# Compliance Policy

> Respect domain allow/deny rules, credit limits, and secret handling.

- **Type:** Skill
- **Install:** `agentstack add skill-zenrows-cli-compliance-policy`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [ZenRows](https://agentstack.voostack.com/s/zenrows)
- **Installs:** 0
- **Category:** [AI & ML](https://agentstack.voostack.com/c/ai-and-ml)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [ZenRows](https://github.com/ZenRows)
- **Source:** https://github.com/ZenRows/cli/tree/main/skills/compliance-policy
- **Website:** https://docs.zenrows.com/cli/introduction

## Install

```sh
agentstack add skill-zenrows-cli-compliance-policy
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Compliance & policy

Every cloud call is checked against `.zenrows/policy.json` before it runs.

## Policy knobs
```
zenrows policy show
zenrows policy set max_credits_per_run 5000
zenrows policy set blocked_domains "example.com,foo.test"
zenrows policy set allowed_domains "mysite.com"      # non-empty = allow-list mode
zenrows policy set allow_browser false               # opt OUT of browser (on by default)
zenrows policy set allow_experimental true
```

## Hard rules
- **Never** print or commit API keys. Keys live in `.zenrows/secrets.json`
  (0600, gitignored) and are redacted from logs and run artifacts.
- Respect `allowed_domains` / `blocked_domains` — enforced by the CLI (→ `POLICY_BLOCKED_DOMAIN`).
- `max_credits_per_run` / `max_pages_per_run` / `max_concurrency` are **advisory budgets** surfaced by `zenrows status` (not hard-enforced by the CLI today) — self-limit against them.
- Confirm destructive `uninstall` with `--yes`.
- **Experimental** commands are off by default (`allow_experimental`). **Browser is on by default** (opt out with `allow_browser=false`).

See [[cost-control]] and [[trace-debug]].

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [ZenRows](https://github.com/ZenRows)
- **Source:** [ZenRows/cli](https://github.com/ZenRows/cli)
- **License:** MIT
- **Homepage:** https://docs.zenrows.com/cli/introduction

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-zenrows-cli-compliance-policy
- Seller: https://agentstack.voostack.com/s/zenrows
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
