| name | governance-policies |
| description | Set up governance policies for OpenClaw — block dangerous commands, detect PII, prevent data exfiltration, protect agent config files. Use when hardening an OpenClaw deployment with AxonFlow. |
| homepage | https://github.com/getaxonflow/axonflow-openclaw-plugin/tree/main/policies |
| tags | security, governance, pii, compliance, openclaw, audit |
AxonFlow Governance Policies for OpenClaw
Use when setting up or hardening an OpenClaw deployment with AxonFlow governance. This skill covers self-hosting AxonFlow, plugin installation, policy configuration, and risk mitigation.
Self-Host AxonFlow
AxonFlow runs locally via Docker Compose. No LLM provider keys required — OpenClaw handles all LLM calls, AxonFlow only enforces policies and records audit trails.
Prerequisites: Docker Engine or Desktop, Docker Compose v2, 4 GB RAM, 10 GB disk.
Quick start: Clone the AxonFlow community repo, copy .env.example to .env, and run docker compose up -d. The Agent starts on port 8080 — all SDK and plugin traffic goes through this port.
Full setup instructions: Self-Hosted Deployment Guide
Install the Plugin
Install via OpenClaw's plugin manager and configure in your OpenClaw config with your AxonFlow endpoint, credentials, and high-risk tool list. Set onError: block for production (fail-closed) or allow for development (fail-open).
In community mode, clientId and clientSecret default to "community" — no credentials needed for the local developer flow. In enterprise mode, provide OAuth2 Client Credentials (Basic auth). The tenantId config field has been removed — tenant is derived server-side from credentials.
Full configuration reference: OpenClaw Integration Guide
What's Protected Automatically
AxonFlow's 80+ built-in system policies apply with no additional setup:
- Dangerous command blocking: Reverse shells,
rm -rf /, curl|bash, cloud metadata SSRF, credential file access, path traversal (10 policies)
- SQL injection: 30+ detection patterns including UNION injection, stacked queries, auth bypass
- PII detection and redaction: SSN, credit card, email, phone, Aadhaar, PAN, NRIC/FIN (Singapore)
- Code security: API keys, connection strings, hardcoded secrets, unsafe code patterns
- Prompt injection: Ignore-instruction patterns, jailbreak attempts, role hijacking
OpenClaw-Specific Hardening
For additional protection against OpenClaw-specific attack vectors, the plugin repository includes ready-to-use policy templates covering:
- Command execution blocking: Reverse shells, destructive filesystem operations, credential file access
- SSRF prevention: Cloud metadata endpoints, internal network addresses
- Agent config protection: Block writes to SOUL.md, MEMORY.md, and other identity files
- Path traversal detection: Workspace escape patterns
Full policy templates with SQL examples: Starter Policies
Top 10 Risks
| Rank | Risk | Hook |
|---|
| 1 | Arbitrary command execution | before_tool_call |
| 2 | Data exfiltration via HTTP | before_tool_call |
| 3 | PII leakage in messages | message_sending |
| 4 | Indirect prompt injection | before_tool_call |
| 5 | Outbound secret exfiltration | message_sending |
| 6 | Malicious skill supply chain | after_tool_call (audit) |
| 7 | Memory/context poisoning | before_tool_call |
| 8 | Credential exposure | message_sending |
| 9 | Cross-tenant leakage | Tenant-scoped policies |
| 10 | Workspace boundary bypass | before_tool_call |
Guardrails
- All policies are evaluated server-side by AxonFlow, not locally.
- High-risk tools require human approval only after AxonFlow allows the tool call. If AxonFlow blocks the tool, it stays blocked.
- The plugin verifies AxonFlow connectivity on startup.
Learn More
Get Started
Policies & Security
Governance & Compliance
Platform & Examples
Source Code
Licensing
- AxonFlow platform (getaxonflow/axonflow): BSL 1.1 (Business Source License). Source-available, not open source.
- @axonflow/openclaw plugin (getaxonflow/axonflow-openclaw-plugin): MIT. Free to use, modify, and redistribute.
- This skill: MIT-0 per ClawHub terms.