Capability Graph Mapper for Openclaw

A security analysis tool that uncovers hidden, emergent capabilities created when multiple AI agent skills are combined into a single agent.

andyxinweiminicloud
v1.0.0
Feb 22, 2026
1
1.5k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install capability-graph-mapper

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install capability-graph-mapper using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Capability Graph Mapper?

The Capability Graph Mapper is a sophisticated security utility designed to analyze the composite permission surface of your AI agent. While individual skills might appear safe in isolation—such as a simple file reader or a JSON parser—their combination can often create unintended emergent capabilities that bypass traditional security reviews. This tool helps developers audit their Openclaw Skills to ensure that disparate functionalities do not inadvertently form a data exfiltration pipeline or an unauthorized shell execution path.

By tracing dependency chains and identifying pairwise compositions, the mapper provides a transparent view of the true power granted to an autonomous agent. It serves as a necessary audit layer for anyone building complex automation workflows, ensuring that every combination of Openclaw Skills is accounted for and safe for production deployment.

Capability Graph Mapper Use Cases

  • Auditing a new agent's skill set before deployment to identify hidden security risks.
  • Performing delta analysis when adding a new skill to see how it changes the overall privilege surface.
  • Identifying dangerous three-hop transitive chains where data is read, transformed, and then exfiltrated.
  • Generating a privilege surface score to quantify the risk level of various Openclaw Skills combinations.

How Capability Graph Mapper Works

  1. Extract declared capabilities such as file access, network requests, and shell execution from each skill manifest.
  2. Perform pairwise composition analysis to check if combining any two skills creates a new, high-risk capability.
  3. Trace transitive chains across three or more hops to find invisible paths between data sources and external sinks.
  4. Calculate a Privilege Surface Score (0-100) based on the density of dangerous capability combinations.
  5. Generate a comprehensive report including a permission matrix and actionable security recommendations for your Openclaw Skills.

Capability Graph Mapper Setup

To begin mapping your agent capabilities, ensure you have the necessary dependencies installed.

sudo apt update && sudo apt install curl python3

Once dependencies are met, you can run the mapper against your local skill manifests or a list of Openclaw Skills slugs.

# Example: Analyze a specific list of skills
capability-graph-mapper --skills log-analyzer,http-poster,env-reader

Capability Graph Mapper Data Schema & Taxonomy

The mapper organizes its analysis into a structured report that highlights the relationship between different Openclaw Skills.

Component Description
Permission Matrix A table mapping specific skills to their atomic capabilities (read, write, exec).
Risk Identifiers Flagged combinations (e.g., RISK 1: Data Exfiltration) with severity levels.
Surface Score A numerical metric (0-100) representing the overall risk density of the skill set.
Delta Report A comparison view showing the risk impact of adding a new skill to an existing set.

Capability Graph Mapper Advanced Features

  • Automated delta analysis for CI/CD pipelines to block risky Openclaw Skills updates before they are merged.
  • Integration with impact estimators to quantify the blast radius of a potential skill compromise.
  • Customizable risk pattern libraries to detect novel or domain-specific attack chains unique to your environment.
  • Multi-agent profile comparison to ensure consistent security policies across different deployments of Openclaw Skills.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*