compliance-auditor

PassAudited by VirusTotal on May 8, 2026.

Overview

Type: OpenClaw Skill Name: ah-compliance-auditor Version: 1.0.0 The skill bundle consists of a metadata file and a comprehensive Markdown instruction set (SKILL.md) designed to guide an AI agent in performing compliance audits (GDPR, SOC2, HIPAA, etc.). There is no executable code, network activity, or evidence of malicious intent; the content is entirely focused on providing templates, checklists, and reporting structures for regulatory analysis.

Findings (0)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

If users paste real personal, health, or payment-card details, that information may appear in the conversation and audit output.

Why it was flagged

The skill is meant to support compliance audits involving sensitive personal, health, and payment-card data. This is purpose-aligned, and the artifacts do not show persistence or exfiltration, but users may place sensitive data into chat context or generated reports.

Skill content
Data Types: [PII, PHI, PCI, etc.]
Recommendation

Use redacted examples, schemas, control descriptions, or summaries where possible, and avoid sharing unnecessary raw regulated data.

What this means

Users could over-rely on generated compliance guidance as if it were an official audit or legal opinion.

Why it was flagged

This is an authority-style claim that may increase user trust. It does not show deception or unsafe behavior, but the artifacts do not establish certification, affiliation, or legal authority.

Skill content
using proven patterns from production AI systems (Oracle, IBM Watson Governance)
Recommendation

Treat outputs as draft checklists or analysis aids and have qualified legal, privacy, or compliance professionals review decisions.