{"_id":"@ellistevo/openclaw-compliance","name":"@ellistevo/openclaw-compliance","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@ellistevo/openclaw-compliance","version":"1.0.0","description":"Static compliance auditor for codebases. Flags SOC2, GDPR, HIPAA, and security issues with professional HTML reports.","main":"src/index.js","bin":{"compliance-audit":"bin/cli.js"},"type":"module","scripts":{"test":"node --test test/index.test.js"},"keywords":["compliance","security","SOC2","GDPR","HIPAA","audit","scanner","openclaw"],"author":{"name":"Steve Ellis","email":"ellistevo@gmail.com"},"license":"MIT","engines":{"node":">=18"},"dependencies":{"glob":"^11.0.0","chalk":"^5.3.0","commander":"^12.0.0"},"gitHead":"22dbacfe9302b81235375615585caba8f35b9db7","_id":"@ellistevo/openclaw-compliance@1.0.0","_nodeVersion":"24.13.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-/r2dFusWC5ZmZVJEIGUObtaiWOHyRHWEH+vskk66MgXha+wDwHE9TKjnDbnPEUl8qKqH3D16i38Wg7w+lMMJNA==","shasum":"c1ab3860f3eedda887abd55f9c3f404e0d9905f5","tarball":"https://registry.npmjs.org/@ellistevo/openclaw-compliance/-/openclaw-compliance-1.0.0.tgz","fileCount":7,"unpackedSize":26704,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCfiPaci6ryAsUooSNAdN7AVyL82crcKDXkD6j+D61g1QIhALG/O6xoeCm2stIPbyzc6//NFIxjRl7hgJEdFg4pN3S7"}]},"_npmUser":{"name":"ellistevo","email":"steven.peter.elliott@gmail.com"},"directories":{},"maintainers":[{"name":"ellistevo","email":"steven.peter.elliott@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/openclaw-compliance_1.0.0_1770519779653_0.3137990230398213"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-08T03:02:59.549Z","1.0.0":"2026-02-08T03:02:59.808Z","modified":"2026-02-08T03:03:00.030Z"},"maintainers":[{"name":"ellistevo","email":"steven.peter.elliott@gmail.com"}],"description":"Static compliance auditor for codebases. Flags SOC2, GDPR, HIPAA, and security issues with professional HTML reports.","keywords":["compliance","security","SOC2","GDPR","HIPAA","audit","scanner","openclaw"],"author":{"name":"Steve Ellis","email":"ellistevo@gmail.com"},"license":"MIT","readme":"# 🛡️ @ellistevo/openclaw-compliance\n\nStatic compliance auditor for codebases. Scans for **SOC2**, **GDPR**, and **HIPAA** issues — hardcoded secrets, PII logging, SQL injection, missing encryption, and more. Generates professional HTML reports ready for auditor review.\n\n## Install\n\n```bash\nnpm install -g @ellistevo/openclaw-compliance\n```\n\n## CLI Usage\n\n```bash\n# Scan current directory for all frameworks\ncompliance-audit\n\n# Scan a specific directory\ncompliance-audit /path/to/project\n\n# Only SOC2 + GDPR, output HTML report\ncompliance-audit ./src -f SOC2,GDPR -o report.html\n\n# JSON output for CI/CD pipelines\ncompliance-audit . --json\n\n# Only high/critical findings\ncompliance-audit . -s high\n```\n\n### Options\n\n| Flag | Description | Default |\n|------|-------------|---------|\n| `-f, --frameworks` | Comma-separated: SOC2, GDPR, HIPAA | `SOC2,GDPR,HIPAA` |\n| `-s, --severity` | Minimum severity: critical, high, medium, low, info | `info` |\n| `-o, --output` | Write HTML report to file | — |\n| `--json` | JSON output | `false` |\n\n### Exit Codes\n\n| Code | Meaning |\n|------|---------|\n| 0 | No issues |\n| 1 | Issues found (no criticals) |\n| 2 | Critical issues found |\n\n## Programmatic Usage\n\n```javascript\nimport { scan, generateHTML } from '@ellistevo/openclaw-compliance';\n\nconst result = await scan('/path/to/project', {\n  frameworks: ['SOC2', 'GDPR'],\n  severity: 'high',\n});\n\nconsole.log(`Found ${result.stats.totalFindings} issues`);\n\n// Generate HTML report\nconst html = generateHTML(result);\n```\n\n## What It Detects\n\n### 🔐 Secrets & Credentials (SEC-001 → SEC-003)\n- Hardcoded API keys (AWS, Google, GitHub, Stripe, Slack)\n- Embedded passwords and private keys\n- Database connection strings with credentials\n\n### 🔑 Authentication (AUTH-001 → AUTH-002)\n- Route handlers without auth middleware\n- Disabled security headers (CSP, CORS wildcards)\n\n### 🔒 Encryption (ENC-001 → ENC-002)\n- HTTP URLs instead of HTTPS\n- Weak cryptographic algorithms (MD5, SHA1, DES)\n\n### 💉 Injection (INJ-001 → INJ-002)\n- SQL injection via string concatenation/template literals\n- Command injection via dynamic shell execution\n\n### 👤 PII & Privacy (PII-001 → PII-002)\n- Logging PII/PHI to console or files\n- Storing sensitive fields without encryption\n\n### 🇪🇺 GDPR (GDPR-001 → GDPR-003)\n- Data collection without consent patterns\n- Missing right-to-erasure / data deletion endpoints\n- No privacy policy references\n\n### 🏥 HIPAA (HIPAA-001 → HIPAA-002)\n- PHI access without role-based access control\n- Missing audit trail/logging\n\n### ⚙️ Infrastructure (INFRA-001 → INFRA-003)\n- Debug mode enabled\n- Missing rate limiting\n- No input validation\n\n## CI/CD Integration\n\n```yaml\n# GitHub Actions\n- name: Compliance Audit\n  run: npx @ellistevo/openclaw-compliance . --json -s high -o compliance-report.html\n\n- name: Upload Report\n  uses: actions/upload-artifact@v4\n  with:\n    name: compliance-report\n    path: compliance-report.html\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md","_rev":"1-e2ef4048cc217cd18c12fe937a6d7e5c"}