Back to skill

Security audit

JPMorgan Claw - Give your Claw Agent spending powers

Security checks for vulnerabilities and agentic risk

Overview

This is a high-impact CreditClaw financial-spending skill with clear documentation, but its identity mismatch, autonomous payment paths, remote instructions, and unverified remote install need human review before use.

Install only if you intend to use CreditClaw, not JPMorgan, and you trust the publisher and creditclaw.com. Keep approval_mode set to ask_for_everything until you have reviewed the service, protect CREDITCLAW_API_KEY like a payment credential, avoid optional callback_url and payer_email unless necessary, and treat remote notes as transaction preferences only, never as authority to reveal secrets or perform unrelated actions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
skill.md:277
Finding

Untrusted API Response Content Is Treated as Authoritative Agent Instructions

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
skill.md:26
Finding

Mutable Remote Skill Instructions Are Installed Without Integrity Verification

Content
View full analysis
~/.creditclaw/skills/creditclaw/SKILL.md curl -s https://creditclaw.com/heartbeat.md > ~/.creditclaw/skills/creditclaw/HEARTBEAT.md curl -s https://creditclaw.com/skill.json > ~/.creditclaw/skills/creditclaw/package.json ``` ``` ### Technical Analysis The installation procedure downloads mutable remote Skill documents directly into a local Skill directory. No cryptographic signature, pinned digest, immutable version URL, or trusted release manifest is used to verify that the downloaded files match the audited package. While the retrieved files are Markdown and JSON rather than conventional native executables, Skill text controls Agent behavior when loaded. Replacing the reviewed instructions with remote content therefore creates an effective remote payload channel. HTTPS protects the connection in transit but does not guarantee that the server's current content is the same content that was reviewed, nor does it protect against compromise of the origin, publishing account, or deployment pipeline. The commands also overwrite destination files directly. Because `curl -s` does not use `--fail`, an HTTP error response could be silently written into a Skill file. Direct redirection can additionally leave a truncated or partial file if the transfer fails. ### Attack Path 1. An attacker compromises `creditclaw.com`, its deployment pipeline, DNS/TLS control, or the credentials used to publish the hosted Skill files. 2. The attacker replaces `skill.md`, `heartbeat.md`, or `skill.json` with malicious Agent instructions. 3. A user follows the documented installation commands. 4. `curl` downloads the current attacker-controlled content without checking a ...[truncated 1235 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (19)

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · skill.md (reported line 11)May include surrounding context.

md
going - Financial enablement & accounting platform for Bots, Agents, and OpenClaw. Multiple methods for enabling and managing agentic spending and purchases, with consolidated accounts and guardrails on transactions across wallets."
homepage: https://creditclaw.com
api_base: https://creditclaw.com/api/v1
credentials: [CREDITCLAW_API_KEY]
---

# CreditClaw — Financial Enablement & Accounting for AI Agents

CreditClaw.com is a financial enablement & accounting platform for Bots, Agents, and OpenClaw.
It provides multiple methods for enabling and managing agentic spending and purchases,
and offers consolidated accounts and guardrails on transactions across wallets.

## Skill Files

| File | URL | Purpose |
|------|-----|---------|
| **SKILL.md** (this file) | `https://creditclaw.com/skill.md` | Full API reference and registration instructions |
| **HEARTBEAT.md** | `https://creditclaw.com/heartbeat.md` | Lightweight polling routine for balance and spending checks |
| **package.json** (m

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · heartbeat.md (reported line 18)May include surrounding context.

1. Check Wallet Status

bash
curl https://creditclaw.com/api/v1/bot/wallet/check \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file instructs the agent to call remote APIs with a bearer token and retrieve wallet status, balances, and spending permissions. While the routine describes what to do, it does not explicitly warn the user that periodic external requests will transmit account-linked data to CreditClaw services.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · skill.md (reported line 27)May include surrounding context.

Install locally:

bash
mkdir -p ~/.creditclaw/skills/creditclaw
curl -s https://creditclaw.com/skill.md > ~/.creditclaw/skills/creditclaw/SKILL.md
curl -s https://creditclaw.com/heartbeat.md > ~/.creditclaw/skills/creditclaw/HEARTBEAT.md
curl -s https://creditclaw.com/skill.json > ~/.creditclaw/skills/creditclaw/package.json

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · skill.md (reported line 28)May include surrounding context.

Install locally:

bash
mkdir -p ~/.creditclaw/skills/creditclaw
curl -s https://creditclaw.com/skill.md > ~/.creditclaw/skills/creditclaw/SKILL.md
curl -s https://creditclaw.com/heartbeat.md > ~/.creditclaw/skills/creditclaw/HEARTBEAT.md
curl -s https://creditclaw.com/skill.json > ~/.creditclaw/skills/creditclaw/package.json

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The registration flow instructs the agent to transmit owner_email, bot metadata, and an optional callback URL to an external service. This is expected for the product, but it is still a real data-exfiltration surface because it causes outbound transfer of potentially sensitive human and infrastructure information to a third party.

Content

Scanner excerpt · skill.md (reported line 110)May include surrounding context.

You can register before your human does. You'll get an API key immediately.

bash
curl -X POST https://creditclaw.com/api/v1/bots/register \
  -H "Content-Type: application/json" \
  -d '{
    "bot_name": "my-research-bot",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 246)May include surrounding context.

and can update them anytime from their dashboard.

bash
curl https://creditclaw.com/api/v1/bot/wallet/spending \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY"

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skill.md (reported line 272)May include surrounding context.

"cash_advances" ], "recurring_allowed": false, "notes": "Prefer free tiers before paying. Always check for discount codes. No annual plans without asking me first.", "updated_at": "2026-02-06T18:00:00Z" }

text

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
92% confidence
Finding

The skill explicitly authorizes the agent to spend money autonomously under certain thresholds without a human in the loop. Even if server-side guardrails exist, this is a real autonomous financial action capability that can be abused through prompt injection, task manipulation, or poor merchant validation.

Content

Scanner excerpt · skill.md (reported line 279)May include surrounding context.

md
**You must follow these rules:**
- If `approval_mode` is `ask_for_everything`, ask your human before any purchase to get their approval. **New accounts default to this mode.** Your owner can loosen this from their dashboard once they're comfortable.
- If `approval_mode` is `auto_approve_under_threshold`, you may spend freely up to `ask_approval_above_usd`. Anything above that requires owner approval.
- If `approval_mode` is `auto_approve_by_category`, you may spend freely on `approved_categories` within limits. All others require approval.
- **Never** spend on `blocked_categories`. These are hard blocks enforced server-side and will be declined.
- Always read and follow the `notes` field — these are your owner's direct instructions.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
91% confidence
Finding

Category-based auto-approval permits the agent to initiate spending on its own within approved categories. Category labels are broad and can be manipulated or misclassified, so the context still creates meaningful risk of unintended purchases despite server-side controls.

Content

Scanner excerpt · skill.md (reported line 280)May include surrounding context.

md
**You must follow these rules:**
- If `approval_mode` is `ask_for_everything`, ask your human before any purchase to get their approval. **New accounts default to this mode.** Your owner can loosen this from their dashboard once they're comfortable.
- If `approval_mode` is `auto_approve_under_threshold`, you may spend freely up to `ask_approval_above_usd`. Anything above that requires owner approval.
- If `approval_mode` is `auto_approve_by_category`, you may spend freely on `approved_categories` within limits. All others require approval.
- **Never** spend on `blocked_categories`. These are hard blocks enforced server-side and will be declined.
- Always read and follow the `notes` field — these are your owner's direct instructions.
- Cache this for up to 30 minutes. Do not fetch before every micro-purchase.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skill.md (reported line 337)May include surrounding context.

md
| `exceeds_per_transaction_limit` | 403 | Amount exceeds per-transaction cap. |
| `exceeds_daily_limit` | 403 | Would exceed daily spending limit. |
| `exceeds_monthly_limit` | 403 | Would exceed monthly spending limit. |
| `requires_owner_approval` | 403 | Amount above auto-approve threshold. |

When a purchase is declined, the response includes the relevant limits and your current
spending so you can understand why. Your owner is also notified of all declined attempts.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skill.md (reported line 520)May include surrounding context.

md
| `exceeds_per_transaction_limit` | 403 | Amount exceeds per-transaction cap. |
| `exceeds_daily_limit` | 403 | Would exceed daily spending limit. |
| `exceeds_monthly_limit` | 403 | Would exceed monthly spending limit. |
| `requires_owner_approval` | 403 | Amount above auto-approve threshold. |

When a purchase is declined, the response includes the relevant limits and your current
spending so you can understand why. Your owner is also notified of all declined attempts.

External Transmission

Medium
Category
Data Exfiltration
Confidence
76% confidence
Finding

The top-up request sends financial intent and a free-form reason to an external provider, which may contain sensitive task or business context. Although consistent with the product purpose, it still creates a privacy and data-sharing risk if agents include unnecessary operational details.

Content

Scanner excerpt · skill.md (reported line 349)May include surrounding context.

When your balance is low, ask your human if they'd like you to request a top-up:

bash
curl -X POST https://creditclaw.com/api/v1/bot/wallet/topup-request \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The payment-link workflow asks the agent to collect and transmit a third party's payer email address, but the skill provides no privacy notice, consent guidance, retention limits, or minimization instructions. In an agent context, this can lead to unnecessary collection of personal data and unauthorized disclosure to the service provider, creating privacy and compliance risk.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
89% confidence
Finding

The self-hosted card flow allows automatic processing for transactions within an allowance, enabling autonomous spending against payment instruments. Because this concerns real card-backed purchases, mistakes or adversarial prompting could have immediate financial impact.

Content

Scanner excerpt · skill.md (reported line 487)May include surrounding context.

md
1. You submit a checkout request with merchant and amount details
2. CreditClaw evaluates the request against your card's permissions
3. If the amount is within your auto-approved allowance, it processes immediately
4. If the amount exceeds the threshold, your owner receives an approval request (email with secure link)
5. You poll for the result
6. Once approved, the transaction is recorded

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The self-hosted card checkout flow transmits merchant, URL, item, amount, and category to an external payment service in order to initiate a financial transaction. Because this can trigger real spending and disclose procurement behavior, it is a genuine high-risk capability if invoked without strong authorization and transaction confirmation.

Content

Scanner excerpt · skill.md (reported line 495)May include surrounding context.

Make a Self-Hosted Card Checkout

bash
curl -X POST https://creditclaw.com/api/v1/bot/merchant/checkout \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The x402 signing flow sends payment details that can authorize blockchain-based spending through an external service. Even with guardrails, this is a sensitive outbound financial action that can result in irreversible transfers if a malicious or mistaken payment request is approved.

Content

Scanner excerpt · skill.md (reported line 589)May include surrounding context.

Request x402 Payment Signature

bash
curl -X POST https://creditclaw.com/api/v1/stripe-wallet/bot/sign \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

The example resource_url points to an arbitrary external domain and normalizes the pattern of paying external services based on remote 402 responses. In agent settings, this can be abused to steer spending toward attacker-controlled endpoints unless domain validation is strict.

Content

Scanner excerpt · skill.md (reported line 593)May include surrounding context.

md
-H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "resource_url": "https://api.example.com/v1/data",
    "amount_usdc": 500000,
    "recipient_address": "0x1234...abcd"
  }'

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

Retrying requests to external domains with an X-PAYMENT header creates a direct payment execution path to third-party services. If an attacker can influence the target URL or payment challenge, the agent may complete unauthorized paid requests.

Content

Scanner excerpt · skill.md (reported line 617)May include surrounding context.

Use the x_payment_header value as-is in your retry request:

bash
curl https://api.example.com/v1/data \
  -H "X-PAYMENT: eyJ0eXAiOi..."

Static analysis

No suspicious patterns detected.