GatewayStack Governance for Openclaw

A deny-by-default security and governance framework that intercepts every tool call to ensure agent safety and compliance.

davidcrowe
v0.2.0
Feb 22, 2026
2
899
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install gatewaystack-governance

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install gatewaystack-governance using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is GatewayStack Governance?

GatewayStack Governance provides an essential security layer for Openclaw Skills by enforcing strict tool-call policies at the process level. By utilizing a deny-by-default architecture, this skill ensures that agents cannot bypass security checks, effectively preventing unauthorized actions and prompt injection attacks. It offers a comprehensive suite of protective measures, including identity mapping and detailed audit trails, making it a critical component for production-grade AI agent deployments.

This framework acts as a technical firewall, ensuring that every interaction between the agent and its available tools is scrutinized. By hooking directly into the process lifecycle, it provides a level of security that cannot be negotiated or talked around by the underlying LLM, establishing a hard boundary for autonomous operations.

GatewayStack Governance Use Cases

  • Preventing unauthorized tool execution by restricting agent access through strict identity and scope allowlists.
  • Detecting and blocking malicious prompt injection attempts using a library of over 40 research-backed patterns.
  • Managing resource consumption with per-user and per-session sliding window rate limits.
  • Maintaining a permanent, append-only audit trail of every tool call and security decision for compliance.
  • Protecting sensitive data by scanning tool outputs for PII and redacting information before it reaches the agent.

How GatewayStack Governance Works

  1. The skill attaches to the before_tool_call hook at the system level to ensure complete coverage for Openclaw Skills.
  2. It performs an Identity check to correlate the calling agent with a specific governance role.
  3. A Scope check verifies if the requested tool exists on the strict allowlist defined in the policy.
  4. Rate limiting logic evaluates the call against current usage windows to prevent abuse or runaway processes.
  5. The call content is analyzed for injection patterns sourced from Cisco, Snyk, and Kaspersky research.
  6. All findings are logged to an append-only JSONL file, and the call is either authorized or blocked based on the policy result.

GatewayStack Governance Setup

To begin securing your environment, install the plugin using the Openclaw CLI:

openclaw plugins install @gatewaystack/gatewaystack-governance

The five core checks are active immediately upon installation. To customize the governance rules and define your own security roles, copy the example policy file:

cp ~/.openclaw/plugins/gatewaystack-governance/policy.example.json \
   ~/.openclaw/plugins/gatewaystack-governance/policy.json

For advanced features like DLP or behavioral monitoring, install the optional GatewayStack dependencies:

npm install @gatewaystack/transformabl-core
npm install @gatewaystack/limitabl-core

GatewayStack Governance Data Schema & Taxonomy

The governance system manages security via structured files and internal patterns to provide transparency for Openclaw Skills:

Component Description File Type
Policy Configuration Defines roles, tools, and security thresholds policy.json
Audit Logs A chronological, append-only record of all tool interactions .jsonl
Identity Map Maps specific agent IDs to security profiles JSON
Injection Patterns 40+ regex-based signatures for threat detection Internal
DLP Signatures Patterns used for PII detection and redaction Internal

GatewayStack Governance Advanced Features

  • Hardened process-level hooks that prevent agents from bypassing security constraints through prompt manipulation.
  • Opt-in Output DLP (Data Loss Prevention) to scan and redact sensitive information from tool responses using transformabl-core.
  • Behavioral monitoring powered by limitabl-core to detect anomalous usage patterns and potential agent compromise.
  • Human-in-the-loop escalation workflows that require manual review for high-risk actions or first-time tool usage.
  • Zero-dependency core logic ensuring that the fundamental security checks remain lightweight and high-performance.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Requires
Bins node
Github Stars: 0
forks: 0

Featured*