clawxpay

Security checks across malware telemetry and agentic risk

Overview

This skill is transparent about using a wallet to pay for API calls, but its default setup can spend from that wallet across many external services without strong built-in user confirmation or spending limits.

Install only with a dedicated wallet containing limited funds. Configure X402_POLICY_PATH with per-transaction caps, daily caps, and recipient allowlists before use, and avoid sending sensitive prompts, files, URLs, or private data through the paid external services unless you intend to share them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The documentation is internally inconsistent: it says the private key is 'never needed at runtime' while the payment flow explicitly depends on local signing for each paid request. This can mislead agent authors into treating key handling as non-runtime-sensitive, increasing the chance of unsafe logging, accidental exposure, or poor threat modeling around a live signing key stored on disk.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The AI inference trigger keywords are extremely broad ('analyze', 'summarize', 'translate', 'answer questions', etc.), which can cause an agent to route many ordinary user requests into paid external model calls. In the context of a pay-per-call gateway, this raises the risk of unintended spending and unnecessary transmission of user data to third-party AI providers.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal