A security analysis tool that uncovers hidden, emergent capabilities created when multiple AI agent skills are combined into a single agent.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install capability-graph-mapper
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install capability-graph-mapper using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
The Capability Graph Mapper is a sophisticated security utility designed to analyze the composite permission surface of your AI agent. While individual skills might appear safe in isolation—such as a simple file reader or a JSON parser—their combination can often create unintended emergent capabilities that bypass traditional security reviews. This tool helps developers audit their Openclaw Skills to ensure that disparate functionalities do not inadvertently form a data exfiltration pipeline or an unauthorized shell execution path.
By tracing dependency chains and identifying pairwise compositions, the mapper provides a transparent view of the true power granted to an autonomous agent. It serves as a necessary audit layer for anyone building complex automation workflows, ensuring that every combination of Openclaw Skills is accounted for and safe for production deployment.
To begin mapping your agent capabilities, ensure you have the necessary dependencies installed.
sudo apt update && sudo apt install curl python3
Once dependencies are met, you can run the mapper against your local skill manifests or a list of Openclaw Skills slugs.
# Example: Analyze a specific list of skills
capability-graph-mapper --skills log-analyzer,http-poster,env-reader
The mapper organizes its analysis into a structured report that highlights the relationship between different Openclaw Skills.
| Component | Description |
|---|---|
| Permission Matrix | A table mapping specific skills to their atomic capabilities (read, write, exec). |
| Risk Identifiers | Flagged combinations (e.g., RISK 1: Data Exfiltration) with severity levels. |
| Surface Score | A numerical metric (0-100) representing the overall risk density of the skill set. |
| Delta Report | A comparison view showing the risk impact of adding a new skill to an existing set. |
Loading
A security analysis tool that identifies dangerous emergent behaviors created by the combination of individually safe agent skills.

A powerful security utility designed to map and project the potential damage of a malicious update within an agent skill dependency graph.

A security monitoring tool that detects AI agent skills that maintain safe behavior during initial audits but shift to malicious patterns after multiple runs or specific triggers.

A diagnostic tool for Openclaw Skills that measures trust root concentration to prevent structural fragility in agent attestation graphs.

A security auditing tool that identifies AI skills gradually claiming broader permissions through subtle, incremental version updates.

A specialized tool for detecting coordinated clone campaigns and reputation gaming in AI agent marketplaces.








































