Generated note: shared plugin assets for this package live at the plugin root. Common local references were rewritten when they appeared in backticks or markdown links.
AuditClaw GRC
AI-native GRC assistant for OpenClaw. Manages compliance frameworks, controls, evidence, risks, policies, vendors, incidents, assets, training, vulnerabilities, access reviews, and questionnaires.
97 actions | 30 tables | 13 frameworks | 990+ controls
Security Model
- Database: SQLite at
~/.openclaw/grc/compliance.sqlite with WAL mode, owner-only permissions (0o600)
- Credentials: Stored in
~/.openclaw/grc/credentials/ with per-provider directories, owner-only permissions (0o700 dirs, 0o600 files), atomic writes, and secure deletion (overwrite with random bytes before removal). Secrets are never logged or exposed in output. See ../../scripts/credential_store.py for implementation.
- Trust center: Generates a local HTML file only. Nothing is published externally. The user decides where to host it.
- Dependencies:
requests==2.31.0 (pinned) for HTTP header scanning. Cloud integrations optionally use boto3 (AWS) and PyJWT (Azure) via try/except -- these are not required and only activate if installed and credentials are configured.
- Scans: All security scans (headers, SSL, GDPR) run locally against user-specified URLs only.
- No telemetry: No data is sent to external endpoints. All operations are local or to user-configured cloud accounts only.
Optional Environment Variables (for cloud integrations)
These are not required for core GRC functionality. They are only used when the user explicitly sets up cloud provider integrations via companion skills:
| Variable |
Used by |
AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY |
AWS integration (via auditclaw-aws) |
GITHUB_TOKEN |
GitHub integration (via auditclaw-github) |
AZURE_SUBSCRIPTION_ID / AZURE_CLIENT_ID / AZURE_CLIENT_SECRET / AZURE_TENANT_ID |
Azure integration (via auditclaw-azure) |
GCP_PROJECT_ID / GOOGLE_APPLICATION_CREDENTIALS |
GCP integration (via auditclaw-gcp) |
GOOGLE_WORKSPACE_SA_KEY / GOOGLE_WORKSPACE_ADMIN_EMAIL |
Google Workspace (via auditclaw-idp) |
OKTA_ORG_URL / OKTA_API_TOKEN |
Okta (via auditclaw-idp) |
Setup
python3 {baseDir}/scripts/init_db.py
pip install -r {baseDir}/scripts/requirements.txt
Database: ~/.openclaw/grc/compliance.sqlite
Voice and Formatting
- Present data as formatted summaries, not raw JSON
- Keep messages under 4096 chars. Show top 5-10 rows, offer "Want the full list?"
- Emoji: ✅ complete, ⚠️ at-risk, 🔴 critical, 📊 scores, 📋 reports, 🔒 security
- Include context: "23/43 controls complete (53%)" not just "23"
- After each action, suggest the next logical step
Activation Triggers
Activate on: compliance, GRC, SOC 2, ISO 27001, HIPAA, GDPR, NIST, PCI DSS, CIS, CMMC, HITRUST, CCPA, FedRAMP, ISO 42001, SOX, ITGC, controls, evidence, risks, audit, gap analysis, security posture, compliance score, framework, security scan.
Database Operations
All queries go through: python3 {baseDir}/scripts/db_query.py --action <action> [args]
Output is JSON. Parse and present as human-readable summaries. For full action reference with all arguments: {baseDir}/references/db-actions.md
Core Actions
| Action |
Purpose |
status |
Overall compliance overview |
activate-framework --slug soc2 |
Load framework controls |
gap-analysis --framework soc2 |
Gaps with priority and effort |
score-history --framework soc2 |
Score trend over time |
list-controls --framework soc2 --status in_progress |
Filtered controls |
update-control --id 5 --status complete |
Update control (also batch: --id 1,2,3) |
add-evidence --title "..." --control-ids 1,2,3 |
Record evidence |
add-risk --title "..." --likelihood 3 --impact 4 |
Log a risk |
add-vendor --name "..." --criticality high |
Register vendor |
add-incident --title "..." --severity critical |
Log incident |
generate-report --framework soc2 |
HTML compliance report |
generate-dashboard |
Dashboard summary + Canvas HTML |
export-evidence --framework soc2 |
ZIP package for auditors |
list-companions |
Show installed companion skills |
Additional Action Categories
- Policies: add, version, submit approval, review, require acknowledgment
- Training: add modules, assign, track completion, list overdue
- Vulnerabilities: add with CVE/CVSS, track remediation
- Access Reviews: create campaigns, add items, approve/revoke
- Questionnaires: create templates, send to vendors, record answers, score
- Incidents: add actions (timeline), post-incident reviews, summary with MTTR
- Assets: register with classification, lifecycle, encryption/backup/patch status
- Alerts: add, list, acknowledge, resolve
- Integrations: add provider, test connection, setup guide, show policy
Framework Activation
Run: python3 {baseDir}/scripts/db_query.py --action activate-framework --slug <slug>
| Framework |
Slug |
Controls |
| SOC 2 Type II |
soc2 |
43 |
| ISO 27001:2022 |
iso27001 |
114 |
| HIPAA Security Rule |
hipaa |
29 |
| GDPR |
gdpr |
25 |
| NIST CSF |
nist-csf |
31 |
| PCI DSS v4.0 |
pci-dss |
30 |
| CIS Controls v8 |
cis-controls |
153 |
| CMMC 2.0 |
cmmc |
113 |
| HITRUST CSF v11 |
hitrust |
152 |
| CCPA/CPRA |
ccpa |
28 |
| FedRAMP Moderate |
fedramp |
282 |
| ISO 42001:2023 |
iso42001 |
40 |
| SOX ITGC |
sox-itgc |
50 |
Framework reference docs: {baseDir}/references/frameworks/
Compliance Score
Run: python3 {baseDir}/scripts/compliance_score.py [--framework <slug>] [--store]
Returns score (0-100), health distribution, trend, and drift detection. Use --store to save for tracking. Methodology: {baseDir}/references/scoring-methodology.md
Security Scanning
- Headers:
python3 {baseDir}/scripts/check_headers.py --url <url> (CSP, HSTS, X-Frame-Options, etc.)
- SSL/TLS:
python3 {baseDir}/scripts/check_ssl.py --domain <domain> (cert validity, chain, cipher)
- GDPR: Browser-based cookie consent check (requires Chromium)
After scans, offer to save results as evidence.
Reports and Exports
- Report:
python3 {baseDir}/scripts/generate_report.py --framework <slug> --format html
- Trust center:
python3 {baseDir}/scripts/generate_trust_center.py [--org-name "Acme Corp"] (local HTML only)
- Evidence export:
python3 {baseDir}/scripts/export_evidence.py --framework <slug>
Interactive Flows
First-Time Setup
When user asks to set up compliance: initialize DB silently, present framework options with control counts and use cases, offer gap analysis after activation.
Smart Defaults
- Evidence type: infer from context (manual/automated/integration)
- Risk assessment: suggest likelihood/impact with reasoning, confirm before saving
- Bulk operations: list exactly what will change, confirm, report summary
Proactive Suggestions
After framework activation -> offer gap analysis and cloud integration setup.
After marking controls complete -> offer score recalculation.
After scanning -> offer to save as evidence.
After scoring (< 30%) -> prioritize critical controls. (>= 90%) -> offer audit report.
Slash Commands
| Command |
Action |
/grc-score |
Quick compliance score |
/grc-gaps |
Priority gaps |
/grc-scan |
Security scan menu |
/grc-report |
Generate report |
/grc-risks |
Risk register |
/grc-incidents |
Active incidents |
/grc-trust |
Generate trust center |
Scheduled Alerts (Cron)
Register via OpenClaw cron tool:
- Evidence expiry: daily 7 AM
- Score recalc: every 6 hours
- Weekly digest: Monday 8 AM
Always include "Using auditclaw-grc skill" in cron messages for routing.
Companion Skills
Optional add-ons for automated cloud evidence collection. Evidence flows into the shared GRC database.
| Skill |
Checks |
Setup |
| auditclaw-aws |
15 AWS checks (S3, IAM, CloudTrail, VPC, etc.) |
aws configure with read-only IAM policy |
| auditclaw-github |
9 GitHub checks (branch protection, secrets, 2FA, etc.) |
GITHUB_TOKEN env var |
| auditclaw-azure |
12 Azure checks (storage, NSG, Key Vault, etc.) |
Service principal with Reader + Security Reader |
| auditclaw-gcp |
12 GCP checks (storage, firewall, IAM, etc.) |
GOOGLE_APPLICATION_CREDENTIALS with Viewer + Security Reviewer |
| auditclaw-idp |
8 identity checks (Google Workspace + Okta) |
SA key + admin email / Okta API token |
Install: clawhub install auditclaw-<provider>
If a user asks to connect a cloud provider, check list-companions first. If not installed, guide them to install it.
Integration Setup
Say "setup aws", "setup github", etc. to get step-by-step guides with exact permissions. Use "test aws connection" to verify before running scans.
Reference Files
{baseDir}/references/db-actions.md - Full action reference with all arguments
{baseDir}/references/schema.md - Database schema
{baseDir}/references/scoring-methodology.md - Scoring algorithm
{baseDir}/references/commands/ - Detailed command guides
{baseDir}/references/frameworks/ - Framework reference docs
{baseDir}/references/integrations/ - Cloud integration guides
1---2name: auditclaw-grc3description: AI-native GRC (Governance, Risk, and Compliance) for OpenClaw. 97 actions across 13 frameworks including SOC 2, ISO 27001, HIPAA, GDPR, NIST CSF, PCI DSS, CIS Controls, CMMC, HITRUST, CCPA, FedRAMP, ISO 42001, and SOX ITGC. Manages controls, evidence, risks, policies, vendors, incidents, assets, training, vulnerabilities, access reviews, and questionnaires. Generates compliance scores, reports, dashboards, and trust center pages. Runs security header, SSL, and GDPR scans. Connects to AWS, Azure, GCP, GitHub, and identity providers via companion skills.4---56> Generated note: shared plugin assets for this package live at the plugin root. Common local references were rewritten when they appeared in backticks or markdown links.78# AuditClaw GRC910AI-native GRC assistant for OpenClaw. Manages compliance frameworks, controls, evidence, risks, policies, vendors, incidents, assets, training, vulnerabilities, access reviews, and questionnaires.1112**97 actions | 30 tables | 13 frameworks | 990+ controls**1314## Security Model1516- **Database**: SQLite at `~/.openclaw/grc/compliance.sqlite` with WAL mode, owner-only permissions (0o600)17- **Credentials**: Stored in `~/.openclaw/grc/credentials/` with per-provider directories, owner-only permissions (0o700 dirs, 0o600 files), atomic writes, and secure deletion (overwrite with random bytes before removal). Secrets are never logged or exposed in output. See `../../scripts/credential_store.py` for implementation.18- **Trust center**: Generates a local HTML file only. Nothing is published externally. The user decides where to host it.19- **Dependencies**: `requests==2.31.0` (pinned) for HTTP header scanning. Cloud integrations optionally use `boto3` (AWS) and `PyJWT` (Azure) via try/except -- these are not required and only activate if installed and credentials are configured.20- **Scans**: All security scans (headers, SSL, GDPR) run locally against user-specified URLs only.21- **No telemetry**: No data is sent to external endpoints. All operations are local or to user-configured cloud accounts only.2223### Optional Environment Variables (for cloud integrations)2425These are **not required** for core GRC functionality. They are only used when the user explicitly sets up cloud provider integrations via companion skills:2627| Variable | Used by |28|----------|---------|29| `AWS_ACCESS_KEY_ID` / `AWS_SECRET_ACCESS_KEY` | AWS integration (via auditclaw-aws) |30| `GITHUB_TOKEN` | GitHub integration (via auditclaw-github) |31| `AZURE_SUBSCRIPTION_ID` / `AZURE_CLIENT_ID` / `AZURE_CLIENT_SECRET` / `AZURE_TENANT_ID` | Azure integration (via auditclaw-azure) |32| `GCP_PROJECT_ID` / `GOOGLE_APPLICATION_CREDENTIALS` | GCP integration (via auditclaw-gcp) |33| `GOOGLE_WORKSPACE_SA_KEY` / `GOOGLE_WORKSPACE_ADMIN_EMAIL` | Google Workspace (via auditclaw-idp) |34| `OKTA_ORG_URL` / `OKTA_API_TOKEN` | Okta (via auditclaw-idp) |3536## Setup3738```bash39python3 {baseDir}/scripts/init_db.py40pip install -r {baseDir}/scripts/requirements.txt41```4243Database: `~/.openclaw/grc/compliance.sqlite`4445## Voice and Formatting4647- Present data as formatted summaries, not raw JSON48- Keep messages under 4096 chars. Show top 5-10 rows, offer "Want the full list?"49- Emoji: ✅ complete, ⚠️ at-risk, 🔴 critical, 📊 scores, 📋 reports, 🔒 security50- Include context: "23/43 controls complete (53%)" not just "23"51- After each action, suggest the next logical step5253## Activation Triggers5455Activate on: compliance, GRC, SOC 2, ISO 27001, HIPAA, GDPR, NIST, PCI DSS, CIS, CMMC, HITRUST, CCPA, FedRAMP, ISO 42001, SOX, ITGC, controls, evidence, risks, audit, gap analysis, security posture, compliance score, framework, security scan.5657## Database Operations5859All queries go through: `python3 {baseDir}/scripts/db_query.py --action <action> [args]`6061Output is JSON. Parse and present as human-readable summaries. For full action reference with all arguments: `{baseDir}/references/db-actions.md`6263### Core Actions6465| Action | Purpose |66|--------|---------|67| `status` | Overall compliance overview |68| `activate-framework --slug soc2` | Load framework controls |69| `gap-analysis --framework soc2` | Gaps with priority and effort |70| `score-history --framework soc2` | Score trend over time |71| `list-controls --framework soc2 --status in_progress` | Filtered controls |72| `update-control --id 5 --status complete` | Update control (also batch: `--id 1,2,3`) |73| `add-evidence --title "..." --control-ids 1,2,3` | Record evidence |74| `add-risk --title "..." --likelihood 3 --impact 4` | Log a risk |75| `add-vendor --name "..." --criticality high` | Register vendor |76| `add-incident --title "..." --severity critical` | Log incident |77| `generate-report --framework soc2` | HTML compliance report |78| `generate-dashboard` | Dashboard summary + Canvas HTML |79| `export-evidence --framework soc2` | ZIP package for auditors |80| `list-companions` | Show installed companion skills |8182### Additional Action Categories8384- **Policies**: add, version, submit approval, review, require acknowledgment85- **Training**: add modules, assign, track completion, list overdue86- **Vulnerabilities**: add with CVE/CVSS, track remediation87- **Access Reviews**: create campaigns, add items, approve/revoke88- **Questionnaires**: create templates, send to vendors, record answers, score89- **Incidents**: add actions (timeline), post-incident reviews, summary with MTTR90- **Assets**: register with classification, lifecycle, encryption/backup/patch status91- **Alerts**: add, list, acknowledge, resolve92- **Integrations**: add provider, test connection, setup guide, show policy9394## Framework Activation9596Run: `python3 {baseDir}/scripts/db_query.py --action activate-framework --slug <slug>`9798| Framework | Slug | Controls |99|-----------|------|----------|100| SOC 2 Type II | soc2 | 43 |101| ISO 27001:2022 | iso27001 | 114 |102| HIPAA Security Rule | hipaa | 29 |103| GDPR | gdpr | 25 |104| NIST CSF | nist-csf | 31 |105| PCI DSS v4.0 | pci-dss | 30 |106| CIS Controls v8 | cis-controls | 153 |107| CMMC 2.0 | cmmc | 113 |108| HITRUST CSF v11 | hitrust | 152 |109| CCPA/CPRA | ccpa | 28 |110| FedRAMP Moderate | fedramp | 282 |111| ISO 42001:2023 | iso42001 | 40 |112| SOX ITGC | sox-itgc | 50 |113114Framework reference docs: `{baseDir}/references/frameworks/`115116## Compliance Score117118Run: `python3 {baseDir}/scripts/compliance_score.py [--framework <slug>] [--store]`119120Returns score (0-100), health distribution, trend, and drift detection. Use `--store` to save for tracking. Methodology: `{baseDir}/references/scoring-methodology.md`121122## Security Scanning123124- **Headers**: `python3 {baseDir}/scripts/check_headers.py --url <url>` (CSP, HSTS, X-Frame-Options, etc.)125- **SSL/TLS**: `python3 {baseDir}/scripts/check_ssl.py --domain <domain>` (cert validity, chain, cipher)126- **GDPR**: Browser-based cookie consent check (requires Chromium)127128After scans, offer to save results as evidence.129130## Reports and Exports131132- **Report**: `python3 {baseDir}/scripts/generate_report.py --framework <slug> --format html`133- **Trust center**: `python3 {baseDir}/scripts/generate_trust_center.py [--org-name "Acme Corp"]` (local HTML only)134- **Evidence export**: `python3 {baseDir}/scripts/export_evidence.py --framework <slug>`135136## Interactive Flows137138### First-Time Setup139When user asks to set up compliance: initialize DB silently, present framework options with control counts and use cases, offer gap analysis after activation.140141### Smart Defaults142- Evidence type: infer from context (manual/automated/integration)143- Risk assessment: suggest likelihood/impact with reasoning, confirm before saving144- Bulk operations: list exactly what will change, confirm, report summary145146### Proactive Suggestions147After framework activation -> offer gap analysis and cloud integration setup.148After marking controls complete -> offer score recalculation.149After scanning -> offer to save as evidence.150After scoring (< 30%) -> prioritize critical controls. (>= 90%) -> offer audit report.151152## Slash Commands153154| Command | Action |155|---------|--------|156| `/grc-score` | Quick compliance score |157| `/grc-gaps` | Priority gaps |158| `/grc-scan` | Security scan menu |159| `/grc-report` | Generate report |160| `/grc-risks` | Risk register |161| `/grc-incidents` | Active incidents |162| `/grc-trust` | Generate trust center |163164## Scheduled Alerts (Cron)165166Register via OpenClaw cron tool:167- Evidence expiry: daily 7 AM168- Score recalc: every 6 hours169- Weekly digest: Monday 8 AM170171Always include "Using auditclaw-grc skill" in cron messages for routing.172173## Companion Skills174175Optional add-ons for automated cloud evidence collection. Evidence flows into the shared GRC database.176177| Skill | Checks | Setup |178|-------|--------|-------|179| **auditclaw-aws** | 15 AWS checks (S3, IAM, CloudTrail, VPC, etc.) | `aws configure` with read-only IAM policy |180| **auditclaw-github** | 9 GitHub checks (branch protection, secrets, 2FA, etc.) | `GITHUB_TOKEN` env var |181| **auditclaw-azure** | 12 Azure checks (storage, NSG, Key Vault, etc.) | Service principal with Reader + Security Reader |182| **auditclaw-gcp** | 12 GCP checks (storage, firewall, IAM, etc.) | `GOOGLE_APPLICATION_CREDENTIALS` with Viewer + Security Reviewer |183| **auditclaw-idp** | 8 identity checks (Google Workspace + Okta) | SA key + admin email / Okta API token |184185Install: `clawhub install auditclaw-<provider>`186187If a user asks to connect a cloud provider, check `list-companions` first. If not installed, guide them to install it.188189### Integration Setup190191Say "setup aws", "setup github", etc. to get step-by-step guides with exact permissions. Use "test aws connection" to verify before running scans.192193## Reference Files194195- `{baseDir}/references/db-actions.md` - Full action reference with all arguments196- `{baseDir}/references/schema.md` - Database schema197- `{baseDir}/references/scoring-methodology.md` - Scoring algorithm198- `{baseDir}/references/commands/` - Detailed command guides199- `{baseDir}/references/frameworks/` - Framework reference docs200- `{baseDir}/references/integrations/` - Cloud integration guides