Skip to content
Back to skills

Governance Guard

ASecurity

Structural authority separation for autonomous agent actions. Three-phase governance pipeline: PROPOSE, DECIDE, PROMOTE. No action is both proposed and approved by the same computational pathway.

  • 14 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 7, 2026
ai-agentsgobashnode

Security analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned September 7, 2026

npx -y skills add modbender/skill-library-mcp --skill governance-guard --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Governance Guard?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Governance Guard
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/modbender-governance-guard/badge)](https://www.skillsdirectory.com/skills/modbender-governance-guard)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: governance-guard
description: >
  Structural authority separation for autonomous agent actions.
  Three-phase governance pipeline: PROPOSE, DECIDE, PROMOTE.
  No action is both proposed and approved by the same computational pathway.
version: 0.1.0
metadata:
  author: MetaCortex Dynamics LLC
  license: MIT
  openclaw:
    requires:
      bins:
        - node
        - npx
    install:
      - kind: node
        package: tsx
        bins: [tsx]
---

# governance-guard

Governance guard enforces structural authority separation on all agent actions through a PROPOSE-DECIDE-PROMOTE pipeline.

## When to activate

Before performing any **write**, **execute**, **network**, **create**, or **delete** action. The governance pipeline MUST be invoked before the action executes. Read actions may also be governed under standard or strict policies.

## How to use

### 1. Full pipeline (recommended)

Run the complete PROPOSE → DECIDE → PROMOTE pipeline in a single call:

```bash
npx tsx scripts/governance.ts pipeline '<intent-json>' --policy policies/standard.yaml
```

The intent JSON must include:
- `skill`: skill identifier
- `tool`: tool/function being invoked
- `model`: LLM model name
- `actionType`: one of `read`, `write`, `execute`, `network`, `create`, `delete`
- `target`: resource being acted upon
- `parameters`: tool parameters (object)
- `dataScope`: data categories accessed (array, e.g. `["personal", "financial"]`)
- `conversationId`: current conversation ID
- `messageId`: current message ID
- `userInstruction`: the user message that triggered this action

### 2. Handle the verdict

The pipeline returns a JSON response:

- If `"governance": "approved"` — proceed with the action
- If `"governance": "deny"` — do NOT proceed; inform the user with the `reason`
- If `"governance": "escalate"` — present the action to the user for approval:

```
Action requires your approval:
  Skill: <skill>
  Action: <actionType> on <target>
  Reason: <reason>
Reply APPROVE or DENY
```

Then resolve:

```bash
npx tsx scripts/governance.ts resolve-escalation <intent-id> approve
# or
npx tsx scripts/governance.ts resolve-escalation <intent-id> deny
```

### 3. Audit decisions

```bash
npx tsx scripts/governance.ts audit --last 10
```

## Policy presets

| Preset | Default | Description |
|--------|---------|-------------|
| `minimal` | approve | Blocks only credentials and destructive commands. Lowest friction. |
| `standard` | deny | Allows common ops, escalates network and data access. Recommended. |
| `strict` | deny | Reads only. Everything else requires explicit approval. Maximum safety. |

## Fail-closed guarantee

If any error occurs during governance evaluation, the default verdict is **DENY**. Missing policy files result in DENY ALL. This is by design. The system fails safe, never open.

## Configuration

Governance data is stored in `~/.openclaw/governance/`:
- `policy.yaml` — active policy file
- `witness.jsonl` — append-only, hash-chained audit log

## Verify witness chain

```bash
npx tsx scripts/governance.ts verify
```

Any tampering with historical records is detected by recomputing the hash chain from genesis.

Files in this skill

  • README.md2.9 KB
  • SKILL.md3.2 KB
  • package-lock.json17.9 KB
  • package.json578 B
  • policies/minimal.yaml681 B
  • policies/standard.yaml1.8 KB
  • policies/strict.yaml1.3 KB
  • references/policy-schema.md3 KB
  • scripts/governance.ts13.7 KB
  • scripts/intent.ts7.2 KB
  • scripts/policy-engine.ts8.3 KB
  • scripts/witness.ts6.8 KB
  • scripts/yaml-parse.ts10 KB
  • tests/fixtures/invalid-policy.yaml51 B
  • tests/fixtures/valid-policy.yaml375 B
  • tests/governance.test.ts15.4 KB
  • tests/intent.test.ts5.8 KB
  • tests/policy-engine.test.ts12.3 KB
  • tests/witness.test.ts8.3 KB
  • tests/yaml-parse.test.ts5.4 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…