Back to skill

Security audit

OpenClaw 1ly Payments

Security checks across malware telemetry and agentic risk

Overview

This skill clearly sets up a payment integration, but it can let an agent spend from configured wallets within user-set limits.

Install this only if you want an agent to use 1ly payment tools. Use a dedicated low-balance wallet, set strict per-call and daily budgets, prefer provider-based wallet authentication over raw private keys, verify the npm package before running it, and do not enable autonomous spending unless purchases within those limits are acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly allows autonomous spending without per-call confirmation once budget variables are set and the user has opted in. Even with per-call and daily caps, this creates a real financial-risk path: a misconfigured, compromised, or prompt-injected agent could initiate unintended paid API calls or transactions up to the configured limits.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal