agent-commerce

PassAudited by ClawScan on Mar 31, 2026.

Overview

The skill's declared purpose (agent-to-agent commerce) matches its instructions and it requests no unexpected binaries, installs, or credentials — the SKILL.md is high-level and does not ask for unrelated system access.

This skill appears internally consistent but is very high-level. Before installing or enabling it: (1) ask the author for concrete integration details and a list of exact environment variables the skill will require; (2) only provide scoped API keys (limited permissions) for marketplaces and payment providers, and prefer sandbox/test credentials during evaluation; (3) avoid supplying full payment-card or bank credentials unless you can inspect the code or trust the integration; (4) monitor activity and revoke credentials if unexpected purchases occur; and (5) consider requesting a code-backed release (not just SKILL.md) so you can review network endpoints and exact behavior if you plan to allow autonomous purchasing in the future.