openclaw-pluginPrecision decisioning, agentic trust, and verifiable identity for autonomous agents
Install via ClawdBot CLI:
clawdbot install knuckles-stack/openclaw-pluginGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
POST → https://governance.taskhawktech.com/signupPotentially destructive shell commands in tool definitions
rm -rf /Calls external URL not in known-safe list
https://governance.taskhawktech.com`AI Analysis
The skill's external API calls are consistent with its stated purpose of cryptographic governance and decision verification. While it sends data to an external endpoint, this appears to be a legitimate service for the skill's functionality, not unauthorized exfiltration. No credential harvesting, hidden instructions, or obfuscation were detected in the provided definition.
Generated Sep 23, 2026
A platform engineering team routes every CI/CD deployment action through Kevros /governance/verify before execution, enforcing max replicas, forbidden commands, and change-window policy. CLAMP decisions auto-adjust unsafe parameters while DENY blocks risky releases. Release tokens are shared with downstream admission controllers for independent verification without callbacks.
A trading desk uses Kevros intent binding to cryptographically link declared trade intent (asset, size, strategy) to the actual order command before submission. Verify-outcome confirms achieved positions against goal state within tolerance. Attestations build a tamper-evident audit ledger for compliance and post-trade review.
Clinical automation agents bind intents for patient-data-touching tasks, then attest each completed action to a hash-chained ledger with raw data SHA-256 hashed and never stored. Compliance teams export monthly cryptographic bundles with PQC signatures and verification instructions for regulators, proving exactly what each agent did and why.
Logistics agents across carriers and brokers use Kevros to bind intents for rerouting and inventory moves, then attest outcomes to a shared provenance chain. Downstream partners independently verify release tokens and hash continuity to establish trust across organizational boundaries without a central authority.
SecOps agents gate remediation actions (isolate host, revoke key, patch) through policy checks before execution, clamping blast-radius parameters. Every action is signed and attested, so incident commanders can reconstruct the agent's decision trail and prove no unauthorized actions occurred during an incident.
Free tier grants 1,000 monthly governance calls per agent, with per-call pricing on premium endpoints like compliance bundles ($0.05/call). Revenue scales directly with agent autonomy adoption across an organization.
Sell seat/agent-based licenses to enterprises needing SOC2, HIPAA, or financial-regulatory audit capabilities, bundling unlimited attestations, intent chains, and PQC-signed compliance exports with SLA support.
Operate as the neutral trust root: charge downstream verifiers (admission controllers, auditors, partner systems) a transaction fee to independently validate release tokens and hash-chained provenance across organizational boundaries.
💬 Integration Tip
On every ALLOW/CLAMP response, persist the release_token, verification_id, and epoch immediately — downstream systems need them for independent verification, and losing them breaks the audit chain. Also compare the KEVROS_API_KEY env var against your agent_id and enforce policy_context client-side when possible to reduce DENY round-trips.
Scored Sep 23, 2026
Audited Apr 17, 2026 · audit v1.0
Meta-skill for AI agent self-improvement. Analyzes runtime logs to detect error patterns, regressions, and inefficiencies, then generates structured improvem...
Stop waiting for prompts. Keep working.
Turn OpenClaw into a learning-loop agent with seeded workspace rules, skill promotion, reflective memory, and proactive maintenance.
Meta-agent skill for orchestrating complex tasks through autonomous sub-agents. Decomposes macro tasks into subtasks, spawns specialized sub-agents with dynamically generated SKILL.md files, coordinates file-based communication, consolidates results, and dissolves agents upon completion. MANDATORY TRIGGERS: orchestrate, multi-agent, decompose task, spawn agents, sub-agents, parallel agents, agent coordination, task breakdown, meta-agent, agent factory, delegate tasks
Complete toolkit for creating autonomous AI agents and managing Discord channels for OpenClaw. Use when setting up multi-agent systems, creating new agents, or managing Discord channel organization.
Billions decentralized identity for agents. Link agents to human identities using Billions ERC-8004 and Attestation Registries. Verify and generate authentic...