| name | governance-policies |
| description | Set up governance policies for OpenClaw — block dangerous commands, detect PII, prevent data exfiltration, protect agent config files. Use when hardening an OpenClaw deployment with AxonFlow. |
| homepage | https://github.com/getaxonflow/axonflow-openclaw-plugin/tree/main/policies |
| tags | security, governance, pii, compliance, openclaw, audit |
AxonFlow Governance Policies for OpenClaw
Use when setting up or hardening an OpenClaw deployment with AxonFlow governance. This skill covers self-hosting AxonFlow, plugin installation, policy configuration, and risk mitigation.
AxonFlow is self-hosted. It runs on your infrastructure via Docker Compose. All policy evaluation, PII detection, and audit logging happens on your own AxonFlow instance. Credentials are only needed for enterprise mode — community mode requires no auth. An anonymous startup ping (version and basic deployment info) is sent by default for local, self-hosted, and remote deployments. Opt out globally with DO_NOT_TRACK=1 or AXONFLOW_TELEMETRY=off.
Self-Host AxonFlow
AxonFlow runs locally via Docker Compose. No LLM provider keys required — OpenClaw handles all LLM calls, AxonFlow only enforces policies and records audit trails.
Prerequisites: Docker Engine or Desktop, Docker Compose v2, 4 GB RAM, 10 GB disk.
Quick start: Clone the AxonFlow community repo, copy .env.example to .env, and run docker compose up -d. The Agent starts on port 8080 — all SDK and plugin traffic goes through this port.
Full setup instructions: Self-Hosted Deployment Guide
Install the Plugin
Recommended:
openclaw plugins install @axonflow/openclaw
The clawhub:@axonflow/openclaw form also works.
Requires OpenClaw 2026.4.14 or later. If you are not on the latest, upgrade with npm install -g openclaw@latest.
Note on the package name: the npm package is @axonflow/openclaw, not @axonflow/openclaw-plugin. The repo name differs from the package name.
On an older OpenClaw CLI? The old workaround is still needed. Versions before 2026.4.14 had a bug (openclaw/openclaw#66618) that made scoped packages fail with ENOENT .../@axonflow/openclaw.zip — both forms of the install command hit it. Fixed upstream in 2026.4.14. If you cannot upgrade, install from npm directly:
TGZ=$(npm pack @axonflow/openclaw 2>/dev/null | tail -1)
openclaw plugins install "./$TGZ"
Configure in your OpenClaw config with your AxonFlow endpoint, credentials, high-risk tool list, and optional requestTimeoutMs override. Set onError: block for production (fail-closed) or allow for development (fail-open). Increase requestTimeoutMs above the default 8000ms when AxonFlow is running remotely or behind a slow VPN.
In community mode, clientId and clientSecret default to "community" — no credentials needed for the local developer flow. In enterprise mode, provide OAuth2 Client Credentials (Basic auth). The tenantId config field has been removed — tenant is derived server-side from credentials.
Full configuration reference: OpenClaw Integration Guide
What's Protected Automatically
AxonFlow's 80+ built-in system policies apply with no additional setup:
- Dangerous command blocking — 10 policies covering destructive operations, remote code execution, credential access, cloud metadata, path traversal
- SQL injection — 30+ detection patterns covering advanced injection techniques
- PII detection and redaction — SSN, credit card, email, phone, Aadhaar, PAN, NRIC/FIN (Singapore)
- Code security — API keys, connection strings, hardcoded secrets, unsafe code patterns
- Prompt manipulation — instruction override and context manipulation attempts
Examples of blocked patterns (all evaluated server-side by AxonFlow):
rm -rf / → blocked by sys_dangerous_destructive_fs
curl ... | sh → blocked by sys_dangerous_shell_download
nc -e /bin/bash → blocked by sys_dangerous_reverse_shell
169.254.169.254 → blocked by sys_dangerous_cloud_metadata
cat ~/.ssh/id_rsa → blocked by sys_dangerous_credential_access
../../etc/passwd → blocked by sys_dangerous_path_traversal
OpenClaw-Specific Hardening
For additional protection against OpenClaw-specific attack vectors, the plugin repository includes ready-to-use policy templates:
Command execution → reverse shells, destructive filesystem ops, credential file access
SSRF prevention → cloud metadata endpoints, internal network addresses
Agent config → SOUL.md, MEMORY.md, identity file write protection
Path traversal → workspace escape patterns
Full policy templates with SQL examples: Starter Policies
Top 10 Risks
| Rank | Risk | Hook |
|---|
| 1 | Arbitrary command execution | before_tool_call |
| 2 | Data exfiltration via HTTP | before_tool_call |
| 3 | PII leakage in messages | message_sending |
| 4 | Indirect prompt injection | before_tool_call |
| 5 | Outbound secret exfiltration | message_sending |
| 6 | Malicious skill supply chain | after_tool_call (audit) |
| 7 | Memory/context poisoning | before_tool_call |
| 8 | Credential exposure | message_sending |
| 9 | Cross-tenant leakage | Tenant-scoped policies |
| 10 | Workspace boundary bypass | before_tool_call |
Guardrails
- All policies are evaluated server-side by AxonFlow, not locally.
- High-risk tools require human approval only after AxonFlow allows the tool call. If AxonFlow blocks the tool, it stays blocked.
- The plugin verifies AxonFlow connectivity on startup.
Learn More
Get Started
Policies & Security
Governance & Compliance
Platform & Examples
Source Code
Licensing
- AxonFlow platform (getaxonflow/axonflow): BSL 1.1 (Business Source License). Source-available, not open source.
- @axonflow/openclaw plugin (getaxonflow/axonflow-openclaw-plugin): MIT. Free to use, modify, and redistribute.
- This skill: MIT-0 per ClawHub terms.