A deny-by-default security and governance framework that intercepts every tool call to ensure agent safety and compliance.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install gatewaystack-governance
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install gatewaystack-governance using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
GatewayStack Governance provides an essential security layer for Openclaw Skills by enforcing strict tool-call policies at the process level. By utilizing a deny-by-default architecture, this skill ensures that agents cannot bypass security checks, effectively preventing unauthorized actions and prompt injection attacks. It offers a comprehensive suite of protective measures, including identity mapping and detailed audit trails, making it a critical component for production-grade AI agent deployments.
This framework acts as a technical firewall, ensuring that every interaction between the agent and its available tools is scrutinized. By hooking directly into the process lifecycle, it provides a level of security that cannot be negotiated or talked around by the underlying LLM, establishing a hard boundary for autonomous operations.
To begin securing your environment, install the plugin using the Openclaw CLI:
openclaw plugins install @gatewaystack/gatewaystack-governance
The five core checks are active immediately upon installation. To customize the governance rules and define your own security roles, copy the example policy file:
cp ~/.openclaw/plugins/gatewaystack-governance/policy.example.json \
~/.openclaw/plugins/gatewaystack-governance/policy.json
For advanced features like DLP or behavioral monitoring, install the optional GatewayStack dependencies:
npm install @gatewaystack/transformabl-core
npm install @gatewaystack/limitabl-core
The governance system manages security via structured files and internal patterns to provide transparency for Openclaw Skills:
| Component | Description | File Type |
|---|---|---|
| Policy Configuration | Defines roles, tools, and security thresholds | policy.json |
| Audit Logs | A chronological, append-only record of all tool interactions | .jsonl |
| Identity Map | Maps specific agent IDs to security profiles | JSON |
| Injection Patterns | 40+ regex-based signatures for threat detection | Internal |
| DLP Signatures | Patterns used for PII detection and redaction | Internal |
Loading
The core integration contract for external bots to securely onboard and interact with GOYFILES datasets and graph search tools.

A satellite pass orchestrator that sends real-time dish alignment data and WhatsApp alerts for manual or automated SDR reception.

An aviation monitoring skill that detects nearby aircraft from local ADS-B feeds and triggers automated notifications based on proximity.

A modern Go-based CLI for managing bookmarks, tags, and assets in a self-hosted Linkding instance.

A file-based protocol for coordinating work between humans and AI agents using plain text files and Git as the source of truth.

Sightglass instruments AI coding agents to capture dependency choices, surfacing risks and biases in the agent's decision-making process.








































