Capability Scope Expansion Watcher for Openclaw

A security auditing tool that identifies AI skills gradually claiming broader permissions through subtle, incremental version updates.

andyxinweiminicloud
v1.1.0
Feb 25, 2026
0
1.4k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install capability-scope-expansion-watcher

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install capability-scope-expansion-watcher using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Capability Scope Expansion Watcher?

The Capability Scope Expansion Watcher is a specialized security utility designed for the Openclaw Skills ecosystem to combat the slow-drift attack pattern. This pattern occurs when a skill incrementally expands its capability scope through small, individually plausible updates that eventually accumulate into a significantly expanded attack surface. While a single update might seem harmless, the cumulative effect can transform a simple read-only tool into a high-risk exfiltration path.

By analyzing the entire version history of a skill, this watcher identifies the transition from declared intent to an actual capability footprint that no single update made obvious. It provides developers and auditors with the visibility needed to maintain trust in their Openclaw Skills by detecting silent scope expansions and risk-class contradictions that traditional point-in-time scanners often miss.

Capability Scope Expansion Watcher Use Cases

  • Tracing a skill's capability evolution across a specific version range to identify cumulative permission drift.
  • Identifying step-size anomalies where regular, small expansions suggest a planned incremental scope-capture strategy.
  • Auditing an agent's installed skill list to find which tools have drifted furthest from their initial security declarations.
  • Detecting capability composition amplification points where separate permissions combine to create dangerous new emergent behaviors.

How Capability Scope Expansion Watcher Works

  1. The user provides a skill identifier, a version range, or an installed skill list as the primary input.
  2. The watcher retrieves the historical metadata and capability declarations for every version within the specified scope.
  3. It computes the per-version permission delta, identifying both declared changes and silent expansions.
  4. It analyzes the step-size pattern to determine if the expansion frequency is consistent with genuine feature growth or suspicious drift.
  5. The tool evaluates the alignment between the skill's effective capability and its self-declared risk classification.
  6. A comprehensive report is generated, providing a verdict such as STABLE, DRIFT, INCREMENTAL-EXPANSION, or SCOPE-CAPTURE.

Capability Scope Expansion Watcher Setup

To use this tool within your environment, ensure you have the necessary binary dependencies. This utility is designed to integrate seamlessly with other Openclaw Skills for automated security auditing.

# Check for required dependencies
python3 --version
curl --version

# Run the watcher on a specific skill
openclaw capability-scope-expansion-watcher --id [SKILL_ID] --range v1.0..v1.5

Capability Scope Expansion Watcher Data Schema & Taxonomy

The watcher organizes its analysis into a structured report that tracks the lifecycle of permissions and risk metadata.

Attribute Description
Per-version Delta The specific permission changes (declared vs. observed) for every update.
Cumulative Scope The total aggregate expansion since the skill's initial release.
Step-size Analysis Evaluation of the pattern and frequency of scope changes.
Composition Points Identification of versions where multiple permissions combined to create new risks.
Expansion Verdict The final security classification (STABLE, DRIFT, or SCOPE-CAPTURE).

Capability Scope Expansion Watcher Advanced Features

  • Risk-class contradiction detection (v1.1) to find mismatches between self-declared risk levels and actual capability footprints.
  • Behavioral vs. declared scope alignment to detect when a skill's functions no longer match its stated purpose.
  • Changelog completeness auditing to flag versions that expand permissions without explicit disclosure.
  • Seamless cross-referencing with other Openclaw Skills like the capability-composition-analyzer and trust-decay-monitor.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*