Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Data Governance Framework
v1.0.0Evaluate and improve your organization's data governance across six domains by scoring controls, identifying risks, and prioritizing remediation actions.
⭐ 0· 591·1 current·1 all-time
by@1kalin
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Name and description match the SKILL.md: a 6-domain governance assessment with scoring and remediation. There are no unrelated required env vars, binaries, or config paths that would be inconsistent with a governance framework.
Instruction Scope
Runtime instructions are limited to asking the user which domains to assess, scoring 48 controls, computing metrics, and producing remediation roadmaps. The SKILL.md does not instruct reading system files, scanning environment variables, or sending data to external endpoints.
Install Mechanism
No install spec and no code files — lowest-risk posture (instruction-only). Nothing is downloaded or written to disk by the skill itself.
Credentials
The skill declares no required environment variables, credentials, or config paths. It does discuss handling sensitive data conceptually (PII, provenance) but does not request secrets or external tokens.
Persistence & Privilege
Flags are default (always:false, user-invocable:true, model invocation allowed). The skill does not request permanent presence or attempt to modify other skills or system-wide settings.
Assessment
This skill is a content/template-style governance framework and appears coherent with its description. Because it is instruction-only, it will not itself exfiltrate data or install code — however, be cautious about sharing actual organizational data or secrets when using it. If you plan to let an autonomous agent use this skill, restrict the agent's access to connectors that contain sensitive PII or credentials unless you explicitly approve that data be used. Also note README links to external AfrexAI pages (context packs, paid content) — those are optional resources outside the skill and should be reviewed separately before following or purchasing.Like a lobster shell, security has layers — review code before you run it.
AI governancevk97dg7fck3sgd4xx2rqyt0g7d181hdbvGDPRvk97dg7fck3sgd4xx2rqyt0g7d181hdbvcompliancevk97dg7fck3sgd4xx2rqyt0g7d181hdbvdata governancevk97dg7fck3sgd4xx2rqyt0g7d181hdbvdata qualityvk97dg7fck3sgd4xx2rqyt0g7d181hdbvlatestvk97dg7fck3sgd4xx2rqyt0g7d181hdbv
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
