Best for
- policy / rule / guardrail / govern / gate / control requests
- block / restrict / deny / disable / disallow an action, model, app, URL, agent, flow, or process
- require / enforce / mandate a behavior or rule
UiPath/skills/skills/uipath-governance/SKILL.md
UiPath governance via `uip gov` — author, deploy, and diagnose policies on three layers. AOps product policies (`uip gov aops-policy`): block/restrict/enforce features in Studio, StudioX, Assistant, Robot, AI Trust Layer, Agent Builder; deploy to user/group/tenant. Access ToolUsePolicy (`uip gov access-policy`): allow/deny when one workflow invokes another as a tool (Agent→Agent/Maestro/Flow/RPA/API/Case), gated by tag, caller, or actor (User/Group). Compliance Standards (ISO 42001): check postu
Decision brief
Uber skill for UiPath governance authoring. Two backing CLI surfaces:
Compatibility matrix
| Platform | Status | Evidence | What to check |
|---|---|---|---|
| Codex | Not declared | No explicit evidence | Portability before use |
| Claude Code | Not declared | No explicit evidence | Portability before use |
| Cursor | Not declared | No explicit evidence | Portability before use |
| Gemini CLI | Not declared | No explicit evidence | Portability before use |
Installation
The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.
npx skills add https://github.com/UiPath/skills --skill "skills/uipath-governance"Inspect the Agent Skill "uipath-governance" from https://github.com/UiPath/skills/blob/33e76a6b8f19e29d6af48adb9799d602c196c3cb/skills/uipath-governance/SKILL.md at commit 33e76a6b8f19e29d6af48adb9799d602c196c3cb. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.
Workflow
1. Classify the intent silently — never announce routing to the user. Internal flow labels (AOps / Access / Compliance standard) are implementation details; the user sees only the outcome. Read references/disambiguation-guide.md — it lists the strong signals for each flow, the p…
Activate on any governance / policy / rule intent — even when the user did not name the underlying CLI:
Sibling redirects: - Platform ops (auth, Orchestrator resources, packaging, deploy) → uipath-platform - Authoring agents / workflows / RPA themselves → uipath-agents / uipath-rpa / uipath-maestro-flow
1. Classify before authoring. First action on any governance request is to classify intent into Branch A (AOps) or Branch B (Access). Use the priors in references/disambiguation-guide.md. Never start create / update / delete until classification is settled — by user wording or b…
When the user's intent fits both branches, render exactly this numbered list (no AskUserQuestion, no table) and wait for a digit reply:
Permission review
The documentation asks the agent to run terminal commands or scripts.
**Never apply, restore, or remove compliance settings without user confirmation.** For apply: run posture analysis first, show the plan (summary + detail). In every case: ask, then END YOUR REPLY — never run the mutating command in the sameThe documentation asks the agent to run terminal commands or scripts.
**Classify the intent silently — never announce routing to the user.** Internal flow labels (AOps / Access / Compliance standard) are implementation details; the user sees only the outcome. Read [`references/disambiguation-guide.md`](./refeEvidence record
| Signal | Value | Evidence type | Meaning |
|---|---|---|---|
| Quality score | 96/100 | Computed | Documentation, specificity, maintenance, and trust rules |
| Repository stars | 149 | Source | Repository attention, not individual Skill quality |
| Compatibility | 0 platforms | Source | Declared in the catalog source record |
| Usage guide | automated source guide | Editorial | Generated or reviewed according to the visible evidence level |
Pinned source
Uber skill for UiPath governance authoring. Two backing CLI surfaces:
| Surface | Governs | CLI |
|---|---|---|
| AOps product policy | Product feature behavior — what Studio / StudioX / Assistant / Robot / AI Trust Layer / Agent Builder can do at design-time / runtime | uip gov aops-policy |
Access policy (ToolUsePolicy) | Resource/tool-use boundary — when an Actor Process invokes a child Resource (Agent / Maestro / Flow / RPA / API / Case Management), is the call allowed? | uip gov access-policy |
Both surfaces share verbs (block, restrict, deny, allow, require, enforce). The same English sentence often maps to either layer, so this skill classifies first and only then routes to the matching mechanic.
Activate on any governance / policy / rule intent — even when the user did not name the underlying CLI:
policy / rule / guardrail / govern / gate / control requestsblock / restrict / deny / disable / disallow an action, model, app, URL, agent, flow, or processrequire / enforce / mandate a behavior or ruleallow only / permit only / limit to / restrict to Xwho can / which … can / on behalf of — actor- or identity-shaped governancecompliance / posture / audit framing on top of policies.uipolicy file path, compliance standard, apply standardISO 42001check compliance, compliance posture, posture against, drift checkis my tenant compliant, am I compliant withorganization-wide, all tenants, entire org, across all tenants — org-scope full applyaccess-policy evaluate)Sibling redirects:
uipath-platformuipath-agents / uipath-rpa / uipath-maestro-flowreferences/disambiguation-guide.md. Never start create / update / delete until classification is settled — by user wording or by the disambiguation question.y in the user's next message. The user's original request is intent, not consent. Sole exception: the user explicitly waived confirmation in advance (e.g., "don't ask for confirmation") — treat the waiver as y.uip gov compliance-packs … call returning HTTP 403 / Forbidden, stop immediately (do not retry, run no further compliance commands) and tell the user the feature requires enrolling in the preview program. Exact wording + placement in references/compliance-pack/preview-gate.md. A 403 is preview-not-enabled; a 401 is a normal login failure — do NOT conflate them.uip login before any uip gov … command. evaluate (Access) additionally requires tenant-scoped login — see access-policy-overview-guide.md § Critical Rules.references/disambiguation-guide.md — it lists the strong signals for each flow, the phrase patterns that need disambiguation, and the canonical worked example. If a strong signal matches, route silently. If the phrasing is ambiguous (matches AOps or Access), ask the disambiguation question and wait for a digit reply. If the user replies with anything other than 1 or 2, treat it as a re-statement of intent and re-classify. Do not run any CLI command before classification is settled — the disambiguation question itself does not need uip, and an unrelated request (platform ops, agent authoring) must redirect to a sibling skill before any setup happens here. If the request contains a standard name (ISO 42001), apply standard, compliance posture, drift check, am I compliant, is my tenant compliant, what packs are available, what packs are configured, which standards are enabled, organization-wide, disable standard, or reset / restore / undo drift on a standard → route silently to the appropriate compliance standard plugin. Read partial-apply/planning.md for scoped requests; coverage/impl.md for posture checks; catalog/impl.md for discovery; query/impl.md for information queries; full-apply/impl.md after confirming the posture plan; disable/impl.md for removal; restore/impl.md for resetting a configured standard back to its recommended settings; catalog/impl.md + state list for listing currently configured packs.uip and login (only after classification routes to a governance flow).
which uip && uip --version
uip login status --output json
If not installed: npm install -g @uipath/cli. If not logged in: uip login (--authority <URL> for non-prod). For Access evaluate, login MUST be tenant-scoped.
If logged in to the wrong tenant within the same org — use the fast path: uip login tenant list --output json then uip login tenant set <NAME>. Full re-login only needed for a different org or authority. See references/auth-context.md § Switching tenants.references/aops-policy/aops-policy-overview-guide.mdreferences/access-policy/access-policy-overview-guide.mdWhen the user's intent fits both branches, render exactly this numbered list (no AskUserQuestion, no table) and wait for a digit reply:
### Which layer should this rule govern?
1. **Govern the product** — control what Studio / StudioX / Assistant / Robot / AI Trust Layer / Agent Builder *can do* (e.g. block ChatGPT inside Studio, enforce Workflow Analyzer, disable a Marketplace widget). Backed by `uip gov aops-policy`.
2. **Govern resource/tool use** — control which Actor Processes / identities can *invoke* which child Resource as a tool (e.g. block agents tagged `Sandbox` from being called, only let the finance group trigger this Flow). Backed by `uip gov access-policy`.
Reply with the number.
The canonical ambiguous prompt is "Block ChatGPT for my finance team using Studio." See references/disambiguation-guide.md for the worked-out reasoning of why both interpretations produce a working but different artifact.
| I need to... | Read |
|---|---|
| Decide which branch a request belongs to (priors, phrase tables, worked example) | references/disambiguation-guide.md |
| Author an AOps product policy | references/aops-policy/aops-policy-overview-guide.md |
| Deploy an AOps policy to user / group / tenant | references/aops-policy/aops-policy-deploy-guide.md |
| Query the deployed AOps policy / effective rules | references/aops-policy/aops-policy-deployed-guide.md |
| Author an Access ToolUsePolicy | references/access-policy/access-policy-overview-guide.md |
| Look up CLI flags / output shapes (AOps) | references/aops-policy/aops-policy-commands.md |
| Look up CLI flags / output shapes (Access) | references/access-policy/access-policy-commands.md |
| Resolve a name to a UUID for Access | references/access-policy/resource-lookup-guide.md |
| Diagnose a governance failure (capability index) | references/diagnose/CAPABILITY.md |
| Recognize a known governance failure pattern | references/diagnose/references/failure-modes.md |
| Walk the diagnostic priority ladder | references/diagnose/references/troubleshooting-guide.md |
| Discover available compliance standards | references/compliance-pack/catalog/impl.md |
| List which compliance standards are currently configured | references/compliance-pack/catalog/impl.md — use state list tenant <id> |
| Posture analysis — what settings are configured vs recommended | references/compliance-pack/coverage/impl.md |
| Apply full compliance pack | Run coverage first, then references/compliance-pack/full-apply/impl.md |
| Apply specific controls / clauses | references/compliance-pack/partial-apply/planning.md |
| Remove compliance standard settings | references/compliance-pack/disable/impl.md |
| Reset / restore a standard to its recommended settings (undo drift) | references/compliance-pack/restore/impl.md |
| Query — what does a clause / control recommend? | uip gov compliance-packs catalog get <packId> --output json (e.g. iso-42001-2023), then references/compliance-pack/query/impl.md |
| Preview disclaimer + 403 opt-in gate (all compliance flows) | references/compliance-pack/preview-gate.md |
uipath-platform.deployed-policy list for gap detection — it returns all rules in priority order, not the merged effective value. Use deployed-policy get <licenseType> <productName> <tenantId> to get the single effective merged policy.uip gov compliance-packs state coverage — do NOT use aops-policy deployed-policy commands; those are for AOps policy debugging (Branch A), not compliance pack flows.state enable — do NOT manually call aops-policy create for each product; that path is only for partial/scoped configuration.synthesize-formdata.mjs + aops-policy create — do NOT call state enable; state enable applies the FULL standard and cannot be scoped to specific clauses or products.state enable organization — the backend does not implement org-scope enable. Instead: list tenants with uip login tenant list, then call state enable tenant <id> for each tenant individually. See references/compliance-pack/full-apply/impl.md § Org-scope deployment.Frequently asked questions
Uber skill for UiPath governance authoring. Two backing CLI surfaces:
The source record exposes this install command: npx skills add https://github.com/UiPath/skills --skill "skills/uipath-governance". Inspect the command and pinned source before running it.
Static rules flagged exec-script in the source; the page lists the matching lines and excerpts.
Alternatives
vasilyu1983/AI-Agents-public
Guides iOS testing with XCTest, XCUITest, Swift Testing, simctl, and xcresult. Use when choosing destinations, controlling flakes, or parsing test artifacts for native apps.
garrytan/gbrain
Generate a publication-quality PDF from any brain page via the gstack make-pdf binary. Strips YAML frontmatter, sanitizes emoji, applies running headers and page numbers. Brain page is always the source of truth; PDF is a rendering.
NVIDIA/skills
How to swap the DeepStream CV detection model in the VSS Alerts Blueprint verification (2d_cv) mode - covers ONNX export, custom bbox parsers, compose mount gotchas, nvinfer config, runtime TRT engine build, deployment, and a segmentation-capable model addendum handoff.
vasilyu1983/AI-Agents-public
Scans public GitHub repos for agent skills, dev practices, and code patterns. Use when enriching skills, setting team policy, or researching a build domain.