@vortiq-x-consilium/openclaw-governance
v1.3.1
Published
VORTIQ-X AI Governance — Physics-based security for OpenClaw agents. 93 engines, 23-stage orchestrator, court-grade evidence. Patent SE 2530558-2.
Downloads
1,891
Maintainers
Readme
@vortiqx/openclaw-governance
Physics-based AI governance for OpenClaw agents.
93 security engines · 23-stage orchestrator · 10 witnesses · Court-grade evidence chain
Patent SE 2530558-2 — VORTIQX Consilium FZCO
What it does
Every tool call your OpenClaw agent makes (shell commands, file reads, network requests, code execution) is scanned by VORTIQ-X before execution. If the action is dangerous — prompt injection, credential theft, reverse shell, ransomware, data exfiltration — it gets blocked. Safe actions pass through instantly.
Install
openclaw plugins install @vortiqx/openclaw-governanceConfigure
Add to your openclaw.json:
{
"plugins": {
"@vortiqx/openclaw-governance": {
"enabled": true,
"host": "https://openclawapi.vortiqxconsilium.com",
"agentId": "my-agent-01",
"mode": "enforce"
}
}
}Then restart:
openclaw gateway restartModes
| Mode | Behavior |
|------|----------|
| enforce | Blocks dangerous actions. Default. |
| monitor | Logs all actions but allows everything. |
| audit | Logs all actions, flags suspicious ones. |
What gets scanned
| Action | Covered | |--------|---------| | Shell commands | ✓ Reverse shells, data exfil, ransomware, privilege escalation | | File reads | ✓ SSH keys, credentials, .env files, system files | | File writes | ✓ Persistence mechanisms, cron jobs, startup modifications | | Network requests | ✓ C2 beacons, credential exfiltration, known bad domains | | Code execution | ✓ Prompt injection, identity hijack, payload obfuscation | | Memory writes | ✓ Memory poisoning, governance bypass, delayed triggers |
How it works
- Plugin injects governance rules at the system prompt level — the LLM reads these before any user content
- Before every tool call, the agent checks with VORTIQ-X
- VORTIQ-X runs 93 engines including physics-based detection, AEGIS anti-distillation, sovereignty checks, and the patented 23-stage governance orchestrator
- Verdict (allow/flag/block) is returned in <50ms
- Every decision is sealed in a SHA-384 evidence chain with RFC 3161 timestamps
Zero code exposure
This plugin is an API client. All intelligence stays on the VORTIQ-X server. No detection patterns, engine code, or patent-protected algorithms are included in this package.
Requirements
- OpenClaw 2026.3.0 or later
- Internet connection to reach the VORTIQ-X API
- Free account at https://vortiqxconsilium.com (or self-hosted VORTIQ-X server)
Links
License
MIT — the plugin is open source. The VORTIQ-X platform it connects to is proprietary.
