← 返回 Skills 市场
52yuanchangxing

Compliance Evidence Assembler

作者 vx:17605205782 · GitHub ↗ · v1.0.0 · MIT-0
darwinlinuxwin32 ✓ 安全检测通过
199
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install compliance-evidence-assembler
功能描述
把审计所需证据整理成目录、清单和缺失项,便于后续评审。;use for compliance, evidence, audit workflows;do not use for 伪造证据, 替代正式审计结论.
使用说明 (SKILL.md)

合规证据组装器

你是什么

你是“合规证据组装器”这个独立 Skill,负责:把审计所需证据整理成目录、清单和缺失项,便于后续评审。

Routing

适合使用的情况

  • 整理这次审计需要的证据包
  • 指出还缺什么
  • 输入通常包含:证据目录、控制项列表或说明
  • 优先产出:证据概览、控制映射、交付建议

不适合使用的情况

  • 不要伪造证据
  • 不要替代正式审计结论
  • 如果用户想直接执行外部系统写入、发送、删除、发布、变更配置,先明确边界,再只给审阅版内容或 dry-run 方案。

工作规则

  1. 先把用户提供的信息重组成任务书,再输出结构化结果。
  2. 缺信息时,优先显式列出“待确认项”,而不是直接编造。
  3. 默认先给“可审阅草案”,再给“可执行清单”。
  4. 遇到高风险、隐私、权限或合规问题,必须加上边界说明。
  5. 如运行环境允许 shell / exec,可使用:
    • python3 "{baseDir}/scripts/run.py" --input \x3C输入文件> --output \x3C输出文件>
  6. 如当前环境不能执行脚本,仍要基于 {baseDir}/resources/template.md{baseDir}/resources/spec.json 的结构直接产出文本。

标准输出结构

请尽量按以下结构组织结果:

  • 证据概览
  • 控制映射
  • 缺失证据
  • 命名建议
  • 补齐优先级
  • 交付建议

本地资源

  • 规范文件:{baseDir}/resources/spec.json
  • 输出模板:{baseDir}/resources/template.md
  • 示例输入输出:{baseDir}/examples/
  • 冒烟测试:{baseDir}/tests/smoke-test.md

安全边界

  • 只做证据编排和缺口提示。
  • 默认只读、可审计、可回滚。
  • 不执行高风险命令,不隐藏依赖,不伪造事实或结果。
安全使用建议
This skill appears coherent and local-only, but take these precautions before use: (1) Review scripts/run.py (it only reads local files and writes reports—no network calls) and run it in a safe/test directory first. (2) Do not point the tool at your root, home, or other dirs that may contain unrelated secrets or system files—the audit will read many filetypes. (3) Use --dry-run or run with sample/example-input.md to verify output format. (4) Keep sensitive inputs redacted before scanning. (5) If you will allow an autonomous agent to call this skill, ensure that its permission to select arbitrary filesystem paths is constrained; otherwise, restrict invocation or supervise runs. Overall the skill is consistent with its described purpose.
功能分析
Type: OpenClaw Skill Name: compliance-evidence-assembler Version: 1.0.0 The skill bundle is a legitimate tool designed for organizing compliance evidence and performing basic security audits on local directories. The primary script, `scripts/run.py`, functions as a read-only reporter that scans files for metadata, CSV structures, and specific security patterns (such as hardcoded secrets or dangerous shell commands) to assist in audit preparation. There is no evidence of data exfiltration, network activity, or malicious intent; in fact, the script includes logic to mask detected secrets and explicitly warns the AI agent against forging evidence or executing high-risk system changes in `SKILL.md`.
能力评估
Purpose & Capability
Name/description (evidence assembly, audit workflows) match the included resources and the Python script: spec.json declares mode 'directory_audit', SKILL.md documents reading templates/spec and producing structured output, and scripts/run.py implements directory/csv/pattern/skill audits. Required binaries (python3) are proportional.
Instruction Scope
SKILL.md and README limit the skill to read-only evidence assembly and dry-run outputs, which aligns with the script. The script will read arbitrary files under any directory the user supplies (and inspects .md, .py, .sh, .json, .csv, etc.), which is expected for a directory-audit tool but means users must avoid pointing it at system/home directories containing secrets or unrelated sensitive data.
Install Mechanism
No install spec; this is an instruction-first skill with a local Python script that depends only on the standard library. No remote downloads, package installs, or archive extraction are present.
Credentials
The skill requires no environment variables, no credentials, and no config paths. The lack of secrets or external service tokens is consistent with a local evidence-assembly utility.
Persistence & Privilege
always is false and the skill does not request persistent privileges. It does not modify other skills or system-wide agent settings. It may be invoked autonomously by the agent (default behavior), which is normal for skills.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install compliance-evidence-assembler
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /compliance-evidence-assembler 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial release of compliance-evidence-assembler. - Organizes audit evidence into catalogs, checklists, and identifies missing items for easier review. - Provides structured outputs: evidence overview, control mapping, missing evidence, naming suggestions, prioritization, and delivery recommendations. - Highlights boundaries: does not fabricate evidence or substitute formal audit conclusions. - Supports both draft and executable checklists, with clear handling of edge cases and missing information. - Designed for compliance, evidence management, and audit workflows; accessible from compatible environments.
元数据
Slug compliance-evidence-assembler
版本 1.0.0
许可证 MIT-0
累计安装 0
当前安装数 0
历史版本数 1
常见问题

Compliance Evidence Assembler 是什么?

把审计所需证据整理成目录、清单和缺失项,便于后续评审。;use for compliance, evidence, audit workflows;do not use for 伪造证据, 替代正式审计结论. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 199 次。

如何安装 Compliance Evidence Assembler?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install compliance-evidence-assembler」即可一键安装,无需额外配置。

Compliance Evidence Assembler 是免费的吗?

是的,Compliance Evidence Assembler 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

Compliance Evidence Assembler 支持哪些平台?

Compliance Evidence Assembler 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(darwin, linux, win32)。

谁开发了 Compliance Evidence Assembler?

由 vx:17605205782(@52yuanchangxing)开发并维护,当前版本 v1.0.0。

💬 留言讨论