{"id":"58555c62-6954-4faf-8b22-5d30c919691c","entityType":"agent","slug":"clawhub-skills-andyxinweiminicloud-delta-disclosure-auditor","name":"delta-disclosure-auditor","canonicalUrl":"https://www.xpersona.co/agent/clawhub-skills-andyxinweiminicloud-delta-disclosure-auditor","canonicalPath":"/agent/clawhub-skills-andyxinweiminicloud-delta-disclosure-auditor","generatedAt":"2026-10-10T04:52:25.772Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"Helps verify that skill updates publish an auditable record of what changed — catching the gap between \"the registry shows the new version\" and \"anyone can see what the new version changed relative to the old one.\" --- name: delta-disclosure-auditor description: > Helps verify that skill updates publish an auditable record of what changed — catching the gap between \"the registry shows the new version\" and \"anyone can see what the new version changed relative to the old one.\" version: 1.0.0 metadata: openclaw: requires: bins: [curl, python3] env: [] emoji: \"📝\" agent_card: capabilities: [delta-disclosure-auditing, change-record-","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. Last updated 4/15/2026.","installCommand":"clawhub skill install skills:andyxinweiminicloud:delta-disclosure-auditor","sourceUrl":"https://github.com/openclaw/skills/tree/main/skills/andyxinweiminicloud/delta-disclosure-auditor","homepage":null,"primaryLinks":[{"label":"View on ClawHub","url":"https://github.com/openclaw/skills/tree/main/skills/andyxinweiminicloud/delta-disclosure-auditor","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":50,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Helps verify that skill updates publish an auditable record of what changed — catching the gap between \"the registry shows the new version\" and \"anyone can see "},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[{"label":"update","status":"self-declared"},{"label":"watch","status":"self-declared"},{"label":"identify","status":"self-declared"},{"label":"continuous","status":"self-declared"}],"verifiedCount":0,"selfDeclaredCount":5,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"},{"key":"update","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"watch","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"identify","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"continuous","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile capability:update|supported|profile capability:watch|supported|profile capability:identify|supported|profile capability:continuous|supported|profile"}},"adoption":{"evidence":{"source":"no-adoption-signals","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No source adoption metrics were available."},"stars":null,"forks":null,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":null},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-02-25T03:36:45.384Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-02-25T03:36:45.384Z","lastIndexedAt":null,"nextCrawlAt":"2026-02-26T03:36:45.385Z","lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install skills:andyxinweiminicloud:delta-disclosure-auditor","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-delta-disclosure-auditor/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-delta-disclosure-auditor/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-delta-disclosure-auditor/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-delta-disclosure-auditor/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-delta-disclosure-auditor/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-delta-disclosure-auditor/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T04:52:25.772Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-delta-disclosure-auditor/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-delta-disclosure-auditor/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-delta-disclosure-auditor/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-delta-disclosure-auditor/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"---\r\nname: delta-disclosure-auditor\r\ndescription: >\r\n  Helps verify that skill updates publish an auditable record of what changed —\r\n  catching the gap between \"the registry shows the new version\" and \"anyone can\r\n  see what the new version changed relative to the old one.\"\r\nversion: 1.0.0\r\nmetadata:\r\n  openclaw:\r\n    requires:\r\n      bins: [curl, python3]\r\n      env: []\r\n    emoji: \"📝\"\r\n  agent_card:\r\n    capabilities: [delta-disclosure-auditing, change-record-verification, update-transparency-checking]\r\n    attack_surface: [L1]\r\n    trust_dimension: rule-adoption\r\n    published:\r\n      clawhub: false\r\n      moltbook: false\r\n---\r\n\r\n# The Skill Updated. Nobody Published What Changed.\r\n\r\n> Helps identify when skill updates lack auditable change records — the\r\n> transparency gap that makes continuous monitoring impossible without\r\n> re-executing the full skill on every version.\r\n\r\n## Problem\r\n\r\nA skill that re-audits on every update is more trustworthy than one audited\r\nonce at install time. But re-auditing requires knowing what changed. If a skill\r\ncan update its capability declarations, dependency set, and validation commands\r\nwithout publishing a machine-readable delta, continuous monitoring reduces to\r\nfull re-execution on every version — expensive, often impractical, and\r\nfrequently skipped.\r\n\r\nThe gap is structural. Most current skill registries record that a new version\r\nwas published. They do not require publishers to disclose what changed between\r\nversions. An auditor comparing v1.1 to v1.2 must either execute both versions\r\nand compare behavior, or accept the new version at face value. Neither option\r\nsupports continuous security monitoring at scale.\r\n\r\nDelta disclosure changes this. If every update is required to publish a diff of\r\nwhat changed — in capability declarations, dependency sets, validation commands,\r\nand behavioral scope — then continuous monitoring becomes tractable. External\r\nauditors can watch for specific types of changes (new outbound endpoints, expanded\r\nfile access, dropped validation commands) without re-executing everything. The\r\nmonitoring cost scales with what changed, not with the full skill surface.\r\n\r\nThe absence of delta disclosure is not evidence of malicious intent. It is\r\nevidence that continuous monitoring is harder than it needs to be.\r\n\r\n## What This Audits\r\n\r\nThis auditor examines delta disclosure completeness across five dimensions:\r\n\r\n1. **Capability declaration delta** — Does each version update publish a diff\r\n   of what capabilities changed? Added capabilities, removed capabilities, and\r\n   scope changes should each be explicitly declared, not inferred by comparison\r\n\r\n2. **Dependency delta** — Does each update disclose which dependencies were\r\n   added, removed, or version-bumped? Dependency changes are a primary vector\r\n   for supply chain attacks and should be immediately visible without full\r\n   diff inspection\r\n\r\n3. **Validation command delta** — Does each update disclose changes to the\r\n   validation suite? Dropped tests, weakened assertions, and removed coverage\r\n   are security-relevant changes that should require explicit disclosure\r\n\r\n4. **Behavioral scope change declaration** — Does each update explicitly\r\n   declare whether its behavioral scope changed? \"This update adds a new\r\n   outbound endpoint\" is a different security posture from \"this update fixes\r\n   a typo\" and should be declared, not inferred\r\n\r\n5. **Delta completeness verification** — Where deltas are published, are they\r\n   complete and accurate? A delta that omits material changes is equivalent\r\n   to no delta at all — and potentially worse, as it creates false assurance\r\n   that monitoring is occurring\r\n\r\n## How to Use\r\n\r\n**Input**: Provide one of:\r\n- A skill identifier to audit update history for delta disclosure\r\n- Two specific skill versions to check for delta between them\r\n- A registry endpoint to assess delta disclosure infrastructure\r\n\r\n**Output**: A delta disclosure report containing:\r\n- Delta infrastructure assessment (structured / partial / absent)\r\n- Per-dimension completeness scores\r\n- Material changes not disclosed in existing deltas\r\n- Monitoring tractability assessment\r\n- Disclosure verdict: COMPLETE / PARTIAL / ABSENT / MISLEADING\r\n\r\n## Example\r\n\r\n**Input**: Audit delta disclosure for `analytics-connector` v1.0 → v1.3\r\n\r\n```\r\n📝 DELTA DISCLOSURE AUDIT\r\n\r\nSkill: analytics-connector\r\nVersion range: v1.0 → v1.3\r\nAudit timestamp: 2025-07-15T16:00:00Z\r\n\r\nDelta infrastructure:\r\n  Registry publishes version diffs: ✗ Not found\r\n  Publisher-provided changelogs: ✅ Present (informal)\r\n  Machine-readable capability deltas: ✗ Not found\r\n\r\nVersion history (reconstructed by comparison):\r\n\r\nv1.0 → v1.1 (publisher changelog: \"performance improvements\"):\r\n  Capability delta (reconstructed):\r\n    Added: outbound-HTTP to analytics-endpoint.example (undisclosed)\r\n    No change to file access scope\r\n  Dependency delta (reconstructed):\r\n    requests library: 2.28 → 2.31\r\n    Added: cryptography==41.0.0 (undisclosed)\r\n  Validation delta (reconstructed):\r\n    Removed: 2 of 8 test assertions (undisclosed)\r\n  Assessment: changelog says \"performance\" — material changes undisclosed\r\n\r\nv1.1 → v1.2 (publisher changelog: \"bug fixes\"):\r\n  Capability delta (reconstructed):\r\n    No change detected\r\n  Dependency delta (reconstructed):\r\n    No change detected\r\n  Validation delta (reconstructed):\r\n    No change detected\r\n  Assessment: changelog accurate — no material changes\r\n\r\nv1.2 → v1.3 (publisher changelog: \"added reporting feature\"):\r\n  Capability delta (reconstructed):\r\n    Added: file-read expanded from /app/data to /app (undisclosed)\r\n    Added: outbound-HTTP to second endpoint (undisclosed)\r\n  Dependency delta (reconstructed):\r\n    Added: 3 new dependencies (undisclosed)\r\n  Validation delta (reconstructed):\r\n    Added: 3 new tests (disclosed in changelog, accurate)\r\n  Assessment: changelog mentions feature, omits capability scope expansion\r\n\r\nDisclosure verdict: MISLEADING\r\n  Changelogs exist but systematically omit material security changes.\r\n  v1.1 added an outbound endpoint and dropped test coverage while claiming\r\n  \"performance improvements.\" v1.3 expanded file access scope while claiming\r\n  only a \"reporting feature.\" These omissions are not detectable without\r\n  full reconstruction — which defeats the purpose of delta disclosure.\r\n\r\nMonitoring tractability: LOW\r\n  Without structured delta disclosure, continuous monitoring requires\r\n  full capability reconstruction on every version. At current update\r\n  velocity (3 versions in observed period), monitoring cost is 3×\r\n  full audit cost rather than incremental.\r\n\r\nRecommended actions:\r\n  1. Require structured capability delta as part of version publication\r\n  2. Flag v1.1 outbound endpoint addition for independent review\r\n  3. Flag v1.3 file access scope expansion as undisclosed material change\r\n  4. Treat v1.1+ as unaudited for security purposes pending delta disclosure\r\n  5. Advocate for registry-level delta disclosure requirements\r\n```\r\n\r\n## Related Tools\r\n\r\n- **skill-update-delta-monitor** — Monitors for suspicious update patterns;\r\n  delta-disclosure-auditor checks whether those updates are transparently documented\r\n- **trust-velocity-calculator** — Quantifies trust decay from update velocity;\r\n  delta disclosure makes velocity-based trust decay calculable without full re-audit\r\n- **transparency-log-auditor** — Checks whether signing events are independently\r\n  logged; delta disclosure provides the content that transparency logs should record\r\n- **hollow-validation-checker** — Detects structural validation failures; delta\r\n  disclosure auditing catches when validation changes are omitted from changelogs\r\n\r\n## Limitations\r\n\r\nDelta disclosure auditing requires access to multiple versions of a skill to\r\nreconstruct what changed when publisher-provided deltas are absent or incomplete.\r\nReconstruction by comparison is necessarily heuristic: behavioral changes that\r\nproduce identical static artifacts cannot be detected without execution.\r\nWhere registries do not preserve version history, reconstruction may be\r\nimpossible for older version pairs. The assessment of whether an undisclosed\r\nchange is \"material\" requires judgment about security relevance; this tool\r\napplies conservative heuristics that may flag innocuous changes. Publisher\r\nchangelogs in natural language cannot be automatically verified for completeness;\r\nthe analysis can identify discrepancies between changelogs and reconstructed\r\ndiffs, but cannot confirm that the reconstruction itself is complete.\r\n","readmeExcerpt":"--- name: delta-disclosure-auditor description: > Helps verify that skill updates publish an auditable record of what changed — catching the gap between \"the registry shows the new version\" and \"anyone can see what the new version changed relative to the old one.\" version: 1.0.0 metadata: openclaw: requires: bins: [curl, python3] env: [] emoji: \"📝\" agent_card: capabilities: [delta-disclosure-auditing, change-record-","codeSnippets":[],"executableExamples":[],"parameters":{},"dependencies":[],"permissions":[],"extractedFiles":[],"languages":["typescript"],"docsSourceLabel":"CLAWHUB","editorialOverview":"Helps verify that skill updates publish an auditable record of what changed — catching the gap between \"the registry shows the new version\" and \"anyone can see what the new version changed relative to the old one.\" --- name: delta-disclosure-auditor description: > Helps verify that skill updates publish an auditable record of what changed — catching the gap between \"the registry shows the new version\" and \"anyone can see what the new version changed relative to the old one.\" version: 1.0.0 metadata: openclaw: requires: bins: [curl, python3] env: [] emoji: \"📝\" agent_card: capabilities: [delta-disclosure-auditing, change-record-","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":408,"uniquenessScore":61,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T04:52:25.772Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}