Token导航 LogoToken导航TokenDH.com
研究检索执行命令clawhub未标认证来源可访问clear审计通过

mova-compliance-auditMOVA 合规审计

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

5,214

周安装

213

GitHub Stars

公开资料未说明

下载量

1,670
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:mova-compliance-audit(MOVA 合规审计)
来源仓库:https://github.com/mova-compact/mova-compliance-audit
安装命令:
openclaw skills install mova-compliance-audit
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install mova-compliance-audit

简介

执行GDPR、PCI-DSS等合规性审计并支持人工复核。

  • 适用于企业信息安全与法规遵从检查。
  • 自动识别漏洞并提供修复建议清单。
  • 需上传待审文档与系统配置信息。mova-compliance-audit 属于研究检索类 Skill,可作为该场景下的辅助能力补充。
  • 不能将工具输出直接视为最终结论。

SKILL.md

name
mova-compliance-audit
description
Submit documents for AI-powered compliance audit against GDPR, PCI-DSS, ISO 27001, or SOC 2 via MOVA HITL. Trigger when the user uploads a document and mentions compliance, regulation, or audit, asks to validate against a regulatory framework, or says "check GDPR compliance", "run PCI-DSS audit", "validate ISO 27001". Human sign-off is mandatory before any audit report is finalized.
license
MIT-0
metadata
{"openclaw":{"plugin":{"name":"MOVA","installCmd":"openclaw plugins install openclaw-mova"},"dataSentToExternalServices":[{"service":"MOVA API (api.mova-lab.eu)","data":"document URL or ID, organization name, selected regulatory framework, AI findings, human decision, audit metadata"},{"service":"Document OCR connector (read-only)","data":"document content extracted for structure parsing and checklist evaluation"},{"service":"Compliance rules engine connector (read-only)","data":"document structure evaluated against framework-specific rule set"}]}}
Contract Skill — A ready-to-use MOVA HITL workflow. Requires the openclaw-mova plugin.

MOVA Compliance Audit

Submit an organization's documents to MOVA for automated regulatory compliance audit — with framework-specific rule matching, a structured findings report, and a mandatory human sign-off gate backed by a tamper-proof audit trail.

What it does

  1. Document ingestion — OCR extraction and structure parsing from uploaded file or URL
  2. Rules engine check — automated evaluation against the selected regulatory framework (GDPR, PCI-DSS, ISO 27001, SOC 2)
  3. Findings report — checklist with pass/fail items, severity codes, and recommended remediation actions
  4. Human gate — compliance officer reviews findings and chooses: approve / approve with conditions / reject / request corrections
  5. Audit receipt — every check, source, and decision is signed, timestamped, and stored in an immutable MOVA audit trail for regulatory inspection

Mandatory escalation rules enforced by policy:

  • Critical findings present → mandatory human review, cannot auto-approve
  • Regulated framework (GDPR, PCI-DSS) → full audit report artifact required
  • Rejection or conditions → remediation items must be recorded with reason

Requirements

Plugin: MOVA OpenClaw plugin must be installed in your OpenClaw workspace.

Data flows:

  • Document URL/ID + org metadata → api.mova-lab.eu (MOVA platform, EU-hosted)
  • Document content → OCR extraction connector (read-only, no data stored)
  • Extracted structure → compliance rules engine (framework-specific, read-only)
  • Audit journal → MOVA R2 storage, cryptographically signed
  • No data sent to third parties beyond the above

Demo

Step 1 — Document submitted for GDPR audit Step 1

Step 2 — AI findings: 3 critical violations, missing DPIA, reject recommended Step 2

Step 3 — Audit receipt + signed decision log Step 3

Quick start

Say "run GDPR compliance audit on this document" and provide a document URL or ID:

document_url: https://example.com/privacy-policy.pdf
framework: gdpr
org_name: Acme Corp

The agent submits the document, shows the AI findings checklist with pass/fail items and severity, then asks for your compliance decision.

Why contract execution matters

  • Framework rules are policy, not prompts — GDPR and PCI-DSS checks trigger mandatory gates that cannot be bypassed by the AI
  • Full checklist traceability — every pass/fail item is linked to a specific rule ID and source citation
  • Immutable audit trail — when a regulator asks "who signed off this audit and what did they see?" — the answer is in the system with an exact timestamp
  • EU AI Act / GDPR Article 22 ready — automated compliance decisions require human oversight, full explainability, and a documented decision chain

What the user receives

OutputDescription
FrameworkSelected regulatory standard (GDPR, PCI-DSS, ISO 27001, SOC 2)
Checklist scorePass / fail count per framework section
Critical findingsCount and list of critical violations
Findings listPer-item: rule ID, description, severity (critical / high / medium / low)
Remediation hintsRecommended corrective actions per finding
Recommended actionAI-suggested compliance decision
Decision optionsapprove / approve_with_conditions / reject / request_corrections
Audit receipt IDPermanent signed record of the compliance decision
Compact journalFull event log: ingest → rules check → human decision

When to trigger

Activate when the user:

  • Uploads a document and mentions compliance, regulation, or audit
  • Says "check GDPR compliance", "run PCI-DSS audit", "validate ISO 27001", "SOC 2 check"
  • Asks to prepare for a regulatory inspection

Before starting, confirm: "Run compliance audit on [document] — framework: [FRAMEWORK]?"

If framework is not specified — ask once: GDPR, PCI-DSS, ISO 27001, or SOC 2. If document URL is missing — ask once for a direct HTTPS link or document ID.

Step 1 — Submit document for audit

Call tool mova_hitl_start_compliance with:

  • document_url: direct HTTPS link to the document
  • document_id: unique identifier (e.g. DOC-2026-001)
  • framework: one of gdpr / pci_dss / iso_27001 / soc2
  • org_name: organization name

Step 2 — Show findings and decision options

If status = "waiting_human" — show the audit findings summary:

Document:   document_id
Framework:  FRAMEWORK
Score:      PASS_COUNT / TOTAL_CHECKS passed
Critical:   CRITICAL_COUNT critical findings
Findings:   [list top findings with rule ID and severity]
Recommended action: ACTION ← RECOMMENDED

Then ask compliance officer to choose:

OptionDescription
approveSign off audit report as compliant
approve_with_conditionsApprove with listed remediation items
rejectDocument fails compliance — block processing
request_correctionsReturn document for corrections

Call tool mova_hitl_decide with:

  • contract_id: from the response above — this is ctr-cau-xxxxxxxx, NOT the document ID
  • option: chosen decision
  • reason: officer reasoning (required for reject and request_corrections)

Step 3 — Show audit receipt

Call tool mova_hitl_audit with contract_id. Call tool mova_hitl_audit_compact with contract_id for the full signed event chain.

Connect your real compliance systems

By default MOVA uses a sandbox mock. To route checks against your live infrastructure, call mova_list_connectors with keyword: "compliance".

Relevant connectors:

Connector IDWhat it covers
connector.ocr.document_extract_v1Document OCR and structure extraction
connector.compliance.rules_engine_v1Framework-specific compliance rule evaluation

Call mova_register_connector with connector_id, endpoint, optional auth_header and auth_value.

Rules

  • NEVER make HTTP requests manually
  • NEVER invent or simulate compliance results — if a tool call fails, show the exact error
  • Use MOVA plugin tools directly — do NOT use exec or shell
  • CONTRACT_ID is ctr-cau-xxxxxxxx from the mova_hitl_start_compliance response — NOT the document ID

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

83.94%
按下载量换算1,402

安全审计

VirusTotal

通过

ClawScan

通过

Static analysis

通过

权限和风险

执行命令

安装流程涉及命令执行,可能通过 openclaw skills install mova-compliance-audit 联网下载 Skill 或依赖。用户安装前应确认命令来源、仓库内容和执行环境。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills