A security auditing tool that identifies AI skills gradually claiming broader permissions through subtle, incremental version updates.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install capability-scope-expansion-watcher
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install capability-scope-expansion-watcher using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
The Capability Scope Expansion Watcher is a specialized security utility designed for the Openclaw Skills ecosystem to combat the slow-drift attack pattern. This pattern occurs when a skill incrementally expands its capability scope through small, individually plausible updates that eventually accumulate into a significantly expanded attack surface. While a single update might seem harmless, the cumulative effect can transform a simple read-only tool into a high-risk exfiltration path.
By analyzing the entire version history of a skill, this watcher identifies the transition from declared intent to an actual capability footprint that no single update made obvious. It provides developers and auditors with the visibility needed to maintain trust in their Openclaw Skills by detecting silent scope expansions and risk-class contradictions that traditional point-in-time scanners often miss.
To use this tool within your environment, ensure you have the necessary binary dependencies. This utility is designed to integrate seamlessly with other Openclaw Skills for automated security auditing.
# Check for required dependencies
python3 --version
curl --version
# Run the watcher on a specific skill
openclaw capability-scope-expansion-watcher --id [SKILL_ID] --range v1.0..v1.5
The watcher organizes its analysis into a structured report that tracks the lifecycle of permissions and risk metadata.
| Attribute | Description |
|---|---|
| Per-version Delta | The specific permission changes (declared vs. observed) for every update. |
| Cumulative Scope | The total aggregate expansion since the skill's initial release. |
| Step-size Analysis | Evaluation of the pattern and frequency of scope changes. |
| Composition Points | Identification of versions where multiple permissions combined to create new risks. |
| Expansion Verdict | The final security classification (STABLE, DRIFT, or SCOPE-CAPTURE). |
Loading
A security analysis tool that uncovers hidden, emergent capabilities created when multiple AI agent skills are combined into a single agent.

A security analysis tool that identifies dangerous emergent behaviors created by the combination of individually safe agent skills.

A powerful security utility designed to map and project the potential damage of a malicious update within an agent skill dependency graph.

A security monitoring tool that detects AI agent skills that maintain safe behavior during initial audits but shift to malicious patterns after multiple runs or specific triggers.

A specialized tool for detecting coordinated clone campaigns and reputation gaming in AI agent marketplaces.

A security-focused auditor that identifies transparency gaps in skill updates by verifying machine-readable deltas and chain-of-custody records.








































