrong.\n\nFile v0.11.3:references/capabilities.md\n\n# compliance-aiops capabilities\n\n> Evidence, not certification. 19 MCP tools (14 read, 3 write, 2 undo). Data\n> source: the local `audit_log` trails governed AIops tools write, discovered via\n> `~/.*-aiops/audit.db` and read **read-only**. No external API, no network, no\n> platform credentials. `since` / `until` accept ISO-8601 timestamps.\n\n## Read / analysis tools (12)\n\n### Audit reads\n\n| Tool | Inputs | Returns |\n|------|--------|---------|\n| `list_audit_sources` | — | discovered sources: `name`, `path`, `tool`, `readable`, `rowCount` |\n| `query_audit_events` | `source?`, `skill?`, `tool?`, `status?`, `risk_level?`, `approved?`, `selector?`, `since?`, `until?`, `limit=100` | matched events (cross-tool), normalised audit rows |\n| `activity_timeline` | `since?`, `until?`, `bucket=\"day\"` (`hour`\\|`day`) | event counts per time bucket |\n\n### Framework mapping\n\n| Tool | Inputs | Returns |\n|------|--------|---------|\n| `list_frameworks` | — | frameworks + control counts (`hipaa`, `pci_dss`, `soc2`, `gdpr`, `iso27001`, `djcp_l3`) |\n| `coverage_summary` | `framework`, `since?`, `until?` | per-control `covered`/`weak`/`uncovered`, evidence counts, strength labels |\n| `control_evidence` | `framework`, `control_id`, `since?`, `until?`, `sample_size=20` | evidence rows + population size + the reproducible query for ONE control |\n| `gap_analysis` | `framework`, `since?`, `until?` | controls with no/weak evidence + honest `strong`/`partial` caveat + remediation hint |\n\n### Assurance reports\n\n| Tool | Inputs | Returns |\n|------|--------|---------|\n| `approval_report` | `since?`, `until?`, `high_only=True` | high-risk write ops + who approved + rationale (CC8.1 / PCI 7-8 / HIPAA §312(a) artifact) |\n| `exceptions_report` | `since?`, `until?` | denied / error / budget_exceeded ops — enforcement + anomaly evidence |\n\n### Integrity\n\n| Tool | Inputs | Returns |\n|------|--------|---------|\n| `verify_source_chain` | `source`, `since?`, `until?` | chain head + row-id gap detection (flags deletions) for one source |\n| `verify_bundle` | `bundle_path` | verifies chain + seal head + optional signature; `ok` + any mismatch detail |\n| `list_bundles` | — | bundles under `~/.compliance-aiops/bundles/` |\n| `oscal_assessment_results` | `bundle_path` | the bundle as a NIST **OSCAL 1.2.3** Assessment Results document, returned inline with a `summary` (satisfied / not-satisfied / **satisfiedOnPartialEvidence** / scanTruncated) and an explicit `limitations` list. Deterministic: v5 UUIDs derived from the chain head, so re-export is byte-identical |\n| `bundle_schedule_hint` | `framework`, `cron=\"0 2 * * 1\"`, `period=\"7d\"`, `sign=False` | ready-to-paste 5-field cron line + non-interactive command for periodic sealing; **writes nothing, no daemon** |\n\n## Write / artifact tools (3 — no external mutation)\n\n| Tool | Risk | Inputs | Returns / effect |\n|------|:---:|--------|------------------|\n| `generate_evidence_bundle` | **medium** | `framework`, `period_start?`, `period_end?`, `out_path?`, `sign=False`, `period?` (relative window e.g. `7d`) | one call: coverage + approval trail + exceptions + sealed records → a bundle `.json` under `~/.compliance-aiops/bundles/`; returns path + `chainHead` |\n| `export_bundle` | **medium** | `bundle_path`, `fmt=\"markdown\"` (`markdown`\\|`csv`\\|`json`\\|`oscal`), `out_path?` | renders a bundle to the chosen format; `oscal` writes `<bundle>.oscal.json` |\n| `sign_bundle` | **medium** | `bundle_path` | adds an HMAC signature over the seal using the stored signing key |\n\n## Integrity model\n\n- Each record hash = `SHA-256(prev_hash ‖ canonical_json(record))`; genesis\n  `prev` = 64 zeros. The `chainHead` is the last record hash.\n- Seal = `{framework, period, sources (+ per-db SHA-256), recordCount, chainHead,\n  generatedAt, generator, optional signature}`.\n- The chain is over **evidence records only**, so `chainHead` is **reproducible**\n  for the same (framework, period, sources).\n- **Tamper-EVIDENT, not tamper-PROOF** — the source `audit.db` remains the system\n  of record; record `chainHead` out-of-band as an anchor.\n\n## Out of scope (by design)\n\n- Scanning or operating infrastructure (use the other AIops-tools)\n- Acting as a GRC platform / policy-management system\n- OSCAL export (documented v0.2 roadmap; v0.1 emits JSON / Markdown / CSV)\n\nWant another framework, control mapping, or export format? Open an issue or PR —\nfeedback and contributions welcome.\n\nFile v0.11.3:references/cli-reference.md\n\n# compliance-aiops CLI reference\n\n> Evidence, not certification. Reads the local audit trails governed\n> AIops tools write (`~/.*-aiops/audit.db`) read-only. No external API, no\n> network, no platform credentials. The CLI is a convenience subset; the full\n> 19-tool surface is available over MCP.\n\n## Setup & diagnostics\n\n```bash\ncompliance-aiops init                      # discover sibling audit DBs, set org name, optional signing key\ncompliance-aiops doctor                    # which sibling audit DBs are present/readable\ncompliance-aiops overview                  # audit sources + per-framework covered/total counts\ncompliance-aiops mcp                        # start the MCP server (stdio transport)\n```\n\n## Reports (read-only)\n\n```bash\ncompliance-aiops report sources                    # discovered audit sources + row counts\ncompliance-aiops report coverage <framework>       # per-control coverage (hipaa|pci_dss|soc2|gdpr)\ncompliance-aiops report gaps <framework>           # controls with no/weak evidence + honest caveat\ncompliance-aiops report approvals                  # high-risk write ops + approver + rationale\ncompliance-aiops report exceptions                 # denied / error / budget_exceeded ops\n```\n\n## Bundles (evidence artifacts)\n\n```bash\ncompliance-aiops bundle generate <framework> [--since <iso>] [--until <iso>] [--period <7d|24h|2w|last-7-days>] [--sign]\n                                                   # hash-chain-sealed bundle → ~/.compliance-aiops/bundles/\ncompliance-aiops bundle verify <path>              # re-verify chain + seal head (+ signature)\ncompliance-aiops bundle list                       # list generated bundles\ncompliance-aiops bundle export <path> --format <markdown|csv|json>\ncompliance-aiops bundle schedule <framework> [--cron \"0 2 * * 1\"] [--period 7d] [--sign]\n                                                   # print a ready-to-paste cron line; WRITES NOTHING, no daemon\n```\n\n## Secrets (optional bundle-signing key, encrypted ~/.compliance-aiops/secrets.enc)\n\nOnly needed if you sign bundles; there are no platform credentials.\n\n```bash\ncompliance-aiops secret set <name> [--value <key>]   # store signing key (hidden prompt if no --value)\ncompliance-aiops secret list                          # names only — values never shown\ncompliance-aiops secret rm <name>\ncompliance-aiops secret migrate                       # import a legacy plaintext key\ncompliance-aiops secret rotate-password               # re-encrypt under a new master password\n```\n\n## Notes\n\n- `<framework>` is one of `hipaa`, `pci_dss`, `soc2`, `gdpr`, `iso27001`, `djcp_l3`.\n- `--since` / `--until` bound the evidence period (ISO-8601). The hash chain is\n  over evidence records only, so the same `(framework, period, sources)`\n  reproduces the same `chainHead`.\n- `--period` is a convenience relative window (`7d` / `24h` / `2w` /\n  `last-7-days`) resolved to a since/until pair ending \"now\"; used only when\n  `--since` / `--until` are not given. `bundle schedule` prints a cron line for\n  running that periodically — it starts no daemon and writes nothing.\n- `--sign` requires a stored signing key; unlock non-interactively by exporting\n  `COMPLIANCE_AIOPS_MASTER_PASSWORD`.\n- Bundles are the only files written (under `~/.compliance-aiops/bundles/`); the\n  source audit DBs are opened read-only.\n\nFile v0.11.3:references/setup-guide.md\n\n# compliance-aiops setup & security guide\n\n> Evidence, not certification. Reads the local audit trails governed\n> AIops tools already write, read-only. **No external API, no network, no\n> platform credentials.**\n\n## 1. Install\n\n```bash\nuv tool install compliance-aiops\n```\n\n## 2. Onboard\n\n```bash\ncompliance-aiops init\n```\n\nThe `init` wizard:\n\n- **Auto-discovers sibling audit DBs** by globbing `~/.*-aiops/audit.db` (e.g.\n  `~/.nutanix-aiops/audit.db`, `~/.<tool>-aiops/audit.db`). These are the local\n  `audit_log` trails your governed AIops tools already write. Each discovered\n  source can be included and tagged.\n- **Records an organization name** and the selected sources into\n  `~/.compliance-aiops/config.yaml`.\n- **Optionally stores a bundle-signing key** — encrypted, Fernet (AES-128-CBC +\n  HMAC) with a scrypt-derived key. This is the *only* secret the tool uses, and\n  it is optional: if you never sign bundles you need no secret at all.\n\nNo platform credentials are collected, because the tool never connects to any\nplatform — its inputs are on-disk audit databases opened **read-only**.\n\nExample `~/.compliance-aiops/config.yaml`:\n\n```yaml\norganization: Acme Health, Inc.\nsources:\n  - name: nutanix\n    path: ~/.nutanix-aiops/audit.db\n    tag: infra\n  - name: k8s\n    path: ~/.k8s-aiops/audit.db\n    tag: platform\n```\n\n## 3. Non-interactive use (MCP server / CI / cron)\n\nOnly needed if you **sign** bundles. Export the master password so the encrypted\nsigning-key store can be unlocked without a prompt:\n\n```bash\nexport COMPLIANCE_AIOPS_MASTER_PASSWORD='your-master-password'\n```\n\n## Signing-key security\n\n- The signing key is **never** written to disk in plaintext. It lives only in\n  `~/.compliance-aiops/secrets.enc`, encrypted with Fernet, the key derived from\n  your master password via scrypt. Only a per-store random salt and the\n  ciphertext are on disk (chmod 600); the master password itself is never stored.\n- A legacy plaintext key is honoured as a fallback with a deprecation warning —\n  migrate with `compliance-aiops secret migrate`.\n- The key is held only in memory during a session and is never logged or echoed.\n\n## State & outputs\n\nState lives under `~/.compliance-aiops/` (relocate with `COMPLIANCE_AIOPS_HOME`):\n\n- `config.yaml` — organization name + selected audit sources\n- `secrets.enc` — the optional encrypted signing key\n- `bundles/` — generated evidence bundles (**the only files the tool writes**)\n- `audit.db` — this tool's own governance audit log (every tool call recorded)\n\nThe source `~/.<tool>-aiops/audit.db` trails are opened **read-only** and never\nmodified.\n\n## Integrity notes\n\n- **Reproducible `chainHead`.** The hash chain is over evidence records only, so\n  the same `(framework, period, sources)` reproduces the same `chainHead`. Record\n  it out-of-band to create an independent anchor.\n- **Tamper-EVIDENT, not tamper-PROOF.** The chain and optional signature let an\n  auditor *detect* alteration; the source `audit.db` remains the system of record.\n- `verify_bundle` re-derives the chain and checks the seal head + signature;\n  `verify_source_chain` flags **row-id gaps** in a source (a sign of deleted rows).\n\n## Verify\n\n```bash\ncompliance-aiops doctor\n```\n\n`doctor` reports which sibling audit DBs are present and readable, and whether the\nconfig and (optional) signing-key store are in place.\n\nFile v0.11.3:skill-card.md\n\n## Description:\n\nProduces compliance evidence from governed AIops audit trails by mapping recorded agent activity to HIPAA, PCI-DSS, SOC 2, GDPR, ISO 27001, and DJCP controls, generating reports, and creating hash-chain-sealed evidence bundles.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[zw008](https://clawhub.ai/user/zw008)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, platform engineers, and compliance teams use this skill to inspect local AIops audit databases, summarize framework control coverage, identify evidence gaps, and prepare tamper-evident evidence bundles for review. It supports evidence preparation, not certification or infrastructure operation.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The security verdict is suspicious because the release installs mutable external code.\n\nMitigation: Review before installing and use a pinned, verified package version where possible.\n\nRisk: The release has inconsistent write-scope disclosures around generated bundles and exports.\n\nMitigation: Run under a restricted account with access only to the audit databases needed and treat generated bundles as sensitive compliance records.\n\nRisk: Unattended signing through cron or CI can expose signing operations to misconfiguration or weak secret handling.\n\nMitigation: Avoid unattended signing until secret handling is reviewed; if signing is needed, provide the master password through a protected environment and verify the generated bundle.\n\nRisk: Compliance outputs can be mistaken for a pass, certification, or full control verdict.\n\nMitigation: Present outputs as evidence from available audit trails only, preserve caveats about partial coverage, and have qualified reviewers assess certification or compliance status.\n\n## Reference(s):\n\n- [Compliance AIops source repository](https://github.com/AIops-tools/Compliance-AIops)\n- [Capabilities reference](references/capabilities.md)\n- [CLI reference](references/cli-reference.md)\n- [Setup and security guide](references/setup-guide.md)\n- [Agent guardrails](references/agent-guardrails.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with inline shell commands, plus generated JSON, Markdown, CSV, or OSCAL evidence artifacts when bundle tools are used]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Reads local audit databases read-only; generated bundles and exports are written under the compliance-aiops home directory and may contain sensitive compliance evidence.]\n\n## Skill Version(s):\n\n0.11.3 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.11.2: 7 files, 17493 bytes\n\nFiles: references/agent-guardrails.md (7993b), references/capabilities.md (4440b), references/cli-reference.md (3342b), references/setup-guide.md (3370b), skill-card.md (2603b), SKILL.md (14887b), _meta.json (136b)\n\nFile v0.11.2:SKILL.md\n\n---\nname: compliance-aiops\nslug: compliance-aiops\ndisplayName: \"Compliance AIops\"\nsummary: \"Compliance evidence from AIops audit trails: HIPAA/PCI/SOC2/GDPR, OSCAL export, 19 tools.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/Compliance-AIops\ntags: [aiops, mcp, governance, compliance]\ndescription: >\n  Use this skill whenever the user needs compliance evidence from the audit trails their governed AIops agents already write — mapping AI-agent infra-ops activity to HIPAA §164.312, PCI-DSS v4.0, SOC 2 TSC, or GDPR controls, producing a change-approval report, a gap analysis, an exceptions/anomaly report, or a hash-chain-sealed, tamper-evident evidence bundle.\n  Always use this skill for \"compliance evidence\", \"HIPAA / PCI-DSS / SOC 2 / GDPR evidence\", \"audit trail report\", \"coverage for control X\", \"which controls are we short on / gap analysis\", \"who approved this change / change-management evidence\", \"denied or errored ops / anomaly evidence\", \"seal / sign an evidence bundle\", \"prove this bundle wasn't altered\", or \"detect deleted audit rows\".\n  Do NOT use to scan or operate infrastructure and do NOT treat it as a GRC platform — it reads the local audit databases the OTHER AIops-tools write and converts them to evidence; for platform operations use those other AIops-tools.\n  Evidence, not certification. Reads sibling audit trails read-only; no external API, no network, no platform credentials. Fully offline and deterministic.\ninstaller:\n  kind: uv\n  package: compliance-aiops\nargument-hint: \"[framework (hipaa|pci_dss|soc2|gdpr|iso27001|djcp_l3) or describe your evidence task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"compliance-aiops\",\"uvx\"]},\"optional\":{\"env\":[\"COMPLIANCE_AIOPS_CONFIG\",\"COMPLIANCE_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/Compliance-AIops\",\"emoji\":\"📋\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone compliance-evidence tooling. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.\n  Data source: the LOCAL audit databases the other governed AIops tools already write, discovered by glob at ~/.*-aiops/audit.db (one shared audit_log schema). These are read READ-ONLY. There is NO external API, NO network, and NO platform credentials.\n  The only optional secret is a bundle-signing key, stored ENCRYPTED in ~/.compliance-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk, unlocked by a master password from COMPLIANCE_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). If you never sign bundles you need no secret at all.\n  Outputs: evidence bundles written to ~/.compliance-aiops/bundles/ (the only files written). All tool calls are themselves audited to a local SQLite DB under ~/.compliance-aiops/ (relocatable via COMPLIANCE_AIOPS_HOME). Write tools (generate_evidence_bundle, export_bundle: low risk; sign_bundle: medium) pass through the @governed_tool decorator but perform NO external mutation.\n  Integrity: bundles are hash-chain-sealed (SHA-256 over ordered records; reproducible chainHead) with an optional HMAC signature. Tamper-EVIDENT, not tamper-PROOF — the source audit.db remains the system of record.\n  Webhooks: none — no outbound network calls at all.\n  Transitive dependencies: the MCP SDK and cryptography (Fernet). No post-install scripts or background services.\n  Evidence, not certification. Fully offline and deterministic; the integrity claims are covered by deterministic offline tests (see docs/VERIFICATION.md). OSCAL export is a v0.2 roadmap item (v0.1 emits JSON/Markdown/CSV).\n---\n\n# Compliance AIops\n\n> **Disclaimer**: Community-maintained open-source project, **not affiliated with, endorsed by, or sponsored by any framework body or GRC vendor.** HIPAA, PCI-DSS, SOC 2, GDPR and OSCAL are referenced descriptively; trademarks belong to their owners. Source at [github.com/AIops-tools/Compliance-AIops](https://github.com/AIops-tools/Compliance-AIops) under the MIT license.\n\nGoverned **compliance-evidence** tooling — **19 MCP tools**. It **reads the audit\ntrails your governed AIops agents already write** (`~/.<tool>-aiops/audit.db`, one\nshared `audit_log` schema, discovered via `~/.*-aiops/audit.db`) **read-only**,\nand turns that activity into **framework-mapped, hash-chain-sealed compliance\nevidence**. It does **not** scan infrastructure and does **not** replace a GRC\nplatform.\n\n> **Standalone**: the governance harness is bundled (`compliance_aiops.governance`).\n> **Not a platform wrapper** — no external API, no network, no platform\n> credentials. **Evidence, not certification**; fully offline and deterministic.\n\n## What This Skill Does\n\n| Group | Tools | Count | Read/Write |\n|-------|-------|:-----:|:----------:|\n| **Audit reads** | `list_audit_sources`, `query_audit_events`, `activity_timeline` | 3 | read |\n| **Framework mapping** | `list_frameworks`, `coverage_summary`, `control_evidence`, `gap_analysis` | 4 | read |\n| **Assurance reports** | `approval_report`, `exceptions_report` | 2 | read |\n| **Integrity** | `verify_source_chain`, `verify_bundle`, `list_bundles`, `bundle_schedule_hint`, `oscal_assessment_results` | 5 | read |\n| **Artifacts** | `generate_evidence_bundle` (low), `export_bundle` (low), `sign_bundle` (medium) | 3 | write (no external mutation) |\n| **Undo** | `undo_list`, `undo_apply` | 2 | undo |\n\n## Frameworks & sample controls\n\n| Framework | Sample controls (strength) |\n|-----------|----------------------------|\n| **HIPAA** §164.312 | 164.312(b) Audit controls (strong), 164.312(a)(1) Access control (strong), 164.312(c)(1) Integrity (strong) |\n| **PCI-DSS v4.0** | 10.2 Audit log content (strong), 10.3 Protect audit logs (strong), 7-8 Least privilege / authn (partial) |\n| **SOC 2 TSC** | CC6.1 Logical access (strong), CC7.2 Monitoring (strong), CC8.1 Change management (strong) |\n| **GDPR** | Art.30 Records of processing (partial), Art.32 Security of processing (strong) |\n| **ISO/IEC 27001:2022** (Annex A) | A.5.15 Access control (strong), A.5.16 Identity mgmt (strong), A.5.18 Access rights (partial), A.8.2 Privileged access (partial), A.8.15 Logging (strong), A.8.16 Monitoring (strong), A.8.32 Change management (strong) |\n| **等保2.0 (DJCP L3)** GB/T 22239-2019 三级 | 8.1.5.4 安全审计 (strong), 8.1.4.2 访问控制 (partial), 8.1.5 安全管理中心/集中审计 (strong) |\n\nAudit trails prove *operating effectiveness* strongly but *control design /\nconfiguration* only partially — each control is labelled `strong` or `partial`,\nand `gap_analysis` surfaces the caveat rather than overclaiming.\n\n## Quick Install\n\n```bash\nuv tool install compliance-aiops\ncompliance-aiops init       # discover sibling ~/.*-aiops/audit.db, set org name, optional signing key\ncompliance-aiops doctor     # which sibling audit DBs are present/readable\n```\n\nOr as an OpenClaw plugin, which installs this skill and its MCP server together:\n\n```bash\nopenclaw plugins install clawhub:@zw008/compliance-aiops\nopenclaw skills info compliance-aiops          # expect: Visible to model: yes\n```\n\nNeeds `uvx` on `PATH`: the MCP server is fetched with uv, pinned to this release.\n\n## When to Use This Skill\n\n- Map AI-agent infra-ops activity to a framework's controls (`coverage_summary`)\n- Pull the evidence rows + population for one control (`control_evidence`)\n- Find controls with no or weak evidence, with the honest caveat (`gap_analysis`)\n- Produce a change-approval artifact — who approved which high-risk write and why\n  (`approval_report`)\n- Produce enforcement / anomaly evidence — denied / errored / budget-tripped ops\n  (`exceptions_report`)\n- Seal a tamper-evident evidence bundle (`generate_evidence_bundle`,\n  `sign_bundle`) and later prove it wasn't altered (`verify_bundle`)\n- Detect deleted / missing audit rows in a source trail (`verify_source_chain`)\n\n**Do NOT use** to scan or operate infrastructure, or as a GRC platform. It reads\nthe audit DBs the *other* AIops-tools write; for platform operations use those\nother AIops-tools.\n\n## Related Skills — Skill Routing\n\n| If the user wants… | Use |\n|--------------------|-----|\n| Compliance evidence from existing AIops audit trails | **compliance-aiops** (this skill) |\n| To actually operate a platform (VMs, storage, clusters, network, …) | the relevant platform **AIops-tools** skill |\n| OT / industrial edge (Modbus, OPC-UA, PLC) | the **industrial-aiops** line |\n| A full GRC platform / policy management | out of scope — this is evidence, not GRC |\n\n## Common Workflows\n\n### 1. \"The SOC 2 auditor wants Q3 change-approval evidence by Friday\"\n\n1. `compliance-aiops doctor` → confirm the source audit trails are discoverable\n   and readable before you promise a delivery date\n2. `compliance-aiops report sources` (MCP: `list_audit_sources`) → which sibling\n   audit trails were found, and the event count and date range in each. If a\n   source you expected is missing, the bundle would be silently incomplete —\n   fix discovery first\n3. `compliance-aiops report coverage soc2` → confirm CC8.1 is actually covered by\n   the evidence you have, before generating anything\n4. `compliance-aiops report approvals` → the high-risk write operations with\n   their named approver and rationale — this is the population CC8.1 is asking\n   about\n5. `compliance-aiops bundle generate soc2 --since 2026-07-01 --until 2026-10-01 --sign`\n   → a hash-chain-sealed bundle under `~/.compliance-aiops/bundles/`\n6. `compliance-aiops bundle export <path> --format markdown` → the\n   auditor-facing report (also `json` / `csv`)\n7. **Failure branch**: if `report coverage` shows CC8.1 thin, **do not generate\n   anyway and hope** — run workflow 2 first and hand the auditor the honest gap\n   statement. A bundle asserts what the audit trail contains; it cannot\n   manufacture evidence that was never recorded.\n\n### 2. \"Which controls are we actually short on?\" (gap analysis)\n\n1. `compliance-aiops report sources` → establish the evidence base and its date\n   coverage; a gap caused by a *missing source* is a different problem from a\n   gap caused by *missing activity*\n2. `compliance-aiops report gaps hipaa` (also `pci_dss`, `soc2`, `gdpr`) →\n   controls with no or weak evidence, each with an honest caveat and a\n   remediation suggestion\n3. `compliance-aiops report exceptions` → the operations that ran **without** an\n   approver or rationale — usually the fastest-to-fix category of gap\n4. Drill into one control's population with `control_evidence` (MCP) to see the\n   **reproducible query** behind the coverage number, so the figure can be\n   defended rather than merely quoted\n5. `compliance-aiops report coverage <framework>` again after remediation to\n   confirm the gap actually closed\n6. **Failure branch**: if `list_frameworks` does not carry the framework or\n   control the auditor named, say so — this tool maps to HIPAA / PCI-DSS /\n   SOC 2 / GDPR and does not silently substitute a near-miss control.\n\n### 3. Prove a delivered bundle was not altered\n\n1. `compliance-aiops bundle list` → locate the bundle and its recorded\n   `chainHead`\n2. `compliance-aiops bundle verify <path>` → re-derives the hash chain, compares\n   it to the seal's `chainHead`, and checks the optional signature\n3. Because the chain is computed over evidence records only, the **same**\n   (framework, period, sources) reproduces the **same** `chainHead` — regenerate\n   and compare to prove reproducibility\n4. Record the `chainHead` **out-of-band** (ticket, email to the auditor, WORM\n   store) at delivery time; that out-of-band copy is what makes later\n   verification meaningful\n5. `verify_source_chain` (MCP) on each source → returns the source chain head and\n   flags **row-id gaps**, a sign that rows were deleted from that `audit.db`\n6. **Failure branch**: a `chainHead` mismatch or a row-id gap means the evidence\n   is **not** trustworthy — escalate, and treat the source `audit.db` as the\n   system of record. Do not re-seal a fresh bundle to make the mismatch go away;\n   the tool is **tamper-evident, not tamper-proof**, and its whole value is that\n   it reports this rather than papering over it.\n\n### 4. 定期封存 — schedule periodic sealed bundles (no daemon)\n\nThis tool ships **no scheduler**; it emits a cron line for you to install.\n\n1. `compliance-aiops report sources` → confirm the sources you want sealed are\n   discoverable from the account cron will run as (a common failure: cron sees a\n   different `$HOME`)\n2. `compliance-aiops bundle schedule soc2 --cron \"0 2 * * 1\" --period 7d --sign`\n   (MCP: `bundle_schedule_hint`) → returns a `cronLine` plus the exact\n   non-interactive command. **It writes nothing.**\n3. Paste the `cronLine` into `crontab -e`, e.g.\n   `0 2 * * 1 compliance-aiops bundle generate soc2 --period 7d --sign`\n4. Export `COMPLIANCE_AIOPS_MASTER_PASSWORD` in the cron environment so the\n   signing key unlocks non-interactively — never inline the real password in the\n   crontab\n5. After the first scheduled run, `compliance-aiops bundle list` and\n   `bundle verify` the newest bundle to confirm the unattended path really works\n6. **Failure branch**: if the cron run produces no bundle, the usual causes are\n   an unset master password (signing cannot unlock) or `COMPLIANCE_AIOPS_HOME`\n   not being set in cron's environment, so sources resolve elsewhere. Verify by\n   running the emitted command by hand with a clean environment before trusting\n   the schedule.\n\n## Governance & Safety\n\nThe skill reads audit trails and writes evidence bundles and records what it\ndoes; it does **not** decide whether producing or signing a bundle is permitted.\nThat is your agent's judgement, or the filesystem permissions of the account it\nruns as. There is no read-only switch, policy file, or approval gate.\n\n- **Audit is the guarantee, and it is not bypassable.** Every operation — MCP and CLI alike — is logged to `~/.compliance-aiops/audit.db` (relocatable via `COMPLIANCE_AIOPS_HOME`): params, result, status, duration, and the risk tier. The CLI writes the same row the MCP path does.\n- The source audit trails are opened **read-only**; the tool never mutates them. The only files written are bundles under `~/.compliance-aiops/bundles/`.\n- `COMPLIANCE_AUDIT_APPROVED_BY` / `COMPLIANCE_AUDIT_RATIONALE` are optional annotations recorded on the audit row (who/why); they are never required and never block.\n- **Tamper-EVIDENT, not tamper-PROOF** — the source `audit.db` remains the system\n  of record.\n\n## References\n\n- `references/capabilities.md` — full tool → inputs → returns reference\n- `references/cli-reference.md` — CLI command reference\n- `references/setup-guide.md` — source discovery, org name, optional signing key, integrity notes\n\nFile v0.11.2:_meta.json\n\n{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"compliance-aiops\",\n  \"version\": \"0.11.2\",\n  \"publishedAt\": 1789221995426\n}\n\nFile v0.11.2:references/agent-guardrails.md\n\n# Agent guardrails — running compliance-aiops with a smaller / local model\n\ncompliance-aiops is a **meta-tool**: it reads the audit databases the other\nAIops tools write, and turns them into framework-mapped evidence. That makes the\nfailure mode here different from an infrastructure tool. A wrong answer does not\nbreak a cluster — it produces a **confident, false compliance claim**, which is\nworse, because it looks like a finding.\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\n## Authorization is not this tool's job — decide it where it belongs\n\nWhether a bundle should be produced or signed is your decision, or the account's.\nThe tool does not gate it — there is no read-only switch and no approval prompt\nto configure. The two right places to control it:\n\n- **The account it runs as.** The tool only ever writes under\n  `~/.compliance-aiops/`, and opens every source `audit.db` strictly read-only —\n  so ordinary filesystem permissions bound what it can do. A write then fails at\n  the OS, which is the only place the permission actually lives.\n- **Your agent's system prompt.** If you want a query-only session, tell the\n  model not to call the bundle-writing tools (they are clearly tagged `[WRITE]`).\n\nWhat the tool *does* guarantee is that you can always see what happened:\n\n## What the tool enforces — do not waste prompt budget on these\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Never modify the audit trail\" | The tool has no capability to write to any source `audit.db` — it opens them read-only. Nothing in the tool surface can alter the evidence it reports on. |\n| \"Don't get stuck retrying\" | The runaway guard trips a circuit breaker if the same call is hammered in a tight loop — a stuck agent is stopped rather than left to burn calls and time. |\n| \"Don't invent an approver or a reason\" | A field the audit row did not record comes back as `null`, never as `\"\"`. \"No approver was recorded\" and \"the approver field was blank\" stay distinguishable — which is exactly the distinction a change-approval finding turns on. |\n| \"Tell me if you only saw part of the trail\" | Every report carries `scanLimit` and `scanTruncated`, and every capped list carries `returned` / `limit` / `truncated`. Truncation is measured — one row past the cap is fetched — never inferred from a count landing on a round number. |\n| \"Check the evidence hasn't been tampered with\" | `verify_source_chain` hash-chains a source's current events and reports row-id gaps; `verify_bundle` re-derives a sealed bundle's chain and reports the first broken link plus signature validity. You do not need to ask the model to reason about integrity — ask it to run the check. |\n| \"Be honest about what an audit log can prove\" | Every control carries a `strength` and a `caveat`, and gap findings carry the design-vs-operating note. Coverage is only claimed where the trail actually contains the evidence. |\n| \"Log everything you do, over both MCP and the CLI\" | Every call is audited to `~/.compliance-aiops/audit.db` regardless of what the model says it did — and the CLI writes the same row the MCP path does, so there is no unaudited entry point. |\n\n## What still needs a prompt\n\nThese are model-behaviour problems the harness cannot fix from the outside.\nCopy this into your agent's system prompt:\n\n```text\nYou operate compliance-aiops, which reads the audit trails other AIops tools\nproduce and maps them to framework controls (HIPAA, PCI-DSS, SOC2, GDPR).\n\nTOOL USE\n- Before answering any question about compliance posture, coverage, or a\n  specific control, you MUST call a tool. Never answer from memory, and never\n  from your training knowledge of what a framework requires.\n- Actually invoke the tool. Do not describe the call you would make, and do not\n  emit an example JSON response in place of calling it.\n- If a tool call fails, report the real error verbatim. An unreadable audit\n  source means unknown coverage, not zero findings and not full coverage.\n\nEVIDENCE INTEGRITY — the part that matters most here\n- NEVER state or imply that an organisation \"is compliant\", \"passes\", or \"is\n  certified\". This tool produces evidence about operations recorded in an audit\n  trail. Certification is a judgement made by a qualified assessor over a much\n  wider scope. Say what the evidence shows; never issue a verdict.\n- If a result has scanTruncated or truncated set to true, the population you saw\n  is a slice. Say so explicitly and do not compute or quote a coverage\n  percentage, a total, or a \"no violations found\" statement from it.\n- Quote counts and control ids exactly as returned. Never round, extrapolate,\n  or fill a gap in the trail with an assumption about what probably happened.\n- A null approver means no approver was recorded — report that as the finding\n  it is. Do not soften it, and do not guess who approved.\n- Report every control's caveat and strength alongside its coverage. A control\n  marked PARTIAL is not covered; it is partly evidenced by operational logs and\n  needs design/configuration evidence from a GRC system.\n- An absence of evidence for a control means the trail contains nothing matching\n  it. That is not proof the control failed, and not proof it passed. Say which\n  one the data supports: neither.\n\nSCOPE\n- Separate observation from interpretation. State what the tools returned, then\n  any interpretation, clearly marked as such.\n- A hash chain is tamper-EVIDENT, not tamper-PROOF. An \"intact\" verdict means\n  the records match a previously recorded head — it does not prove nothing was\n  ever deleted before that head was taken. Row-id gaps are the signal for that,\n  and they are reported separately.\n- Do not confuse the source tools' identifiers with each other: a `source` is an\n  AIops tool's audit database, a `skill` is the tool that logged the row, and a\n  `tool` is the individual operation. They are three different columns.\n```\n\n## Recommended setup for a local model\n\nKeep the agent query-only until you trust the setup — the tool already opens\nevery source trail read-only, and the only thing it can write is a bundle under\n`~/.compliance-aiops/`:\n\n```bash\ncompliance-aiops doctor\n```\n\nOptionally annotate the audit trail with who is operating and why — recorded on\nevery row, never required:\n\n```bash\nexport COMPLIANCE_AUDIT_APPROVED_BY=\"your.name@example.com\"\nexport COMPLIANCE_AUDIT_RATIONALE=\"Q3 SOC2 evidence collection\"\n```\n\n## If your model still struggles\n\nSome behaviours are model-capacity limits rather than prompt problems:\n\n- **The model editorialises into a verdict.** This is the characteristic failure\n  of smaller models on this tool. Ask for the numbers first (\"what does\n  coverage_summary return for soc2?\") and only then for a summary, rather than\n  asking \"are we SOC2 compliant?\" — the second phrasing invites a verdict the\n  data cannot support.\n- **Multi-tool workflows time out or drift.** Lead with `posture_overview` — it\n  folds source availability and per-framework coverage into one call.\n- **The model ignores later tool results in a long context.** Ask about one\n  control at a time with `control_evidence` rather than pulling a whole\n  framework's population.\n- **The model describes calls instead of making them.** This is usually a\n  runtime/tool-calling-format mismatch, not a prompt problem — check that your\n  client advertises the tools in the format your model was trained on.\n\nFeedback on running this with a specific local model is genuinely useful —\nopen an issue at\n[github.com/AIops-tools/Compliance-AIops](https://github.com/AIops-tools/Compliance-AIops/issues)\nwith the model, runtime, and what went wrong.\n\nFile v0.11.2:references/capabilities.md\n\n# compliance-aiops capabilities\n\n> Evidence, not certification. 19 MCP tools (14 read, 3 write, 2 undo). Data\n> source: the local `audit_log` trails governed AIops tools write, discovered via\n> `~/.*-aiops/audit.db` and read **read-only**. No external API, no network, no\n> platform credentials. `since` / `until` accept ISO-8601 timestamps.\n\n## Read / analysis tools (12)\n\n### Audit reads\n\n| Tool | Inputs | Returns |\n|------|--------|---------|\n| `list_audit_sources` | — | discovered sources: `name`, `path`, `tool`, `readable`, `rowCount` |\n| `query_audit_events` | `source?`, `skill?`, `tool?`, `status?`, `risk_level?`, `approved?`, `selector?`, `since?`, `until?`, `limit=100` | matched events (cross-tool), normalised audit rows |\n| `activity_timeline` | `since?`, `until?`, `bucket=\"day\"` (`hour`\\|`day`) | event counts per time bucket |\n\n### Framework mapping\n\n| Tool | Inputs | Returns |\n|------|--------|---------|\n| `list_frameworks` | — | frameworks + control counts (`hipaa`, `pci_dss`, `soc2`, `gdpr`, `iso27001`, `djcp_l3`) |\n| `coverage_summary` | `framework`, `since?`, `until?` | per-control `covered`/`weak`/`uncovered`, evidence counts, strength labels |\n| `control_evidence` | `framework`, `control_id`, `since?`, `until?`, `sample_size=20` | evidence rows + population size + the reproducible query for ONE control |\n| `gap_analysis` | `framework`, `since?`, `until?` | controls with no/weak evidence + honest `strong`/`partial` caveat + remediation hint |\n\n### Assurance reports\n\n| Tool | Inputs | Returns |\n|------|--------|---------|\n| `approval_report` | `since?`, `until?`, `high_only=True` | high-risk write ops + who approved + rationale (CC8.1 / PCI 7-8 / HIPAA §312(a) artifact) |\n| `exceptions_report` | `since?`, `until?` | denied / error / budget_exceeded ops — enforcement + anomaly evidence |\n\n### Integrity\n\n| Tool | Inputs | Returns |\n|------|--------|---------|\n| `verify_source_chain` | `source`, `since?`, `until?` | chain head + row-id gap detection (flags deletions) for one source |\n| `verify_bundle` | `bundle_path` | verifies chain + seal head + optional signature; `ok` + any mismatch detail |\n| `list_bundles` | — | bundles under `~/.compliance-aiops/bundles/` |\n| `oscal_assessment_results` | `bundle_path` | the bundle as a NIST **OSCAL 1.2.3** Assessment Results document, returned inline with a `summary` (satisfied / not-satisfied / **satisfiedOnPartialEvidence** / scanTruncated) and an explicit `limitations` list. Deterministic: v5 UUIDs derived from the chain head, so re-export is byte-identical |\n| `bundle_schedule_hint` | `framework`, `cron=\"0 2 * * 1\"`, `period=\"7d\"`, `sign=False` | ready-to-paste 5-field cron line + non-interactive command for periodic sealing; **writes nothing, no daemon** |\n\n## Write / artifact tools (3 — no external mutation)\n\n| Tool | Risk | Inputs | Returns / effect |\n|------|:---:|--------|------------------|\n| `generate_evidence_bundle` | **medium** | `framework`, `period_start?`, `period_end?`, `out_path?`, `sign=False`, `period?` (relative window e.g. `7d`) | one call: coverage + approval trail + exceptions + sealed records → a bundle `.json` under `~/.compliance-aiops/bundles/`; returns path + `chainHead` |\n| `export_bundle` | **medium** | `bundle_path`, `fmt=\"markdown\"` (`markdown`\\|`csv`\\|`json`\\|`oscal`), `out_path?` | renders a bundle to the chosen format; `oscal` writes `<bundle>.oscal.json` |\n| `sign_bundle` | **medium** | `bundle_path` | adds an HMAC signature over the seal using the stored signing key |\n\n## Integrity model\n\n- Each record hash = `SHA-256(prev_hash ‖ canonical_json(record))`; genesis\n  `prev` = 64 zeros. The `chainHead` is the last record hash.\n- Seal = `{framework, period, sources (+ per-db SHA-256), recordCount, chainHead,\n  generatedAt, generator, optional signature}`.\n- The chain is over **evidence records only**, so `chainHead` is **reproducible**\n  for the same (framework, period, sources).\n- **Tamper-EVIDENT, not tamper-PROOF** — the source `audit.db` remains the system\n  of record; record `chainHead` out-of-band as an anchor.\n\n## Out of scope (by design)\n\n- Scanning or operating infrastructure (use the other AIops-tools)\n- Acting as a GRC platform / policy-management system\n- OSCAL export (documented v0.2 roadmap; v0.1 emits JSON / Markdown / CSV)\n\nWant another framework, control mapping, or export format? Open an issue or PR —\nfeedback and contributions welcome.\n\nFile v0.11.2:references/cli-reference.md\n\n# compliance-aiops CLI reference\n\n> Evidence, not certification. Reads the local audit trails governed\n> AIops tools write (`~/.*-aiops/audit.db`) read-only. No external API, no\n> network, no platform credentials. The CLI is a convenience subset; the full\n> 19-tool surface is available over MCP.\n\n## Setup & diagnostics\n\n```bash\ncompliance-aiops init                      # discover sibling audit DBs, set org name, optional signing key\ncompliance-aiops doctor                    # which sibling audit DBs are present/readable\ncompliance-aiops overview                  # audit sources + per-framework covered/total counts\ncompliance-aiops mcp                        # start the MCP server (stdio transport)\n```\n\n## Reports (read-only)\n\n```bash\ncompliance-aiops report sources                    # discovered audit sources + row counts\ncompliance-aiops report coverage <framework>       # per-control coverage (hipaa|pci_dss|soc2|gdpr)\ncompliance-aiops report gaps <framework>           # controls with no/weak evidence + honest caveat\ncompliance-aiops report approvals                  # high-risk write ops + approver + rationale\ncompliance-aiops report exceptions                 # denied / error / budget_exceeded ops\n```\n\n## Bundles (evidence artifacts)\n\n```bash\ncompliance-aiops bundle generate <framework> [--since <iso>] [--until <iso>] [--period <7d|24h|2w|last-7-days>] [--sign]\n                                                   # hash-chain-sealed bundle → ~/.compliance-aiops/bundles/\ncompliance-aiops bundle verify <path>              # re-verify chain + seal head (+ signature)\ncompliance-aiops bundle list                       # list generated bundles\ncompliance-aiops bundle export <path> --format <markdown|csv|json>\ncompliance-aiops bundle schedule <framework> [--cron \"0 2 * * 1\"] [--period 7d] [--sign]\n                                                   # print a ready-to-paste cron line; WRITES NOTHING, no daemon\n```\n\n## Secrets (optional bundle-signing key, encrypted ~/.compliance-aiops/secrets.enc)\n\nOnly needed if you sign bundles; there are no platform credentials.\n\n```bash\ncompliance-aiops secret set <name> [--value <key>]   # store signing key (hidden prompt if no --value)\ncompliance-aiops secret list                          # names only — values never shown\ncompliance-aiops secret rm <name>\ncompliance-aiops secret migrate                       # import a legacy plaintext key\ncompliance-aiops secret rotate-password               # re-encrypt under a new master password\n```\n\n## Notes\n\n- `<framework>` is one of `hipaa`, `pci_dss`, `soc2`, `gdpr`, `iso27001`, `djcp_l3`.\n- `--since` / `--until` bound the evidence period (ISO-8601). The hash chain is\n  over evidence records only, so the same `(framework, period, sources)`\n  reproduces the same `chainHead`.\n- `--period` is a convenience relative window (`7d` / `24h` / `2w` /\n  `last-7-days`) resolved to a since/until pair ending \"now\"; used only when\n  `--since` / `--until` are not given. `bundle schedule` prints a cron line for\n  running that periodically — it starts no daemon and writes nothing.\n- `--sign` requires a stored signing key; unlock non-interactively by exporting\n  `COMPLIANCE_AIOPS_MASTER_PASSWORD`.\n- Bundles are the only files written (under `~/.compliance-aiops/bundles/`); the\n  source audit DBs are opened read-only.\n\nFile v0.11.2:references/setup-guide.md\n\n# compliance-aiops setup & security guide\n\n> Evidence, not certification. Reads the local audit trails governed\n> AIops tools already write, read-only. **No external API, no network, no\n> platform credentials.**\n\n## 1. Install\n\n```bash\nuv tool install compliance-aiops\n```\n\n## 2. Onboard\n\n```bash\ncompliance-aiops init\n```\n\nThe `init` wizard:\n\n- **Auto-discovers sibling audit DBs** by globbing `~/.*-aiops/audit.db` (e.g.\n  `~/.nutanix-aiops/audit.db`, `~/.<tool>-aiops/audit.db`). These are the local\n  `audit_log` trails your governed AIops tools already write. Each discovered\n  source can be included and tagged.\n- **Records an organization name** and the selected sources into\n  `~/.compliance-aiops/config.yaml`.\n- **Optionally stores a bundle-signing key** — encrypted, Fernet (AES-128-CBC +\n  HMAC) with a scrypt-derived key. This is the *only* secret the tool uses, and\n  it is optional: if you never sign bundles you need no secret at all.\n\nNo platform credentials are collected, because the tool never connects to any\nplatform — its inputs are on-disk audit databases opened **read-only**.\n\nExample `~/.compliance-aiops/config.yaml`:\n\n```yaml\norganization: Acme Health, Inc.\nsources:\n  - name: nutanix\n    path: ~/.nutanix-aiops/audit.db\n    tag: infra\n  - name: k8s\n    path: ~/.k8s-aiops/audit.db\n    tag: platform\n```\n\n## 3. Non-interactive use (MCP server / CI / cron)\n\nOnly needed if you **sign** bundles. Export the master password so the encrypted\nsigning-key store can be unlocked without a prompt:\n\n```bash\nexport COMPLIANCE_AIOPS_MASTER_PASSWORD='your-master-password'\n```\n\n## Signing-key security\n\n- The signing key is **never** written to disk in plaintext. It lives only in\n  `~/.compliance-aiops/secrets.enc`, encrypted with Fernet, the key derived from\n  your master password via scrypt. Only a per-store random salt and the\n  ciphertext are on disk (chmod 600); the master password itself is never stored.\n- A legacy plaintext key is honoured as a fallback with a deprecation warning —\n  migrate with `compliance-aiops secret migrate`.\n- The key is held only in memory during a session and is never logged or echoed.\n\n## State & outputs\n\nState lives under `~/.compliance-aiops/` (relocate with `COMPLIANCE_AIOPS_HOME`):\n\n- `config.yaml` — organization name + selected audit sources\n- `secrets.enc` — the optional encrypted signing key\n- `bundles/` — generated evidence bundles (**the only files the tool writes**)\n- `audit.db` — this tool's own governance audit log (every tool call recorded)\n\nThe source `~/.<tool>-aiops/audit.db` trails are opened **read-only** and never\nmodified.\n\n## Integrity notes\n\n- **Reproducible `chainHead`.** The hash chain is over evidence records only, so\n  the same `(framework, period, sources)` reproduces the same `chainHead`. Record\n  it out-of-band to create an independent anchor.\n- **Tamper-EVIDENT, not tamper-PROOF.** The chain and optional signature let an\n  auditor *detect* alteration; the source `audit.db` remains the system of record.\n- `verify_bundle` re-derives the chain and checks the seal head + signature;\n  `verify_source_chain` flags **row-id gaps** in a source (a sign of deleted rows).\n\n## Verify\n\n```bash\ncompliance-aiops doctor\n```\n\n`doctor` reports which sibling audit DBs are present and readable, and whether the\nconfig and (optional) signing-key store are in place.\n\nFile v0.11.2:skill-card.md\n\n## Description:\n\nCompliance AIops helps agents turn local AIops audit trails into framework-mapped compliance evidence, gap analyses, approval and exception reports, and tamper-evident evidence bundles.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[zw008](https://clawhub.ai/user/zw008)\n\n### License/Terms of Use:\n\nMIT\n\n## Use Case:\n\nDevelopers, operators, and compliance teams use this skill to gather evidence from existing governed AIops audit logs for HIPAA, PCI-DSS, SOC 2, GDPR, ISO 27001, and DJCP L3 review workflows. It is intended for evidence collection, control coverage review, gap analysis, approval and exception reporting, and tamper-evident bundle generation, not for infrastructure operation or certification decisions.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill asks users to install mutable external package code.\n\nMitigation: Install only from a trusted publisher and pin or verify the package release before use.\n\nRisk: Unattended signed evidence generation can use local secrets without a built-in approval gate.\n\nMitigation: Run the skill under a least-privileged account, restrict access to intended audit databases, and use secure handling for COMPLIANCE_AIOPS_MASTER_PASSWORD.\n\nRisk: Generated bundles may be mistaken for compliance certification.\n\nMitigation: Treat outputs as evidence artifacts only and have qualified reviewers assess compliance scope and conclusions.\n\n## Reference(s):\n\n- [Project homepage](https://github.com/AIops-tools/Compliance-AIops)\n- [Capabilities reference](references/capabilities.md)\n- [Agent guardrails](references/agent-guardrails.md)\n- [CLI reference](references/cli-reference.md)\n- [Setup and security guide](references/setup-guide.md)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, JSON, CSV, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown guidance with inline shell commands; generated evidence artifacts can be JSON, Markdown, CSV, or OSCAL JSON.]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Outputs are based on local read-only audit databases; evidence bundles are written under ~/.compliance-aiops/bundles/ and can include hash-chain seals and optional signatures.]\n\n## Skill Version(s):\n\n0.11.2 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.11.1: 7 files, 17609 bytes\n\nFiles: references/agent-guardrails.md (7993b), references/capabilities.md (4440b), references/cli-reference.md (3342b), references/setup-guide.md (3370b), skill-card.md (2966b), SKILL.md (14893b), _meta.json (136b)\n\nFile v0.11.1:SKILL.md\n\n---\nname: compliance-aiops\nslug: compliance-aiops\ndisplayName: \"Compliance AIops\"\nsummary: \"Compliance evidence from AIops audit trails: HIPAA/PCI/SOC2/GDPR, OSCAL export, 19 tools.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/Compliance-AIops\ntags: [aiops, mcp, governance, compliance]\ndescription: >\n  Use this skill whenever the user needs compliance evidence from the audit trails their governed AIops agents already write — mapping AI-agent infra-ops activity to HIPAA §164.312, PCI-DSS v4.0, SOC 2 TSC, or GDPR controls, producing a change-approval report, a gap analysis, an exceptions/anomaly report, or a hash-chain-sealed, tamper-evident evidence bundle.\n  Always use this skill for \"compliance evidence\", \"HIPAA / PCI-DSS / SOC 2 / GDPR evidence\", \"audit trail report\", \"coverage for control X\", \"which controls are we short on / gap analysis\", \"who approved this change / change-management evidence\", \"denied or errored ops / anomaly evidence\", \"seal / sign an evidence bundle\", \"prove this bundle wasn't altered\", or \"detect deleted audit rows\".\n  Do NOT use to scan or operate infrastructure and do NOT treat it as a GRC platform — it reads the local audit databases the OTHER AIops-tools write and converts them to evidence; for platform operations use those other AIops-tools.\n  Evidence, not certification. Reads sibling audit trails read-only; no external API, no network, no platform credentials. Fully offline and deterministic.\ninstaller:\n  kind: uv\n  package: compliance-aiops\nargument-hint: \"[framework (hipaa|pci_dss|soc2|gdpr|iso27001|djcp_l3) or describe your evidence task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"compliance-aiops\",\"uvx\"]},\"optional\":{\"env\":[\"COMPLIANCE_AIOPS_CONFIG\",\"COMPLIANCE_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/Compliance-AIops\",\"emoji\":\"📋\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone compliance-evidence tooling. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.\n  Data source: the LOCAL audit databases the other governed AIops tools already write, discovered by glob at ~/.*-aiops/audit.db (one shared audit_log schema). These are read READ-ONLY. There is NO external API, NO network, and NO platform credentials.\n  The only optional secret is a bundle-signing key, stored ENCRYPTED in ~/.compliance-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk, unlocked by a master password from COMPLIANCE_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). If you never sign bundles you need no secret at all.\n  Outputs: evidence bundles written to ~/.compliance-aiops/bundles/ (the only files written). All tool calls are themselves audited to a local SQLite DB under ~/.compliance-aiops/ (relocatable via COMPLIANCE_AIOPS_HOME). Write tools (generate_evidence_bundle, export_bundle: low risk; sign_bundle: medium) pass through the @governed_tool decorator but perform NO external mutation.\n  Integrity: bundles are hash-chain-sealed (SHA-256 over ordered records; reproducible chainHead) with an optional HMAC signature. Tamper-EVIDENT, not tamper-PROOF — the source audit.db remains the system of record.\n  Webhooks: none — no outbound network calls at all.\n  Transitive dependencies: the MCP SDK and cryptography (Fernet). No post-install scripts or background services.\n  Evidence, not certification. Fully offline and deterministic; the integrity claims are covered by deterministic offline tests (see docs/VERIFICATION.md). OSCAL export is a v0.2 roadmap item (v0.1 emits JSON/Markdown/CSV).\n---\n\n# Compliance AIops\n\n> **Disclaimer**: Community-maintained open-source project, **not affiliated with, endorsed by, or sponsored by any framework body or GRC vendor.** HIPAA, PCI-DSS, SOC 2, GDPR and OSCAL are referenced descriptively; trademarks belong to their owners. Source at [github.com/AIops-tools/Compliance-AIops](https://github.com/AIops-tools/Compliance-AIops) under the MIT license.\n\nGoverned **compliance-evidence** tooling — **19 MCP tools**. It **reads the audit\ntrails your governed AIops agents already write** (`~/.<tool>-aiops/audit.db`, one\nshared `audit_log` schema, discovered via `~/.*-aiops/audit.db`) **read-only**,\nand turns that activity into **framework-mapped, hash-chain-sealed compliance\nevidence**. It does **not** scan infrastructure and does **not** replace a GRC\nplatform.\n\n> **Standalone**: the governance harness is bundled (`compliance_aiops.governance`).\n> **Not a platform wrapper** — no external API, no network, no platform\n> credentials. **Evidence, not certification**; fully offline and deterministic.\n\n## What This Skill Does\n\n| Group | Tools | Count | Read/Write |\n|-------|-------|:-----:|:----------:|\n| **Audit reads** | `list_audit_sources`, `query_audit_events`, `activity_timeline` | 3 | read |\n| **Framework mapping** | `list_frameworks`, `coverage_summary`, `control_evidence`, `gap_analysis` | 4 | read |\n| **Assurance reports** | `approval_report`, `exceptions_report` | 2 | read |\n| **Integrity** | `verify_source_chain`, `verify_bundle`, `list_bundles`, `bundle_schedule_hint`, `oscal_assessment_results` | 5 | read |\n| **Artifacts** | `generate_evidence_bundle` (low), `export_bundle` (low), `sign_bundle` (medium) | 3 | write (no external mutation) |\n| **Undo** | `undo_list`, `undo_apply` | 2 | undo |\n\n## Frameworks & sample controls\n\n| Framework | Sample controls (strength) |\n|-----------|----------------------------|\n| **HIPAA** §164.312 | 164.312(b) Audit controls (strong), 164.312(a)(1) Access control (strong), 164.312(c)(1) Integrity (strong) |\n| **PCI-DSS v4.0** | 10.2 Audit log content (strong), 10.3 Protect audit logs (strong), 7-8 Least privilege / authn (partial) |\n| **SOC 2 TSC** | CC6.1 Logical access (strong), CC7.2 Monitoring (strong), CC8.1 Change management (strong) |\n| **GDPR** | Art.30 Records of processing (partial), Art.32 Security of processing (strong) |\n| **ISO/IEC 27001:2022** (Annex A) | A.5.15 Access control (strong), A.5.16 Identity mgmt (strong), A.5.18 Access rights (partial), A.8.2 Privileged access (partial), A.8.15 Logging (strong), A.8.16 Monitoring (strong), A.8.32 Change management (strong) |\n| **等保2.0 (DJCP L3)** GB/T 22239-2019 三级 | 8.1.5.4 安全审计 (strong), 8.1.4.2 访问控制 (partial), 8.1.5 安全管理中心/集中审计 (strong) |\n\nAudit trails prove *operating effectiveness* strongly but *control design /\nconfiguration* only partially — each control is labelled `strong` or `partial`,\nand `gap_analysis` surfaces the caveat rather than overclaiming.\n\n## Quick Install\n\n```bash\nuv tool install compliance-aiops\ncompliance-aiops init       # discover sibling ~/.*-aiops/audit.db, set org name, optional signing key\ncompliance-aiops doctor     # which sibling audit DBs are present/readable\n```\n\nOr as an OpenClaw plugin, which installs this skill and its MCP server together:\n\n```bash\nopenclaw plugins install clawhub:@aiops-tools/compliance-aiops\nopenclaw skills info compliance-aiops          # expect: Visible to model: yes\n```\n\nNeeds `uvx` on `PATH`: the MCP server is fetched with uv, pinned to this release.\n\n## When to Use This Skill\n\n- Map AI-agent infra-ops activity to a framework's controls (`coverage_summary`)\n- Pull the evidence rows + population for one control (`control_evidence`)\n- Find controls with no or weak evidence, with the honest caveat (`gap_analysis`)\n- Produce a change-approval artifact — who approved which high-risk write and why\n  (`approval_report`)\n- Produce enforcement / anomaly evidence — denied / errored / budget-tripped ops\n  (`exceptions_report`)\n- Seal a tamper-evident evidence bundle (`generate_evidence_bundle`,\n  `sign_bundle`) and later prove it wasn't altered (`verify_bundle`)\n- Detect deleted / missing audit rows in a source trail (`verify_source_chain`)\n\n**Do NOT use** to scan or operate infrastructure, or as a GRC platform. It reads\nthe audit DBs the *other* AIops-tools write; for platform operations use those\nother AIops-tools.\n\n## Related Skills — Skill Routing\n\n| If the user wants… | Use |\n|--------------------|-----|\n| Compliance evidence from existing AIops audit trails | **compliance-aiops** (this skill) |\n| To actually operate a platform (VMs, storage, clusters, network, …) | the relevant platform **AIops-tools** skill |\n| OT / industrial edge (Modbus, OPC-UA, PLC) | the **industrial-aiops** line |\n| A full GRC platform / policy management | out of scope — this is evidence, not GRC |\n\n## Common Workflows\n\n### 1. \"The SOC 2 auditor wants Q3 change-approval evidence by Friday\"\n\n1. `compliance-aiops doctor` → confirm the source audit trails are discoverable\n   and readable before you promise a delivery date\n2. `compliance-aiops report sources` (MCP: `list_audit_sources`) → which sibling\n   audit trails were found, and the event count and date range in each. If a\n   source you expected is missing, the bundle would be silently incomplete —\n   fix discovery first\n3. `compliance-aiops report coverage soc2` → confirm CC8.1 is actually covered by\n   the evidence you have, before generating anything\n4. `compliance-aiops report approvals` → the high-risk write operations with\n   their named approver and rationale — this is the population CC8.1 is asking\n   about\n5. `compliance-aiops bundle generate soc2 --since 2026-07-01 --until 2026-10-01 --sign`\n   → a hash-chain-sealed bundle under `~/.compliance-aiops/bundles/`\n6. `compliance-aiops bundle export <path> --format markdown` → the\n   auditor-facing report (also `json` / `csv`)\n7. **Failure branch**: if `report coverage` shows CC8.1 thin, **do not generate\n   anyway and hope** — run workflow 2 first and hand the auditor the honest gap\n   statement. A bundle asserts what the audit trail contains; it cannot\n   manufacture evidence that was never recorded.\n\n### 2. \"Which controls are we actually short on?\" (gap analysis)\n\n1. `compliance-aiops report sources` → establish the evidence base and its date\n   coverage; a gap caused by a *missing source* is a different problem from a\n   gap caused by *missing activity*\n2. `compliance-aiops report gaps hipaa` (also `pci_dss`, `soc2`, `gdpr`) →\n   controls with no or weak evidence, each with an honest caveat and a\n   remediation suggestion\n3. `compliance-aiops report exceptions` → the operations that ran **without** an\n   approver or rationale — usually the fastest-to-fix category of gap\n4. Drill into one control's population with `control_evidence` (MCP) to see the\n   **reproducible query** behind the coverage number, so the figure can be\n   defended rather than merely quoted\n5. `compliance-aiops report coverage <framework>` again after remediation to\n   confirm the gap actually closed\n6. **Failure branch**: if `list_frameworks` does not carry the framework or\n   control the auditor named, say so — this tool maps to HIPAA / PCI-DSS /\n   SOC 2 / GDPR and does not silently substitute a near-miss control.\n\n### 3. Prove a delivered bundle was not altered\n\n1. `compliance-aiops bundle list` → locate the bundle and its recorded\n   `chainHead`\n2. `compliance-aiops bundle verify <path>` → re-derives the hash chain, compares\n   it to the seal's `chainHead`, and checks the optional signature\n3. Because the chain is computed over evidence records only, the **same**\n   (framework, period, sources) reproduces the **same** `chainHead` — regenerate\n   and compare to prove reproducibility\n4. Record the `chainHead` **out-of-band** (ticket, email to the auditor, WORM\n   store) at delivery time; that out-of-band copy is what makes later\n   verification meaningful\n5. `verify_source_chain` (MCP) on each source → returns the source chain head and\n   flags **row-id gaps**, a sign that rows were deleted from that `audit.db`\n6. **Failure branch**: a `chainHead` mismatch or a row-id gap means the evidence\n   is **not** trustworthy — escalate, and treat the source `audit.db` as the\n   system of record. Do not re-seal a fresh bundle to make the mismatch go away;\n   the tool is **tamper-evident, not tamper-proof**, and its whole value is that\n   it reports this rather than papering over it.\n\n### 4. 定期封存 — schedule periodic sealed bundles (no daemon)\n\nThis tool ships **no scheduler**; it emits a cron line for you to install.\n\n1. `compliance-aiops report sources` → confirm the sources you want sealed are\n   discoverable from the account cron will run as (a common failure: cron sees a\n   different `$HOME`)\n2. `compliance-aiops bundle schedule soc2 --cron \"0 2 * * 1\" --period 7d --sign`\n   (MCP: `bundle_schedule_hint`) → returns a `cronLine` plus the exact\n   non-interactive command. **It writes nothing.**\n3. Paste the `cronLine` into `crontab -e`, e.g.\n   `0 2 * * 1 compliance-aiops bundle generate soc2 --period 7d --sign`\n4. Export `COMPLIANCE_AIOPS_MASTER_PASSWORD` in the cron environment so the\n   signing key unlocks non-interactively — never inline the real password in the\n   crontab\n5. After the first scheduled run, `compliance-aiops bundle list` and\n   `bundle verify` the newest bundle to confirm the unattended path really works\n6. **Failure branch**: if the cron run produces no bundle, the usual causes are\n   an unset master password (signing cannot unlock) or `COMPLIANCE_AIOPS_HOME`\n   not being set in cron's environment, so sources resolve elsewhere. Verify by\n   running the emitted command by hand with a clean environment before trusting\n   the schedule.\n\n## Governance & Safety\n\nThe skill reads audit trails and writes evidence bundles and records what it\ndoes; it does **not** decide whether producing or signing a bundle is permitted.\nThat is your agent's judgement, or the filesystem permissions of the account it\nruns as. There is no read-only switch, policy file, or approval gate.\n\n- **Audit is the guarantee, and it is not bypassable.** Every operation — MCP and CLI alike — is logged to `~/.compliance-aiops/audit.db` (relocatable via `COMPLIANCE_AIOPS_HOME`): params, result, status, duration, and the risk tier. The CLI writes the same row the MCP path does.\n- The source audit trails are opened **read-only**; the tool never mutates them. The only files written are bundles under `~/.compliance-aiops/bundles/`.\n- `COMPLIANCE_AUDIT_APPROVED_BY` / `COMPLIANCE_AUDIT_RATIONALE` are optional annotations recorded on the audit row (who/why); they are never required and never block.\n- **Tamper-EVIDENT, not tamper-PROOF** — the source `audit.db` remains the system\n  of record.\n\n## References\n\n- `references/capabilities.md` — full tool → inputs → returns reference\n- `references/cli-reference.md` — CLI command reference\n- `references/setup-guide.md` — source discovery, org name, optional signing key, integrity notes\n\nFile v0.11.1:_meta.json\n\n{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"compliance-aiops\",\n  \"version\": \"0.11.1\",\n  \"publishedAt\": 1789207150143\n}\n\nFile v0.11.1:references/agent-guardrails.md\n\n# Agent guardrails — running compliance-aiops with a smaller / local model\n\ncompliance-aiops is a **meta-tool**: it reads the audit databases the other\nAIops tools write, and turns them into framework-mapped evidence. That makes the\nfailure mode here different from an infrastructure tool. A wrong answer does not\nbreak a cluster — it produces a **confident, false compliance claim**, which is\nworse, because it looks like a finding.\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\n## Authorization is not this tool's job — decide it where it belongs\n\nWhether a bundle should be produced or signed is your decision, or the account's.\nThe tool does not gate it — there is no read-only switch and no approval prompt\nto configure. The two right places to control it:\n\n- **The account it runs as.** The tool only ever writes under\n  `~/.compliance-aiops/`, and opens every source `audit.db` strictly read-only —\n  so ordinary filesystem permissions bound what it can do. A write then fails at\n  the OS, which is the only place the permission actually lives.\n- **Your agent's system prompt.** If you want a query-only session, tell the\n  model not to call the bundle-writing tools (they are clearly tagged `[WRITE]`).\n\nWhat the tool *does* guarantee is that you can always see what happened:\n\n## What the tool enforces — do not waste prompt budget on these\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Never modify the audit trail\" | The tool has no capability to write to any source `audit.db` — it opens them read-only. Nothing in the tool surface can alter the evidence it reports on. |\n| \"Don't get stuck retrying\" | The runaway guard trips a circuit breaker if the same call is hammered in a tight loop — a stuck agent is stopped rather than left to burn calls and time. |\n| \"Don't invent an approver or a reason\" | A field the audit row did not record comes back as `null`, never as `\"\"`. \"No approver was recorded\" and \"the approver field was blank\" stay distinguishable — which is exactly the distinction a change-approval finding turns on. |\n| \"Tell me if you only saw part of the trail\" | Every report carries `scanLimit` and `scanTruncated`, and every capped list carries `returned` / `limit` / `truncated`. Truncation is measured — one row past the cap is fetched — never inferred from a count landing on a round number. |\n| \"Check the evidence hasn't been tampered with\" | `verify_source_chain` hash-chains a source's current events and reports row-id gaps; `verify_bundle` re-derives a sealed bundle's chain and reports the first broken link plus signature validity. You do not need to ask the model to reason about integrity — ask it to run the check. |\n| \"Be honest about what an audit log can prove\" | Every control carries a `strength` and a `caveat`, and gap findings carry the design-vs-operating note. Coverage is only claimed where the trail actually contains the evidence. |\n| \"Log everything you do, over both MCP and the CLI\" | Every call is audited to `~/.compliance-aiops/audit.db` regardless of what the model says it did — and the CLI writes the same row the MCP path does, so there is no unaudited entry point. |\n\n## What still needs a prompt\n\nThese are model-behaviour problems the harness cannot fix from the outside.\nCopy this into your agent's system prompt:\n\n```text\nYou operate compliance-aiops, which reads the audit trails other AIops tools\nproduce and maps them to framework controls (HIPAA, PCI-DSS, SOC2, GDPR).\n\nTOOL USE\n- Before answering any question about compliance posture, coverage, or a\n  specific control, you MUST call a tool. Never answer from memory, and never\n  from your training knowledge of what a framework requires.\n- Actually invoke the tool. Do not describe the call you would make, and do not\n  emit an example JSON response in place of calling it.\n- If a tool call fails, report the real error verbatim. An unreadable audit\n  source means unknown coverage, not zero findings and not full coverage.\n\nEVIDENCE INTEGRITY — the part that matters most here\n- NEVER state or imply that an organisation \"is compliant\", \"passes\", or \"is\n  certified\". This tool produces evidence about operations recorded in an audit\n  trail. Certification is a judgement made by a qualified assessor over a much\n  wider scope. Say what the evidence shows; never issue a verdict.\n- If a result has scanTruncated or truncated set to true, the population you saw\n  is a slice. Say so explicitly and do not compute or quote a coverage\n  percentage, a total, or a \"no violations found\" statement from it.\n- Quote counts and control ids exactly as returned. Never round, extrapolate,\n  or fill a gap in the trail with an assumption about what probably happened.\n- A null approver means no approver was recorded — report that as the finding\n  it is. Do not soften it, and do not guess who approved.\n- Report every control's caveat and strength alongside its coverage. A control\n  marked PARTIAL is not covered; it is partly evidenced by operational logs and\n  needs design/configuration evidence from a GRC system.\n- An absence of evidence for a control means the trail contains nothing matching\n  it. That is not proof the control failed, and not proof it passed. Say which\n  one the data supports: neither.\n\nSCOPE\n- Separate observation from interpretation. State what the tools returned, then\n  any interpretation, clearly marked as such.\n- A hash chain is tamper-EVIDENT, not tamper-PROOF. An \"intact\" verdict means\n  the records match a previously recorded head — it does not prove nothing was\n  ever deleted before that head was taken. Row-id gaps are the signal for that,\n  and they are reported separately.\n- Do not confuse the source tools' identifiers with each other: a `source` is an\n  AIops tool's audit database, a `skill` is the tool that logged the row, and a\n  `tool` is the individual operation. They are three different columns.\n```\n\n## Recommended setup for a local model\n\nKeep the agent query-only until you trust the setup — the tool already opens\nevery source trail read-only, and the only thing it can write is a bundle under\n`~/.compliance-aiops/`:\n\n```bash\ncompliance-aiops doctor\n```\n\nOptionally annotate the audit trail with who is operating and why — recorded on\nevery row, never required:\n\n```bash\nexport COMPLIANCE_AUDIT_APPROVED_BY=\"your.name@example.com\"\nexport COMPLIANCE_AUDIT_RATIONALE=\"Q3 SOC2 evidence collection\"\n```\n\n## If your model still struggles\n\nSome behaviours are model-capacity limits rather than prompt problems:\n\n- **The model editorialises into a verdict.** This is the characteristic failure\n  of smaller models on this tool. Ask for the numbers first (\"what does\n  coverage_summary return for soc2?\") and only then for a summary, rather than\n  asking \"are we SOC2 compliant?\" — the second phrasing invites a verdict the\n  data cannot support.\n- **Multi-tool workflows time out or drift.** Lead with `posture_overview` — it\n  folds source availability and per-framework coverage into one call.\n- **The model ignores later tool results in a long context.** Ask about one\n  control at a time with `control_evidence` rather than pulling a whole\n  framework's population.\n- **The model describes calls instead of making them.** This is usually a\n  runtime/tool-calling-format mismatch, not a prompt problem — check that your\n  client advertises the tools in the format your model was trained on.\n\nFeedback on running this with a specific local model is genuinely useful —\nopen an issue at\n[github.com/AIops-tools/Compliance-AIops](https://github.com/AIops-tools/Compliance-AIops/issues)\nwith the model, runtime, and what went wrong.\n\nFile v0.11.1:references/capabilities.md\n\n# compliance-aiops capabilities\n\n> Evidence, not certification. 19 MCP tools (14 read, 3 write, 2 undo). Data\n> source: the local `audit_log` trails governed AIops tools write, discovered via\n> `~/.*-aiops/audit.db` and read **read-only**. No external API, no network, no\n> platform credentials. `since` / `until` accept ISO-8601 timestamps.\n\n## Read / analysis tools (12)\n\n### Audit reads\n\n| Tool | Inputs | Returns |\n|------|--------|---------|\n| `list_audit_sources` | — | discovered sources: `name`, `path`, `tool`, `readable`, `rowCount` |\n| `query_audit_events` | `source?`, `skill?`, `tool?`, `status?`, `risk_level?`, `approved?`, `selector?`, `since?`, `until?`, `limit=100` | matched events (cross-tool), normalised audit rows |\n| `activity_timeline` | `since?`, `until?`, `bucket=\"day\"` (`hour`\\|`day`) | event counts per time bucket |\n\n### Framework mapping\n\n| Tool | Inputs | Returns |\n|------|--------|---------|\n| `list_frameworks` | — | frameworks + control counts (`hipaa`, `pci_dss`, `soc2`, `gdpr`, `iso27001`, `djcp_l3`) |\n| `coverage_summary` | `framework`, `since?`, `until?` | per-control `covered`/`weak`/`uncovered`, evidence counts, strength labels |\n| `control_evidence` | `framework`, `control_id`, `since?`, `until?`, `sample_size=20` | evidence rows + population size + the reproducible query for ONE control |\n| `gap_analysis` | `framework`, `since?`, `until?` | controls with no/weak evidence + honest `strong`/`partial` caveat + remediation hint |\n\n### Assurance reports\n\n| Tool | Inputs | Returns |\n|------|--------|---------|\n| `approval_report` | `since?`, `until?`, `high_only=True` | high-risk write ops + who approved + rationale (CC8.1 / PCI 7-8 / HIPAA §312(a) artifact) |\n| `exceptions_report` | `since?`, `until?` | denied / error / budget_exceeded ops — enforcement + anomaly evidence |\n\n### Integrity\n\n| Tool | Inputs | Returns |\n|------|--------|---------|\n| `verify_source_chain` | `source`, `since?`, `until?` | chain head + row-id gap detection (flags deletions) for one source |\n| `verify_bundle` | `bundle_path` | verifies chain + seal head + optional signature; `ok` + any mismatch detail |\n| `list_bundles` | — | bundles under `~/.compliance-aiops/bundles/` |\n| `oscal_assessment_results` | `bundle_path` | the bundle as a NIST **OSCAL 1.2.3** Assessment Results document, returned inline with a `summary` (satisfied / not-satisfied / **satisfiedOnPartialEvidence** / scanTruncated) and an explicit `limitations` list. Deterministic: v5 UUIDs derived from the chain head, so re-export is byte-identical |\n| `bundle_schedule_hint` | `framework`, `cron=\"0 2 * * 1\"`, `period=\"7d\"`, `sign=False` | ready-to-paste 5-field cron line + non-interactive command for periodic sealing; **writes nothing, no daemon** |\n\n## Write / artifact tools (3 — no external mutation)\n\n| Tool | Risk | Inputs | Returns / effect |\n|------|:---:|--------|------------------|\n| `generate_evidence_bundle` | **medium** | `framework`, `period_start?`, `period_end?`, `out_path?`, `sign=False`, `period?` (relative window e.g. `7d`) | one call: coverage + approval trail + exceptions + sealed records → a bundle `.json` under `~/.compliance-aiops/bundles/`; returns path + `chainHead` |\n| `export_bundle` | **medium** | `bundle_path`, `fmt=\"markdown\"` (`markdown`\\|`csv`\\|`json`\\|`oscal`), `out_path?` | renders a bundle to the chosen format; `oscal` writes `<bundle>.oscal.json` |\n| `sign_bundle` | **medium** | `bundle_path` | adds an HMAC signature over the seal using the stored signing key |\n\n## Integrity model\n\n- Each record hash = `SHA-256(prev_hash ‖ canonical_json(record))`; genesis\n  `prev` = 64 zeros. The `chainHead` is the last record hash.\n- Seal = `{framework, period, sources (+ per-db SHA-256), recordCount, chainHead,\n  generatedAt, generator, optional signature}`.\n- The chain is over **evidence records only**, so `chainHead` is **reproducible**\n  for the same (framework, period, sources).\n- **Tamper-EVIDENT, not tamper-PROOF** — the source `audit.db` remains the system\n  of record; record `chainHead` out-of-band as an anchor.\n\n## Out of scope (by design)\n\n- Scanning or operating infrastructure (use the other AIops-tools)\n- Acting as a GRC platform / policy-management system\n- OSCAL export (documented v0.2 roadmap; v0.1 emits JSON / Markdown / CSV)\n\nWant another framework, control mapping, or export format? Open an issue or PR —\nfeedback and contributions welcome.\n\nFile v0.11.1:references/cli-reference.md\n\n# compliance-aiops CLI reference\n\n> Evidence, not certification. Reads the local audit trails governed\n> AIops tools write (`~/.*-aiops/audit.db`) read-only. No external API, no\n> network, no platform credentials. The CLI is a convenience subset; the full\n> 19-tool surface is available over MCP.\n\n## Setup & diagnostics\n\n```bash\ncompliance-aiops init                      # discover sibling audit DBs, set org name, optional signing key\ncompliance-aiops doctor                    # which sibling audit DBs are present/readable\ncompliance-aiops overview                  # audit sources + per-framework covered/total counts\ncompliance-aiops mcp                        # start the MCP server (stdio transport)\n```\n\n## Reports (read-only)\n\n```bash\ncompliance-aiops report sources                    # discovered audit sources + row counts\ncompliance-aiops report coverage <framework>       # per-control coverage (hipaa|pci_dss|soc2|gdpr)\ncompliance-aiops report gaps <framework>           # controls with no/weak evidence + honest caveat\ncompliance-aiops report approvals                  # high-risk write ops + approver + rationale\ncompliance-aiops report exceptions                 # denied / error / budget_exceeded ops\n```\n\n## Bundles (evidence artifacts)\n\n```bash\ncompliance-aiops bundle generate <framework> [--since <iso>] [--until <iso>] [--period <7d|24h|2w|last-7-days>] [--sign]\n                                                   # hash-chain-sealed bundle → ~/.compliance-aiops/bundles/\ncompliance-aiops bundle verify <path>              # re-verify chain + seal head (+ signature)\ncompliance-aiops bundle list                       # list generated bundles\ncompliance-aiops bundle export <path> --format <markdown|csv|json>\ncompliance-aiops bundle schedule <framework> [--cron \"0 2 * * 1\"] [--period 7d] [--sign]\n                                                   # print a ready-to-paste cron line; WRITES NOTHING, no daemon\n```\n\n## Secrets (optional bundle-signing key, encrypted ~/.compliance-aiops/secrets.enc)\n\nOnly needed if you sign bundles; there are no platform credentials.\n\n```bash\ncompliance-aiops secret set <name> [--value <key>]   # store signing key (hidden prompt if no --value)\ncompliance-aiops secret list                          # names only — values never shown\ncompliance-aiops secret rm <name>\ncompliance-aiops secret migrate                       # import a legacy plaintext key\ncompliance-aiops secret rotate-password               # re-encrypt under a new master password\n```\n\n## Notes\n\n- `<framework>` is one of `hipaa`, `pci_dss`, `soc2`, `gdpr`, `iso27001`, `djcp_l3`.\n- `--since` / `--until` bound the evidence period (ISO-8601). The hash chain is\n  over evidence records only, so the same `(framework, period, sources)`\n  reproduces the same `chainHead`.\n- `--period` is a convenience relative window (`7d` / `24h` / `2w` /\n  `last-7-days`) resolved to a since/until pair ending \"now\"; used only when\n  `--since` / `--until` are not given. `bundle schedule` prints a cron line for\n  running that periodically — it starts no daemon and writes nothing.\n- `--sign` requires a stored signing key; unlock non-interactively by exporting\n  `COMPLIANCE_AIOPS_MASTER_PASSWORD`.\n- Bundles are the only files written (under `~/.compliance-aiops/bundles/`); the\n  source audit DBs are opened read-only.\n\nFile v0.11.1:references/setup-guide.md\n\n# compliance-aiops setup & security guide\n\n> Evidence, not certification. Reads the local audit trails governed\n> AIops tools already write, read-only. **No external API, no network, no\n> platform credentials.**\n\n## 1. Install\n\n```bash\nuv tool install compliance-aiops\n```\n\n## 2. Onboard\n\n```bash\ncompliance-aiops init\n```\n\nThe `init` wizard:\n\n- **Auto-discovers sibling audit DBs** by globbing `~/.*-aiops/audit.db` (e.g.\n  `~/.nutanix-aiops/audit.db`, `~/.<tool>-aiops/audit.db`). These are the local\n  `audit_log` trails your governed AIops tools already write. Each discovered\n  source can be included and tagged.\n- **Records an organization name** and the selected sources into\n  `~/.compliance-aiops/config.yaml`.\n- **Optionally stores a bundle-signing key** — encrypted, Fernet (AES-128-CBC +\n  HMAC) with a scrypt-derived key. This is the *only* secret the tool uses, and\n  it is optional: if you never sign bundles you need no secret at all.\n\nNo platform credentials are collected, because the tool never connects to any\nplatform — its inputs are on-disk audit databases opened **read-only**.\n\nExample `~/.compliance-aiops/config.yaml`:\n\n```yaml\norganization: Acme Health, Inc.\nsources:\n  - name: nutanix\n    path: ~/.nutanix-aiops/audit.db\n    tag: infra\n  - name: k8s\n    path: ~/.k8s-aiops/audit.db\n    tag: platform\n```\n\n## 3. Non-interactive use (MCP server / CI / cron)\n\nOnly needed if you **sign** bundles. Export the master password so the encrypted\nsigning-key store can be unlocked without a prompt:\n\n```bash\nexport COMPLIANCE_AIOPS_MASTER_PASSWORD='your-master-password'\n```\n\n## Signing-key security\n\n- The signing key is **never** written to disk in plaintext. It lives only in\n  `~/.compliance-aiops/secrets.enc`, encrypted with Fernet, the key derived from\n  your master password via scrypt. Only a per-store random salt and the\n  ciphertext are on disk (chmod 600); the master password itself is never stored.\n- A legacy plaintext key is honoured as a fallback with a deprecation warning —\n  migrate with `compliance-aiops secret migrate`.\n- The key is held only in memory during a session and is never logged or echoed.\n\n## State & outputs\n\nState lives under `~/.compliance-aiops/` (relocate with `COMPLIANCE_AIOPS_HOME`):\n\n- `config.yaml` — organization name + selected audit sources\n- `secrets.enc` — the optional encrypted signing key\n- `bundles/` — generated evidence bundles (**the only files the tool writes**)\n- `audit.db` — this tool's own governance audit log (every tool call recorded)\n\nThe source `~/.<tool>-aiops/audit.db` trails are opened **read-only** and never\nmodified.\n\n## Integrity notes\n\n- **Reproducible `chainHead`.** The hash chain is over evidence records only, so\n  the same `(framework, period, sources)` reproduces the same `chainHead`. Record\n  it out-of-band to create an independent anchor.\n- **Tamper-EVIDENT, not tamper-PROOF.** The chain and optional signature let an\n  auditor *detect* alteration; the source `audit.db` remains the system of record.\n- `verify_bundle` re-derives the chain and checks the seal head + signature;\n  `verify_source_chain` flags **row-id gaps** in a source (a sign of deleted rows).\n\n## Verify\n\n```bash\ncompliance-aiops doctor\n```\n\n`doctor` reports which sibling audit DBs are present and readable, and whether the\nconfig and (optional) signing-key store are in place.\n\nFile v0.11.1:skill-card.md\n\n## Description:\n\nCompliance AIops turns local AIops audit trails into framework-mapped evidence reports and tamper-evident evidence bundles for HIPAA, PCI-DSS, SOC 2, GDPR, ISO 27001, and DJCP L3.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[zw008](https://clawhub.ai/user/zw008)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, platform teams, and compliance operators use this skill to query existing AIops audit trails, map recorded activity to compliance controls, produce approval, exception, coverage, and gap reports, and generate sealed evidence bundles. It supports evidence collection and review, not certification or infrastructure operation.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill handles sensitive local audit evidence and may expose operational history through reports or bundles.\n\nMitigation: Run it under a dedicated least-privilege account with access only to the audit databases intended for review.\n\nRisk: Unattended or signed bundle generation can depend on local secret delivery and may create evidence artifacts without an interactive review step.\n\nMitigation: Use protected secret delivery for COMPLIANCE_AIOPS_MASTER_PASSWORD, avoid unattended signing unless required, and review generated bundles before sharing.\n\nRisk: Generated bundles are evidence derived from local audit logs and can be mistaken for certification or a complete compliance verdict.\n\nMitigation: Treat outputs as supporting evidence only, preserve the source audit databases as the system of record, and have qualified reviewers assess final compliance.\n\nRisk: Package provenance is unavailable for this release in server-resolved evidence.\n\nMitigation: Review package provenance and pin or verify the exact release before installation.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/zw008/skills/compliance-aiops)\n- [Project homepage](https://github.com/AIops-tools/Compliance-AIops)\n- [Capabilities reference](references/capabilities.md)\n- [CLI reference](references/cli-reference.md)\n- [Setup and security guide](references/setup-guide.md)\n- [Agent guardrails](references/agent-guardrails.md)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands, Markdown, JSON, Code, Configuration]\n\n**Output Format:** [Markdown guidance with CLI commands and generated evidence outputs in JSON, Markdown, CSV, or OSCAL JSON]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Produces reports and local evidence bundles from existing audit databases; signed bundles require an optional configured signing key.]\n\n## Skill Version(s):\n\n0.11.1 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.11.0: 7 files, 17400 bytes\n\nFiles: references/agent-guardrails.md (7993b), references/capabilities.md (4440b), references/cli-reference.md (3342b), references/setup-guide.md (3370b), skill-card.md (2818b), SKILL.md (14573b), _meta.json (136b)\n\nFile v0.11.0:SKILL.md\n\n---\nname: compliance-aiops\nslug: compliance-aiops\ndisplayName: \"Compliance AIops\"\nsummary: \"Compliance evidence from AIops audit trails: HIPAA/PCI/SOC2/GDPR, OSCAL export, 19 tools.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/Compliance-AIops\ntags: [aiops, mcp, governance, compliance]\ndescription: >\n  Use this skill whenever the user needs compliance evidence from the audit trails their governed AIops agents already write — mapping AI-agent infra-ops activity to HIPAA §164.312, PCI-DSS v4.0, SOC 2 TSC, or GDPR controls, producing a change-approval report, a gap analysis, an exceptions/anomaly report, or a hash-chain-sealed, tamper-evident evidence bundle.\n  Always use this skill for \"compliance evidence\", \"HIPAA / PCI-DSS / SOC 2 / GDPR evidence\", \"audit trail report\", \"coverage for control X\", \"which controls are we short on / gap analysis\", \"who approved this change / change-management evidence\", \"denied or errored ops / anomaly evidence\", \"seal / sign an evidence bundle\", \"prove this bundle wasn't altered\", or \"detect deleted audit rows\".\n  Do NOT use to scan or operate infrastructure and do NOT treat it as a GRC platform — it reads the local audit databases the OTHER AIops-tools write and converts them to evidence; for platform operations use those other AIops-tools.\n  Evidence, not certification. Reads sibling audit trails read-only; no external API, no network, no platform credentials. Fully offline and deterministic.\ninstaller:\n  kind: uv\n  package: compliance-aiops\nargument-hint: \"[framework (hipaa|pci_dss|soc2|gdpr|iso27001|djcp_l3) or describe your evidence task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"compliance-aiops\",\"uvx\"]},\"optional\":{\"env\":[\"COMPLIANCE_AIOPS_CONFIG\",\"COMPLIANCE_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/Compliance-AIops\",\"emoji\":\"📋\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone compliance-evidence tooling. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.\n  Data source: the LOCAL audit databases the other governed AIops tools already write, discovered by glob at ~/.*-aiops/audit.db (one shared audit_log schema). These are read READ-ONLY. There is NO external API, NO network, and NO platform credentials.\n  The only optional secret is a bundle-signing key, stored ENCRYPTED in ~/.compliance-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk, unlocked by a master password from COMPLIANCE_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). If you never sign bundles you need no secret at all.\n  Outputs: evidence bundles written to ~/.compliance-aiops/bundles/ (the only files written). All tool calls are themselves audited to a local SQLite DB under ~/.compliance-aiops/ (relocatable via COMPLIANCE_AIOPS_HOME). Write tools (generate_evidence_bundle, export_bundle: low risk; sign_bundle: medium) pass through the @governed_tool decorator but perform NO external mutation.\n  Integrity: bundles are hash-chain-sealed (SHA-256 over ordered records; reproducible chainHead) with an optional HMAC signature. Tamper-EVIDENT, not tamper-PROOF — the source audit.db remains the system of record.\n  Webhooks: none — no outbound network calls at all.\n  Transitive dependencies: the MCP SDK and cryptography (Fernet). No post-install scripts or background services.\n  Evidence, not certification. Fully offline and deterministic; the integrity claims are covered by deterministic offline tests (see docs/VERIFICATION.md). OSCAL export is a v0.2 roadmap item (v0.1 emits JSON/Markdown/CSV).\n---\n\n# Compliance AIops\n\n> **Disclaimer**: Community-maintained open-source project, **not affiliated with, endorsed by, or sponsored by any framework body or GRC vendor.** HIPAA, PCI-DSS, SOC 2, GDPR and OSCAL are referenced descriptively; trademarks belong to their owners. Source at [github.com/AIops-tools/Compliance-AIops](https://github.com/AIops-tools/Compliance-AIops) under the MIT license.\n\nGoverned **compliance-evidence** tooling — **19 MCP tools**. It **reads the audit\ntrails your governed AIops agents already write** (`~/.<tool>-aiops/audit.db`, one\nshared `audit_log` schema, discovered via `~/.*-aiops/audit.db`) **read-only**,\nand turns that activity into **framework-mapped, hash-chain-sealed compliance\nevidence**. It does **not** scan infrastructure and does **not** replace a GRC\nplatform.\n\n> **Standalone**: the governance harness is bundled (`compliance_aiops.governance`).\n> **Not a platform wrapper** — no external API, no network, no platform\n> credentials. **Evidence, not certification**; fully offline and deterministic.\n\n## What This Skill Does\n\n| Group | Tools | Count | Read/Write |\n|-------|-------|:-----:|:----------:|\n| **Audit reads** | `list_audit_sources`, `query_audit_events`, `activity_timeline` | 3 | read |\n| **Framework mapping** | `list_frameworks`, `coverage_summary`, `control_evidence`, `gap_analysis` | 4 | read |\n| **Assurance reports** | `approval_report`, `exceptions_report` | 2 | read |\n| **Integrity** | `verify_source_chain`, `verify_bundle`, `list_bundles`, `bundle_schedule_hint`, `oscal_assessment_results` | 5 | read |\n| **Artifacts** | `generate_evidence_bundle` (low), `export_bundle` (low), `sign_bundle` (medium) | 3 | write (no external mutation) |\n| **Undo** | `undo_list`, `undo_apply` | 2 | undo |\n\n## Frameworks & sample controls\n\n| Framework | Sample controls (strength) |\n|-----------|----------------------------|\n| **HIPAA** §164.312 | 164.312(b) Audit controls (strong), 164.312(a)(1) Access control (strong), 164.312(c)(1) Integrity (strong) |\n| **PCI-DSS v4.0** | 10.2 Audit log content (strong), 10.3 Protect audit logs (strong), 7-8 Least privilege / authn (partial) |\n| **SOC 2 TSC** | CC6.1 Logical access (strong), CC7.2 Monitoring (strong), CC8.1 Change management (strong) |\n| **GDPR** | Art.30 Records of processing (partial), Art.32 Security of processing (strong) |\n| **ISO/IEC 27001:2022** (Annex A) | A.5.15 Access control (strong), A.5.16 Identity mgmt (strong), A.5.18 Access rights (partial), A.8.2 Privileged access (partial), A.8.15 Logging (strong), A.8.16 Monitoring (strong), A.8.32 Change management (strong) |\n| **等保2.0 (DJCP L3)** GB/T 22239-2019 三级 | 8.1.5.4 安全审计 (strong), 8.1.4.2 访问控制 (partial), 8.1.5 安全管理中心/集中审计 (strong) |\n\nAudit trails prove *operating effectiveness* strongly but *control design /\nconfiguration* only partially — each control is labelled `strong` or `partial`,\nand `gap_analysis` surfaces the caveat rather than overclaiming.\n\n## Quick Install\n\n```bash\nuv tool install compliance-aiops\ncompliance-aiops init       # discover sibling ~/.*-aiops/audit.db, set org name, optional signing key\ncompliance-aiops doctor     # which sibling audit DBs are present/readable\n```\n\n## When to Use This Skill\n\n- Map AI-agent infra-ops activity to a framework's controls (`coverage_summary`)\n- Pull the evidence rows + population for one control (`control_evidence`)\n- Find controls with no or weak evidence, with the honest caveat (`gap_analysis`)\n- Produce a change-approval artifact — who approved which high-risk write and why\n  (`approval_report`)\n- Produce enforcement / anomaly evidence — denied / errored / budget-tripped ops\n  (`exceptions_report`)\n- Seal a tamper-evident evidence bundle (`generate_evidence_bundle`,\n  `sign_bundle`) and later prove it wasn't altered (`verify_bundle`)\n- Detect deleted / missing audit rows in a source trail (`verify_source_chain`)\n\n**Do NOT use** to scan or operate infrastructure, or as a GRC platform. It reads\nthe audit DBs the *other* AIops-tools write; for platform operations use those\nother AIops-tools.\n\n## Related Skills — Skill Routing\n\n| If the user wants… | Use |\n|--------------------|-----|\n| Compliance evidence from existing AIops audit trails | **compliance-aiops** (this skill) |\n| To actually operate a platform (VMs, storage, clusters, network, …) | the relevant platform **AIops-tools** skill |\n| OT / industrial edge (Modbus, OPC-UA, PLC) | the **industrial-aiops** line |\n| A full GRC platform / policy management | out of scope — this is evidence, not GRC |\n\n## Common Workflows\n\n### 1. \"The SOC 2 auditor wants Q3 change-approval evidence by Friday\"\n\n1. `compliance-aiops doctor` → confirm the source audit trails are discoverable\n   and readable before you promise a delivery date\n2. `compliance-aiops report sources` (MCP: `list_audit_sources`) → which sibling\n   audit trails were found, and the event count and date range in each. If a\n   source you expected is missing, the bundle would be silently incomplete —\n   fix discovery first\n3. `compliance-aiops report coverage soc2` → confirm CC8.1 is actually covered by\n   the evidence you have, before generating anything\n4. `compliance-aiops report approvals` → the high-risk write operations with\n   their named approver and rationale — this is the population CC8.1 is asking\n   about\n5. `compliance-aiops bundle generate soc2 --since 2026-07-01 --until 2026-10-01 --sign`\n   → a hash-chain-sealed bundle under `~/.compliance-aiops/bundles/`\n6. `compliance-aiops bundle export <path> --format markdown` → the\n   auditor-facing report (also `json` / `csv`)\n7. **Failure branch**: if `report coverage` shows CC8.1 thin, **do not generate\n   anyway and hope** — run workflow 2 first and hand the auditor the honest gap\n   statement. A bundle asserts what the audit trail contains; it cannot\n   manufacture evidence that was never recorded.\n\n### 2. \"Which controls are we actually short on?\" (gap analysis)\n\n1. `compliance-aiops report sources` → establish the evidence base and its date\n   coverage; a gap caused by a *missing source* is a different problem from a\n   gap caused by *missing activity*\n2. `compliance-aiops report gaps hipaa` (also `pci_dss`, `soc2`, `gdpr`) →\n   controls with no or weak evidence, each with an honest caveat and a\n   remediation suggestion\n3. `compliance-aiops report exceptions` → the operations that ran **without** an\n   approver or rationale — usually the fastest-to-fix category of gap\n4. Drill into one control's population with `control_evidence` (MCP) to see the\n   **reproducible query** behind the coverage number, so the figure can be\n   defended rather than merely quoted\n5. `compliance-aiops report coverage <framework>` again after remediation to\n   confirm the gap actually closed\n6. **Failure branch**: if `list_frameworks` does not carry the framework or\n   control the auditor named, say so — this tool maps to HIPAA / PCI-DSS /\n   SOC 2 / GDPR and does not silently substitute a near-miss control.\n\n### 3. Prove a delivered bundle was not altered\n\n1. `compliance-aiops bundle list` → locate the bundle and its recorded\n   `chainHead`\n2. `compliance-aiops bundle verify <path>` → re-derives the hash chain, compares\n   it to the seal's `chainHead`, and checks the optional signature\n3. Because the chain is computed over evidence records only, the **same**\n   (framework, period, sources) reproduces the **same** `chainHead` — regenerate\n   and compare to prove reproducibility\n4. Record the `chainHead` **out-of-band** (ticket, email to the auditor, WORM\n   store) at delivery time; that out-of-band copy is what makes later\n   verification meaningful\n5. `verify_source_chain` (MCP) on each source → returns the source chain head and\n   flags **row-id gaps**, a sign that rows were deleted from that `audit.db`\n6. **Failure branch**: a `chainHead` mismatch or a row-id gap means the evidence\n   is **not** trustworthy — escalate, and treat the source `audit.db` as the\n   system of record. Do not re-seal a fresh bundle to make the mismatch go away;\n   the tool is **tamper-evident, not tamper-proof**, and its whole value is that\n   it reports this rather than papering over it.\n\n### 4. 定期封存 — schedule periodic sealed bundles (no daemon)\n\nThis tool ships **no scheduler**; it emits a cron line for you to install.\n\n1. `compliance-aiops report sources` → confirm the sources you want sealed are\n   discoverable from the account cron will run as (a common failure: cron sees a\n   different `$HOME`)\n2. `compliance-aiops bundle schedule soc2 --cron \"0 2 * * 1\" --period 7d --sign`\n   (MCP: `bundle_schedule_hint`) → returns a `cronLine` plus the exact\n   non-interactive command. **It writes nothing.**\n3. Paste the `cronLine` into `crontab -e`, e.g.\n   `0 2 * * 1 compliance-aiops bundle generate soc2 --period 7d --sign`\n4. Export `COMPLIANCE_AIOPS_MASTER_PASSWORD` in the cron environment so the\n   signing key unlocks non-interactively — never inline the real password in the\n   crontab\n5. After the first scheduled run, `compliance-aiops bundle list` and\n   `bundle verify` the newest bundle to confirm the unattended path really works\n6. **Failure branch**: if the cron run produces no bundle, the usual causes are\n   an unset master password (signing cannot unlock) or `COMPLIANCE_AIOPS_HOME`\n   not being set in cron's environment, so sources resolve elsewhere. Verify by\n   running the emitted command by hand with a clean environment before trusting\n   the schedule.\n\n## Governance & Safety\n\nThe skill reads audit trails and writes evidence bundles and records what it\ndoes; it does **not** decide whether producing or signing a bundle is permitted.\nThat is your agent's judgement, or the filesystem permissions of the account it\nruns as. There is no read-only switch, policy file, or approval gate.\n\n- **Audit is the guarantee, and it is not bypassable.** Every operation — MCP and CLI alike — is logged to `~/.compliance-aiops/audit.db` (relocatable via `COMPLIANCE_AIOPS_HOME`): params, result, status, duration, and the risk tier. The CLI writes the same row the MCP path does.\n- The source audit trails are opened **read-only**; the tool never mutates them. The only files written are bundles under `~/.compliance-aiops/bundles/`.\n- `COMPLIANCE_AUDIT_APPROVED_BY` / `COMPLIANCE_AUDIT_RATIONALE` are optional annotations recorded on the audit row (who/why); they are never required and never block.\n- **Tamper-EVIDENT, not tamper-PROOF** — the source `audit.db` remains the system\n  of record.\n\n## References\n\n- `references/capabilities.md` — full tool → inputs → returns reference\n- `references/cli-reference.md` — CLI command reference\n- `references/setup-guide.md` — source discovery, org name, optional signing key, integrity notes\n\nFile v0.11.0:_meta.json\n\n{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"compliance-aiops\",\n  \"version\": \"0.11.0\",\n  \"publishedAt\": 1789174071821\n}\n\nFile v0.11.0:references/agent-guardrails.md\n\n# Agent guardrails — running compliance-aiops with a smaller / local model\n\ncompliance-aiops is a **meta-tool**: it reads the audit databases the other\nAIops tools write, and turns them into framework-mapped evidence. That makes the\nfailure mode here different from an infrastructure tool. A wrong answer does not\nbreak a cluster — it produces a **confident, false compliance claim**, which is\nworse, because it looks like a finding.\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\n## Authorization is not this tool's job — decide it where it belongs\n\nWhether a bundle should be produced or signed is your decision, or the account's.\nThe tool does not gate it — there is no read-only switch and no approval prompt\nto configure. The two right places to control it:\n\n- **The account it runs as.** The tool only ever writes under\n  `~/.compliance-aiops/`, and opens every source `audit.db` strictly read-only —\n  so ordinary filesystem permissions bound what it can do. A write then fails at\n  the OS, which is the only place the permission actually lives.\n- **Your agent's system prompt.** If you want a query-only session, tell the\n  model not to call the bundle-writing tools (they are clearly tagged `[WRITE]`).\n\nWhat the tool *does* guarantee is that you can always see what happened:\n\n## What the tool enforces — do not waste prompt budget on these\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Never modify the audit trail\" | The tool has no capability to write to any source `audit.db` — it opens them read-only. Nothing in the tool surface can alter the evidence it reports on. |\n| \"Don't get stuck retrying\" | The runaway guard trips a circuit breaker if the same call is hammered in a tight loop — a stuck agent is stopped rather than left to burn calls and time. |\n| \"Don't invent an approver or a reason\" | A field the audit row did not record comes back as `null`, never as `\"\"`. \"No approver was recorded\" and \"the approver field was blank\" stay distinguishable — which is exactly the distinction a change-approval finding turns on. |\n| \"Tell me if you only saw part of the trail\" | Every report carries `scanLimit` and `scanTruncated`, and every capped list carries `returned` / `limit` / `truncated`. Truncation is measured — one row past the cap is fetched — never inferred from a count landing on a round number. |\n| \"Check the evidence hasn't been tampered with\" | `verify_source_chain` hash-chains a source's current events and reports row-id gaps; `verify_bundle` re-derives a sealed bundle's chain and reports the first broken link plus signature validity. You do not need to ask the model to reason about integrity — ask it to run the check. |\n| \"Be honest about what an audit log can prove\" | Every control carries a `strength` and a `caveat`, and gap findings carry the design-vs-operating note. Coverage is only claimed where the trail actually contains the evidence. |\n| \"Log everything you do, over both MCP and the CLI\" | Every call is audited to `~/.compliance-aiops/audit.db` regardless of what the model says it did — and the CLI writes the same row the MCP path does, so there is no unaudited entry point. |\n\n## What still needs a prompt\n\nThese are model-behaviour problems the harness cannot fix from the outside.\nCopy this into your agent's system prompt:\n\n```text\nYou operate compliance-aiops, which reads the audit trails other AIops tools\nproduce and maps them to framework controls (HIPAA, PCI-DSS, SOC2, GDPR).\n\nTOOL USE\n- Before answering any question about compliance posture, coverage, or a\n  specific control, you MUST call a tool. Never answer from memory, and never\n  from your training knowledge of what a framework requires.\n- Actually invoke the tool. Do not describe the call you would make, and do not\n  emit an example JSON response in place of calling it.\n- If a tool call fails, report the real error verbatim. An unreadable audit\n  source means unknown coverage, not zero findings and not full coverage.\n\nEVIDENCE INTEGRITY — the part that matters most here\n- NEVER state or imply that an organisation \"is compliant\", \"passes\", or \"is\n  certified\". This tool produces evidence about operations recorded in an audit\n  trail. Certification is a judgement made by a qualified assessor over a much\n  wider scope. Say what the evidence shows; never issue a verdict.\n- If a result has scanTruncated or truncated set to true, the population you saw\n  is a slice. Say so explicitly and do not compute or quote a coverage\n  percentage, a total, or a \"no violations found\" statement from it.\n- Quote counts and control ids exactly as returned. Never round, extrapolate,\n  or fill a gap in the trail with an assumption about what probably happened.\n- A null approver means no approver was recorded — report that as the finding\n  it is. Do not soften it, and do not guess who approved.\n- Report every control's caveat and strength alongside its coverage. A control\n  marked PARTIAL is not covered; it is partly evidenced by operational logs and\n  needs design/configuration evidence from a GRC system.\n- An absence of evidence for a control means the trail contains nothing matching\n  it. That is not proof the control failed, and not proof it passed. Say which\n  one the data supports: neither.\n\nSCOPE\n- Separate observation from interpretation. State what the tools returned, then\n  any interpretation, clearly marked as such.\n- A hash chain is tamper-EVIDENT, not tamper-PROOF. An \"intact\" verdict means\n  the records match a previously recorded head — it does not prove nothing was\n  ever deleted before that head was taken. Row-id gaps are the signal for that,\n  and they are reported separately.\n- Do not confuse the source tools' identifiers with each other: a `source` is an\n  AIops tool's audit database, a `skill` is the tool that logged the row, and a\n  `tool` is the individual operation. They are three different columns.\n```\n\n## Recommended setup for a local model\n\nKeep the agent query-only until you trust the setup — the tool already opens\nevery source trail read-only, and the only thing it can write is a bundle under\n`~/.compliance-aiops/`:\n\n```bash\ncompliance-aiops doctor\n```\n\nOptionally annotate the audit trail with who is operating and why — recorded on\nevery row, never required:\n\n```bash\nexport COMPLIANCE_AUDIT_APPROVED_BY=\"your.name@example.com\"\nexport COMPLIANCE_AUDIT_RATIONALE=\"Q3 SOC2 evidence collection\"\n```\n\n## If your model still struggles\n\nSome behaviours are model-capacity limits rather than prompt problems:\n\n- **The model editorialises into a verdict.** This is the characteristic failure\n  of smaller models on this tool. Ask for the numbers first (\"what does\n  coverage_summary return for soc2?\") and only then for a summary, rather than\n  asking \"are we SOC2 compliant?\" — the second phrasing invites a verdict the\n  data cannot support.\n- **Multi-tool workflows time out or drift.** Lead with `posture_overview` — it\n  folds source availability and per-framework coverage into one call.\n- **The model ignores later tool results in a long context.** Ask about one\n  control at a time with `control_evidence` rather than pulling a whole\n  framework's population.\n- **The model describes calls instead of making them.** This is usually a\n  runtime/tool-calling-format mismatch, not a prompt problem — check that your\n  client advertises the tools in the format your model was trained on.\n\nFeedback on running this with a specific local model is genuinely useful —\nopen an issue at\n[github.com/AIops-tools/Compliance-AIops](https://github.com/AIops-tools/Compliance-AIops/issues)\nwith the model, runtime, and what went wrong.\n\nFile v0.11.0:references/capabilities.md\n\n# compliance-aiops capabilities\n\n> Evidence, not certification. 19 MCP tools (14 read, 3 write, 2 undo). Data\n> source: the local `audit_log` trails governed AIops tools write, discovered via\n> `~/.*-aiops/audit.db` and read **read-only**. No external API, no network, no\n> platform credentials. `since` / `until` accept ISO-8601 timestamps.\n\n## Read / analysis tools (12)\n\n### Audit reads\n\n| Tool | Inputs | Returns |\n|------|--------|---------|\n| `list_audit_sources` | — | discovered sources: `name`, `path`, `tool`, `readable`, `rowCount` |\n| `query_audit_events` | `source?`, `skill?`, `tool?`, `status?`, `risk_level?`, `approved?`, `selector?`, `since?`, `until?`, `limit=100` | matched events (cross-tool), normalised audit rows |\n| `activity_timeline` | `since?`, `until?`, `bucket=\"day\"` (`hour`\\|`day`) | event counts per time bucket |\n\n### Framework mapping\n\n| Tool | Inputs | Returns |\n|------|--------|---------|\n| `list_frameworks` | — | frameworks + control counts (`hipaa`, `pci_dss`, `soc2`, `gdpr`, `iso27001`, `djcp_l3`) |\n| `coverage_summary` | `framework`, `since?`, `until?` | per-control `covered`/`weak`/`uncovered`, evidence counts, strength labels |\n| `control_evidence` | `framework`, `control_id`, `since?`, `until?`, `sample_size=20` | evidence rows + population size + the reproducible query for ONE control |\n| `gap_analysis` | `framework`, `since?`, `until?` | controls with no/weak evidence + honest `strong`/`partial` caveat + remediation hint |\n\n### Assurance reports\n\n| Tool | Inputs | Returns |\n|------|--------|---------|\n| `approval_report` | `since?`, `until?`, `high_only=True` | high-risk write ops + who approved + rationale (CC8.1 / PCI 7-8 / HIPAA §312(a) artifact) |\n| `exceptions_report` | `since?`, `until?` | denied / error / budget_exceeded ops — enforcement + anomaly evidence |\n\n### Integrity\n\n| Tool | Inputs | Returns |\n|------|--------|---------|\n| `verify_source_chain` | `source`, `since?`, `until?` | chain head + row-id gap detection (flags deletions) for one source |\n| `verify_bundle` | `bundle_path` | verifies chain + seal head + optional signature; `ok` + any mismatch detail |\n| `list_bundles` | — | bundles under `~/.compliance-aiops/bundles/` |\n| `oscal_assessment_results` | `bundle_path` | the bundle as a NIST **OSCAL 1.2.3** Assessment Results document, returned inline with a `summary` (satisfied / not-satisfied / **satisfiedOnPartialEvidence** / scanTruncated) and an explicit `limitations` list. Deterministic: v5 UUIDs derived from the chain head, so re-export is byte-identical |\n| `bundle_schedule_hint` | `framework`, `cron=\"0 2 * * 1\"`, `period=\"7d\"`, `sign=False` | ready-to-paste 5-field cron line + non-interactive command for periodic sealing; **writes nothing, no daemon** |\n\n## Write / artifact tools (3 — no external mutation)\n\n| Tool | Risk | Inputs | Returns / effect |\n|------|:---:|--------|------------------|\n| `generate_evidence_bundle` | **medium** | `framework`, `period_start?`, `period_end?`, `out_path?`, `sign=False`, `period?` (relative window e.g. `7d`) | one call: coverage + approval trail + exceptions + sealed records → a bundle `.json` under `~/.compliance-aiops/bundles/`; returns path + `chainHead` |\n| `export_bundle` | **medium** | `bundle_path`, `fmt=\"markdown\"` (`markdown`\\|`csv`\\|`json`\\|`oscal`), `out_path?` | renders a bundle to the chosen format; `oscal` writes `<bundle>.oscal.json` |\n| `sign_bundle` | **medium** | `bundle_path` | adds an HMAC signature over the seal using the stored signing key |\n\n## Integrity model\n\n- Each record hash = `SHA-256(prev_hash ‖ canonical_json(record))`; genesis\n  `prev` = 64 zeros. The `chainHead` is the last record hash.\n- Seal = `{framework, period, sources (+ per-db SHA-256), recordCount, chainHead,\n  generatedAt, generator, optional signature}`.\n- The chain is over **evidence records only**, so `chainHead` is **reproducible**\n  for the same (framework, period, sources).\n- **Tamper-EVIDENT, not tamper-PROOF** — the source `audit.db` remains the system\n  of record; record `chainHead` out-of-band as an anchor.\n\n## Out of scope (by design)\n\n- Scanning or operating infrastructure (use the other AIops-tools)\n- Acting as a GRC platform / policy-management system\n- OSCAL export (documented v0.2 roadmap; v0.1 emits JSON / Markdown / CSV)\n\nWant another framework, control mapping, or export format? Open an issue or PR —\nfeedback and contributions welcome.\n\nFile v0.11.0:references/cli-reference.md\n\n# compliance-aiops CLI reference\n\n> Evidence, not certification. Reads the local audit trails governed\n> AIops tools write (`~/.*-aiops/audit.db`) read-only. No external API, no\n> network, no platform credentials. The CLI is a convenience subset; the full\n> 19-tool surface is available over MCP.\n\n## Setup & diagnostics\n\n```bash\ncompliance-aiops init                      # discover sibling audit DBs, set org name, optional signing key\ncompliance-aiops doctor                    # which sibling audit DBs are present/readable\ncompliance-aiops overview                  # audit sources + per-framework covered/total counts\ncompliance-aiops mcp                        # start the MCP server (stdio transport)\n```\n\n## Reports (read-only)\n\n```bash\ncompliance-aiops report sources                    # discovered audit sources + row counts\ncompliance-aiops report coverage <framework>       # per-control coverage (hipaa|pci_dss|soc2|gdpr)\ncompliance-aiops report gaps <framework>           # controls with no/weak evidence + honest caveat\ncompliance-aiops report approvals                  # high-risk write ops + approver + rationale\ncompliance-aiops report exceptions                 # denied / error / budget_exceeded ops\n```\n\n## Bundles (evidence artifacts)\n\n```bash\ncompliance-aiops bundle generate <framework> [--since <iso>] [--until <iso>] [--period <7d|24h|2w|last-7-days>] [--sign]\n                                                   # hash-chain-sealed bundle → ~/.compliance-aiops/bundles/\ncompliance-aiops bundle verify <path>              # re-verify chain + seal head (+ signature)\ncompliance-aiops bundle list                       # list generated bundles\ncompliance-aiops bundle export <path> --format <markdown|csv|json>\ncompliance-aiops bundle schedule <framework> [--cron \"0 2 * * 1\"] [--period 7d] [--sign]\n                                                   # print a ready-to-paste cron line; WRITES NOTHING, no daemon\n```\n\n## Secrets (optional bundle-signing key, encrypted ~/.compliance-aiops/secrets.enc)\n\nOnly needed if you sign bundles; there are no platform credentials.\n\n```bash\ncompliance-aiops secret set <name> [--value <key>]   # store signing key (hidden prompt if no --value)\ncompliance-aiops secret list                          # names only — values never shown\ncompliance-aiops secret rm <name>\ncompliance-aiops secret migrate                       # import a legacy plaintext key\ncompliance-aiops secret rotate-password               # re-encrypt under a new master password\n```\n\n## Notes\n\n- `<framework>` is one of `hipaa`, `pci_dss`, `soc2`, `gdpr`, `iso27001`, `djcp_l3`.\n- `--since` / `--until` bound the evidence period (ISO-8601). The hash chain is\n  over evidence records only, so the same `(framework, period, s\n\nArchive v0.10.0: 7 files, 17430 bytes\n\nFiles: references/agent-guardrails.md (7993b), references/capabilities.md (4440b), references/cli-reference.md (3342b), references/setup-guide.md (3370b), skill-card.md (2819b), SKILL.md (14701b), _meta.json (136b)\n\nArchive v0.9.0: 7 files, 17299 bytes\n\nFiles: references/agent-guardrails.md (7993b), references/capabilities.md (4048b), references/cli-reference.md (3342b), references/setup-guide.md (3370b), skill-card.md (3106b), SKILL.md (14678b), _meta.json (135b)\n\nArchive v0.8.0: 7 files, 17288 bytes\n\nFiles: references/agent-guardrails.md (7993b), references/capabilities.md (4048b), references/cli-reference.md (3342b), references/setup-guide.md (3370b), skill-card.md (3160b), SKILL.md (14678b), _meta.json (135b)\n\nArchive v0.7.0: 7 files, 17194 bytes\n\nFiles: references/agent-guardrails.md (7993b), references/capabilities.md (4048b), references/cli-reference.md (3342b), references/setup-guide.md (3370b), skill-card.md (2786b), SKILL.md (14678b), _meta.json (135b)\n\nArchive v0.6.0: 7 files, 17193 bytes\n\nFiles: references/agent-guardrails.md (7993b), references/capabilities.md (4048b), references/cli-reference.md (3342b), references/setup-guide.md (3370b), skill-card.md (2931b), SKILL.md (14678b), _meta.json (135b)\n\nArchive v0.5.0: 7 files, 16768 bytes\n\nFiles: references/agent-guardrails.md (7182b), references/capabilities.md (4048b), references/cli-reference.md (3342b), references/setup-guide.md (3370b), skill-card.md (2989b), SKILL.md (14652b), _meta.json (135b)","readmeExcerpt":"Skill: compliance-aiops Owner: zw008 Summary: Use this skill whenever the user needs compliance evidence from the audit trails their governed AIops agents already write — mapping AI-agent infra-ops activity to HIPAA §164.312, PCI-DSS v4.0, SOC 2 TSC, or GDPR controls, producing a change-approval report, a gap analysis, an exceptions/anomaly report, or a hash-chain-sealed, tamper-evident evidence bundle. Always use th","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"uv tool install compliance-aiops\ncompliance-aiops init       # discover sibling ~/.*-aiops/audit.db, set org name, optional signing key\ncompliance-aiops doctor     # which sibling audit DBs are present/readable"},{"language":"bash","snippet":"openclaw plugins install clawhub:@zw008/compliance-aiops\nopenclaw skills info compliance-aiops          # expect: Visible to model: yes"},{"language":"text","snippet":"You operate compliance-aiops, which reads the audit trails other AIops tools\nproduce and maps them to framework controls (HIPAA, PCI-DSS, SOC2, GDPR).\n\nTOOL USE\n- Before answering any question about compliance posture, coverage, or a\n  specific control, you MUST call a tool. Never answer from memory, and never\n  from your training knowledge of what a framework requires.\n- Actually invoke the tool. Do not describe the call you would make, and do not\n  emit an example JSON response in place of calling it.\n- If a tool call fails, report the real error verbatim. An unreadable audit\n  source means unknown coverage, not zero findings and not full coverage.\n\nEVIDENCE INTEGRITY — the part that matters most here\n- NEVER state or imply that an organisation \"is compliant\", \"passes\", or \"is\n  certified\". This tool produces evidence about operations recorded in an audit\n  trail. Certification is a judgement made by a qualified assessor over a much\n  wider scope. Say what the evidence shows; never issue a verdict.\n- If a result has scanTruncated or truncated set to true, the population you saw\n  is a slice. Say so explicitly and do not compute or quote a coverage\n  percentage, a total, or a \"no violations found\" statement from it.\n- Quote counts and control ids exactly as returned. Never round, extrapolate,\n  or fill a gap in the trail with an assumption about what probably happened.\n- A null approver means no approver was recorded — report that as the finding\n  it is. Do not soften it, and do not guess who approved.\n- Report every control's caveat and strength alongside its coverage. A control\n  marked PARTIAL is not covered; it is partly evidenced by operational logs and\n  needs design/configuration evidence from a GRC system.\n- An absence of evidence for a control means the trail contains nothing matching\n  it. That is not proof the control failed, and not proof it passed. Say which\n  one the data supports: neither.\n\nSCOPE\n- Separate observation from interpretation. State what"},{"language":"bash","snippet":"compliance-aiops doctor"},{"language":"bash","snippet":"export COMPLIANCE_AUDIT_APPROVED_BY=\"your.name@example.com\"\nexport COMPLIANCE_AUDIT_RATIONALE=\"Q3 SOC2 evidence collection\""},{"language":"bash","snippet":"compliance-aiops init                      # discover sibling audit DBs, set org name, optional signing key\ncompliance-aiops doctor                    # which sibling audit DBs are present/readable\ncompliance-aiops overview                  # audit sources + per-framework covered/total counts\ncompliance-aiops mcp                        # start the MCP server (stdio transport)"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: compliance-aiops\nslug: compliance-aiops\ndisplayName: \"Compliance AIops\"\nsummary: \"Compliance evidence from AIops audit trails: HIPAA/PCI/SOC2/GDPR, OSCAL export, 19 tools.\"\nlicense: MIT\nhomepage: https://github.com/AIops-tools/Compliance-AIops\ntags: [aiops, mcp, governance, compliance]\ndescription: >\n  Use this skill whenever the user needs compliance evidence from the audit trails their governed AIops agents already write — mapping AI-agent infra-ops activity to HIPAA §164.312, PCI-DSS v4.0, SOC 2 TSC, or GDPR controls, producing a change-approval report, a gap analysis, an exceptions/anomaly report, or a hash-chain-sealed, tamper-evident evidence bundle.\n  Always use this skill for \"compliance evidence\", \"HIPAA / PCI-DSS / SOC 2 / GDPR evidence\", \"audit trail report\", \"coverage for control X\", \"which controls are we short on / gap analysis\", \"who approved this change / change-management evidence\", \"denied or errored ops / anomaly evidence\", \"seal / sign an evidence bundle\", \"prove this bundle wasn't altered\", or \"detect deleted audit rows\".\n  Do NOT use to scan or operate infrastructure and do NOT treat it as a GRC platform — it reads the local audit databases the OTHER AIops-tools write and converts them to evidence; for platform operations use those other AIops-tools.\n  Evidence, not certification. Reads sibling audit trails read-only; no external API, no network, no platform credentials. Fully offline and deterministic.\ninstaller:\n  kind: uv\n  package: compliance-aiops\nargument-hint: \"[framework (hipaa|pci_dss|soc2|gdpr|iso27001|djcp_l3) or describe your evidence task]\"\nallowed-tools:\n  - Bash\nmetadata: {\"openclaw\":{\"requires\":{\"anyBins\":[\"compliance-aiops\",\"uvx\"]},\"optional\":{\"env\":[\"COMPLIANCE_AIOPS_CONFIG\",\"COMPLIANCE_AIOPS_MASTER_PASSWORD\"]},\"homepage\":\"https://github.com/AIops-tools/Compliance-AIops\",\"emoji\":\"📋\",\"os\":[\"macos\",\"linux\"]}}\ncompatibility: >\n  Standalone compliance-evidence tooling. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.\n  Data source: the LOCAL audit databases the other governed AIops tools already write, discovered by glob at ~/.*-aiops/audit.db (one shared audit_log schema). These are read READ-ONLY. There is NO external API, NO network, and NO platform credentials.\n  The only optional secret is a bundle-signing key, stored ENCRYPTED in ~/.compliance-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk, unlocked by a master password from COMPLIANCE_AIOPS_MASTER_PASSWORD (non-interactive/MCP/CI) or an interactive prompt (CLI on a TTY). If you never sign bundles you need no secret at all.\n  Outputs: evidence bundles written to ~/.compliance-aiops/bundles/ (the only files written). All tool calls are themselves audited to a local SQLite DB under ~/.compliance-aiops/ (relocatable via COMPLIANCE_AIOPS_HOME). Write tools (generate_evidence_bundle, export_bundle: low risk; sign_bundle: "},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7b067awq2s97bn3d7p5qfhw5827pxc\",\n  \"slug\": \"compliance-aiops\",\n  \"version\": \"0.11.3\",\n  \"publishedAt\": 1789451503021\n}"},{"path":"references/agent-guardrails.md","content":"# Agent guardrails — running compliance-aiops with a smaller / local model\n\ncompliance-aiops is a **meta-tool**: it reads the audit databases the other\nAIops tools write, and turns them into framework-mapped evidence. That makes the\nfailure mode here different from an infrastructure tool. A wrong answer does not\nbreak a cluster — it produces a **confident, false compliance claim**, which is\nworse, because it looks like a finding.\n\nIf you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,\nOllama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably\nbetter results with a short system prompt. This page gives you one, and — more\nimportantly — tells you which guardrails you **no longer need to write**, because\nthe tool now enforces them itself.\n\n## Authorization is not this tool's job — decide it where it belongs\n\nWhether a bundle should be produced or signed is your decision, or the account's.\nThe tool does not gate it — there is no read-only switch and no approval prompt\nto configure. The two right places to control it:\n\n- **The account it runs as.** The tool only ever writes under\n  `~/.compliance-aiops/`, and opens every source `audit.db` strictly read-only —\n  so ordinary filesystem permissions bound what it can do. A write then fails at\n  the OS, which is the only place the permission actually lives.\n- **Your agent's system prompt.** If you want a query-only session, tell the\n  model not to call the bundle-writing tools (they are clearly tagged `[WRITE]`).\n\nWhat the tool *does* guarantee is that you can always see what happened:\n\n## What the tool enforces — do not waste prompt budget on these\n\n| You might be tempted to prompt | Why you don't need to |\n|---|---|\n| \"Never modify the audit trail\" | The tool has no capability to write to any source `audit.db` — it opens them read-only. Nothing in the tool surface can alter the evidence it reports on. |\n| \"Don't get stuck retrying\" | The runaway guard trips a circuit breaker if the same call is hammered in a tight loop — a stuck agent is stopped rather than left to burn calls and time. |\n| \"Don't invent an approver or a reason\" | A field the audit row did not record comes back as `null`, never as `\"\"`. \"No approver was recorded\" and \"the approver field was blank\" stay distinguishable — which is exactly the distinction a change-approval finding turns on. |\n| \"Tell me if you only saw part of the trail\" | Every report carries `scanLimit` and `scanTruncated`, and every capped list carries `returned` / `limit` / `truncated`. Truncation is measured — one row past the cap is fetched — never inferred from a count landing on a round number. |\n| \"Check the evidence hasn't been tampered with\" | `verify_source_chain` hash-chains a source's current events and reports row-id gaps; `verify_bundle` re-derives a sealed bundle's chain and reports the first broken link plus signature validity. You do not need to ask the model to reason about integrity — ask it to run the check. |\n|"},{"path":"references/capabilities.md","content":"# compliance-aiops capabilities\n\n> Evidence, not certification. 19 MCP tools (14 read, 3 write, 2 undo). Data\n> source: the local `audit_log` trails governed AIops tools write, discovered via\n> `~/.*-aiops/audit.db` and read **read-only**. No external API, no network, no\n> platform credentials. `since` / `until` accept ISO-8601 timestamps.\n\n## Read / analysis tools (12)\n\n### Audit reads\n\n| Tool | Inputs | Returns |\n|------|--------|---------|\n| `list_audit_sources` | — | discovered sources: `name`, `path`, `tool`, `readable`, `rowCount` |\n| `query_audit_events` | `source?`, `skill?`, `tool?`, `status?`, `risk_level?`, `approved?`, `selector?`, `since?`, `until?`, `limit=100` | matched events (cross-tool), normalised audit rows |\n| `activity_timeline` | `since?`, `until?`, `bucket=\"day\"` (`hour`\\|`day`) | event counts per time bucket |\n\n### Framework mapping\n\n| Tool | Inputs | Returns |\n|------|--------|---------|\n| `list_frameworks` | — | frameworks + control counts (`hipaa`, `pci_dss`, `soc2`, `gdpr`, `iso27001`, `djcp_l3`) |\n| `coverage_summary` | `framework`, `since?`, `until?` | per-control `covered`/`weak`/`uncovered`, evidence counts, strength labels |\n| `control_evidence` | `framework`, `control_id`, `since?`, `until?`, `sample_size=20` | evidence rows + population size + the reproducible query for ONE control |\n| `gap_analysis` | `framework`, `since?`, `until?` | controls with no/weak evidence + honest `strong`/`partial` caveat + remediation hint |\n\n### Assurance reports\n\n| Tool | Inputs | Returns |\n|------|--------|---------|\n| `approval_report` | `since?`, `until?`, `high_only=True` | high-risk write ops + who approved + rationale (CC8.1 / PCI 7-8 / HIPAA §312(a) artifact) |\n| `exceptions_report` | `since?`, `until?` | denied / error / budget_exceeded ops — enforcement + anomaly evidence |\n\n### Integrity\n\n| Tool | Inputs | Returns |\n|------|--------|---------|\n| `verify_source_chain` | `source`, `since?`, `until?` | chain head + row-id gap detection (flags deletions) for one source |\n| `verify_bundle` | `bundle_path` | verifies chain + seal head + optional signature; `ok` + any mismatch detail |\n| `list_bundles` | — | bundles under `~/.compliance-aiops/bundles/` |\n| `oscal_assessment_results` | `bundle_path` | the bundle as a NIST **OSCAL 1.2.3** Assessment Results document, returned inline with a `summary` (satisfied / not-satisfied / **satisfiedOnPartialEvidence** / scanTruncated) and an explicit `limitations` list. Deterministic: v5 UUIDs derived from the chain head, so re-export is byte-identical |\n| `bundle_schedule_hint` | `framework`, `cron=\"0 2 * * 1\"`, `period=\"7d\"`, `sign=False` | ready-to-paste 5-field cron line + non-interactive command for periodic sealing; **writes nothing, no daemon** |\n\n## Write / artifact tools (3 — no external mutation)\n\n| Tool | Risk | Inputs | Returns / effect |\n|------|:---:|--------|------------------|\n| `generate_evidence_bundle` | **medium** | `framework`, `period_start?`, `period_end?`, `out_pat"},{"path":"references/cli-reference.md","content":"# compliance-aiops CLI reference\n\n> Evidence, not certification. Reads the local audit trails governed\n> AIops tools write (`~/.*-aiops/audit.db`) read-only. No external API, no\n> network, no platform credentials. The CLI is a convenience subset; the full\n> 19-tool surface is available over MCP.\n\n## Setup & diagnostics\n\n```bash\ncompliance-aiops init                      # discover sibling audit DBs, set org name, optional signing key\ncompliance-aiops doctor                    # which sibling audit DBs are present/readable\ncompliance-aiops overview                  # audit sources + per-framework covered/total counts\ncompliance-aiops mcp                        # start the MCP server (stdio transport)\n```\n\n## Reports (read-only)\n\n```bash\ncompliance-aiops report sources                    # discovered audit sources + row counts\ncompliance-aiops report coverage <framework>       # per-control coverage (hipaa|pci_dss|soc2|gdpr)\ncompliance-aiops report gaps <framework>           # controls with no/weak evidence + honest caveat\ncompliance-aiops report approvals                  # high-risk write ops + approver + rationale\ncompliance-aiops report exceptions                 # denied / error / budget_exceeded ops\n```\n\n## Bundles (evidence artifacts)\n\n```bash\ncompliance-aiops bundle generate <framework> [--since <iso>] [--until <iso>] [--period <7d|24h|2w|last-7-days>] [--sign]\n                                                   # hash-chain-sealed bundle → ~/.compliance-aiops/bundles/\ncompliance-aiops bundle verify <path>              # re-verify chain + seal head (+ signature)\ncompliance-aiops bundle list                       # list generated bundles\ncompliance-aiops bundle export <path> --format <markdown|csv|json>\ncompliance-aiops bundle schedule <framework> [--cron \"0 2 * * 1\"] [--period 7d] [--sign]\n                                                   # print a ready-to-paste cron line; WRITES NOTHING, no daemon\n```\n\n## Secrets (optional bundle-signing key, encrypted ~/.compliance-aiops/secrets.enc)\n\nOnly needed if you sign bundles; there are no platform credentials.\n\n```bash\ncompliance-aiops secret set <name> [--value <key>]   # store signing key (hidden prompt if no --value)\ncompliance-aiops secret list                          # names only — values never shown\ncompliance-aiops secret rm <name>\ncompliance-aiops secret migrate                       # import a legacy plaintext key\ncompliance-aiops secret rotate-password               # re-encrypt under a new master password\n```\n\n## Notes\n\n- `<framework>` is one of `hipaa`, `pci_dss`, `soc2`, `gdpr`, `iso27001`, `djcp_l3`.\n- `--since` / `--until` bound the evidence period (ISO-8601). The hash chain is\n  over evidence records only, so the same `(framework, period, sources)`\n  reproduces the same `chainHead`.\n- `--period` is a convenience relative window (`7d` / `24h` / `2w` /\n  `last-7-days`) resolved to a since/until pair ending \"now\"; used only when\n  `--since` / `--until` are not given. `bundle schedul"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":2185,"uniquenessScore":39,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T05:36:48.313Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T05:36:48.313Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T10:45:04.220Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}