← 返回 Skills 市场
krishnakumarmahadevan-cmd

Compliance Management

作者 ToolWeb · GitHub ↗ · v1.0.0 · MIT-0
cross-platform ⚠ suspicious
113
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install toolweb-compliance-management
功能描述
Multi-framework compliance assessment and management system for evaluating organizational adherence to security and regulatory standards.
安全使用建议
This skill describes a remote Compliance Management API but provides no server URL, no authentication requirements, and no source/homepage. Before installing or using it: (1) Ask the publisher for the API base URL, auth method (API key/OAuth), and hosting domain; do not supply sensitive org data until you confirm the destination and TLS/ownership. (2) Prefer skills that declare required env vars (API_KEY, BASE_URL) and list a trusted source or homepage. (3) If you must test it, do so with non-sensitive, synthetic data in a sandbox. (4) If the agent ever asks to send real configuration or credentials to an unspecified endpoint, deny and investigate — that is the primary risk here.
功能分析
Type: OpenClaw Skill Name: toolweb-compliance-management Version: 1.0.0 The skill provides a legitimate interface for a compliance management platform hosted at api.mkkpro.com, allowing users to perform assessments against frameworks like ISO 27001 and NIST CSF. The files (SKILL.md, openapi.json) describe standard API interactions for submitting organizational profiles and control responses to receive gap analyses. No indicators of data exfiltration, malicious execution, or prompt injection were found.
能力评估
Purpose & Capability
The SKILL.md and openapi.json present a networked Compliance Management API (endpoints for assessments, frameworks, controls). A networked API integration normally requires a base URL and authentication (API key, token, or similar). This skill declares no required environment variables, no server URL, and no install or hosting details — which is inconsistent with the stated purpose of acting as an external API client or wrapper.
Instruction Scope
The runtime instructions and examples are scoped to submitting assessment payloads and returning assessment results. They do not instruct the agent to read unrelated local files, scan system configuration, or exfiltrate other data. No instructions request unrelated environmental context.
Install Mechanism
This is an instruction-only skill with no install spec and no code files executed on the host. That reduces disk-execution risk. The included openapi.json is a spec file only and contains no server entries.
Credentials
A multi-framework API normally needs credentials and a target server. The skill requests no environment variables, no primary credential, and no config paths. That absence is disproportionate to an API integration and leaves unclear where requests would be sent and what auth (if any) would be used. The missing credential requirements are a notable gap.
Persistence & Privilege
The skill is not marked always:true and does not request persistent system-wide configuration or privileges. It appears to be an on-demand, user-invocable instruction-only skill.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install toolweb-compliance-management
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /toolweb-compliance-management 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Compliance Management Platform — Initial Release - Launches a multi-framework compliance assessment and management API supporting ISO 27001, NIST CSF, SOC 2, and more. - Enables organizations to centralize compliance evaluations, manage control responses, and generate compliance reports. - Provides endpoints for executing assessments, retrieving framework/control metadata, and accessing comprehensive gap analysis. - Includes robust request structure with support for organization profiles, detailed control evidence, and session tracking. - Offers multiple pricing plans, including Free, Developer, Professional, and Enterprise tiers.
元数据
Slug toolweb-compliance-management
版本 1.0.0
许可证 MIT-0
累计安装 0
当前安装数 0
历史版本数 1
常见问题

Compliance Management 是什么?

Multi-framework compliance assessment and management system for evaluating organizational adherence to security and regulatory standards. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 113 次。

如何安装 Compliance Management?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install toolweb-compliance-management」即可一键安装,无需额外配置。

Compliance Management 是免费的吗?

是的,Compliance Management 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

Compliance Management 支持哪些平台?

Compliance Management 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Compliance Management?

由 ToolWeb(@krishnakumarmahadevan-cmd)开发并维护,当前版本 v1.0.0。

💬 留言讨论