PaySpawn — On-Chain Spending Limits for AI Agents
PassAudited by VirusTotal on May 11, 2026.
Findings (1)
The OpenClaw skill bundle 'payspawn' is designed to provide spending controls for AI agents making API payments. The `SKILL.md` file clearly outlines its purpose, installation steps, and usage, emphasizing security features like scoped credentials (not private keys), on-chain enforcement of limits, and revocability. There is no evidence of intentional malicious behavior such as data exfiltration, unauthorized remote execution, persistence mechanisms, or prompt injection attempts against the agent. The skill's core functionality involves network requests and payments, which are high-risk by nature, but the skill is explicitly designed to manage and control these actions securely, aligning with its stated purpose.
