clawdio
Analysis
The skill is a coherent paid audio-report API, but using it can automatically spend USDC from an x402 wallet, so it should be reviewed before installation.
Findings (2)
Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.
Checks for instructions or behavior that redirect the agent, misuse tools, execute unexpected code, cascade across systems, exploit user trust, or continue outside the intended task.
Step 3: Purchase a Report ($1.49 USDC) ... curl https://clawdio.vail.report/catalog/purchase?id={uuid} ... Your x402 wallet automatically ... Signs a USDC payment ... Retries the request with the PAYMENT-SIGNATURE headerThe documented high-impact action is a simple GET request that may be automatically retried with a signed payment, without an explicit instruction to obtain user approval before spending.
Checks whether tool use, credentials, dependencies, identity, account access, or inter-agent boundaries are broader than the stated purpose.
You need an x402-compatible wallet funded with USDC on Base Mainnet ... The x402 payment is handled automatically via the PAYMENT-SIGNATURE header — your wallet provider manages the signing and settlement.
The skill requires delegated wallet authority capable of authorizing crypto payments; the artifacts do not show a scoped wallet, spending cap, or approval boundary.
