payment gaurd

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The artifacts describe an instruction-only payment safety checklist with no code, install steps, credentials, or hidden behavior, though real payments should still require human approval.

This appears to be a benign payment-safety guardrail. Before installing, remember that payment workflows are high impact: use the skill to double-check beneficiary, amount, currency, purpose, and authorization, but do not let any agent send money without your explicit final review in the official payment system.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

#
ASI02: Tool Misuse and Exploitation
Low
What this means

The skill may influence whether a payment workflow proceeds or is blocked, so users should keep final control over any real payment.

Why it was flagged

The skill is intended for workflows involving real money movement, which is high impact. The same artifact frames this as a safety guardrail and requires verification before proceeding.

Skill content
use when chatgpt is asked to prepare, verify, review, or execute a payment action
Recommendation

Use it as a review and safety checklist, and require explicit human confirmation in the secure payment interface before sending money.