Gatewaystack Governance
/install gatewaystack-governance
GatewayStack Governance
Deny-by-default governance for every tool call in OpenClaw.
Five core checks run automatically on every invocation:
- Identity — maps the agent to a policy role. Unknown agents are denied.
- Scope — deny-by-default tool allowlist. Unlisted tools are blocked.
- Rate limiting — per-user and per-session sliding window limits.
- Injection detection — 40+ patterns from Cisco, Snyk, and Kaspersky research.
- Audit logging — every decision recorded to append-only JSONL.
Three opt-in features extend governance further:
- Output DLP — scans tool output for PII using
@gatewaystack/transformabl-core. Log or redact. - Escalation — human-in-the-loop review for medium-severity detections and first-time tool use.
- Behavioral monitoring — detects anomalous tool usage patterns using
@gatewaystack/limitabl-core.
Install
openclaw plugins install @gatewaystack/gatewaystack-governance
One command. Zero config. The core 5 checks are active on every tool call immediately.
The plugin hooks into before_tool_call at the process level — the agent can't bypass it, skip it, or talk its way around it.
Customize
To override the defaults, create a policy file:
cp ~/.openclaw/plugins/gatewaystack-governance/policy.example.json \
~/.openclaw/plugins/gatewaystack-governance/policy.json
Configure which tools are allowed, who can use them, rate limits, injection detection sensitivity, and the three optional features (DLP, escalation, behavioral monitoring — all disabled by default).
Optional GatewayStack packages
The opt-in features use GatewayStack packages via lazy import. Install only what you need:
npm install @gatewaystack/transformabl-core # for output DLP
npm install @gatewaystack/limitabl-core # for behavioral monitoring
The core 5 checks have zero external dependencies and work without these packages.
Links
- Make sure OpenClaw is installed (local or Docker)
- Run the install command in chat:
/install gatewaystack-governance - After installation, invoke the skill by name or use
/gatewaystack-governance - Provide required inputs per the skill's parameter spec and get structured output
What is Gatewaystack Governance?
Deny-by-default governance for every tool call — identity, scope, rate limiting, injection detection, audit logging, plus opt-in output DLP, escalation, and... It is an AI Agent Skill for Claude Code / OpenClaw, with 757 downloads so far.
How do I install Gatewaystack Governance?
Run "/install gatewaystack-governance" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.
Is Gatewaystack Governance free?
Yes, Gatewaystack Governance is completely free (open-source). You can download, install and use it at no cost.
Which platforms does Gatewaystack Governance support?
Gatewaystack Governance is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).
Who created Gatewaystack Governance?
It is built and maintained by David Crowe (@davidcrowe); the current version is v0.2.0.