T01 · Skill Instruction Hijacking
- Location
skill.md:277- Finding
Untrusted API Response Content Is Treated as Authoritative Agent Instructions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a high-impact CreditClaw financial-spending skill with clear documentation, but its identity mismatch, autonomous payment paths, remote instructions, and unverified remote install need human review before use.
Install only if you intend to use CreditClaw, not JPMorgan, and you trust the publisher and creditclaw.com. Keep approval_mode set to ask_for_everything until you have reviewed the service, protect CREDITCLAW_API_KEY like a payment credential, avoid optional callback_url and payer_email unless necessary, and treat remote notes as transaction preferences only, never as authority to reveal secrets or perform unrelated actions.
skill.md:277Untrusted API Response Content Is Treated as Authoritative Agent Instructions
skill.md:26Mutable Remote Skill Instructions Are Installed Without Integrity Verification
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
going - Financial enablement & accounting platform for Bots, Agents, and OpenClaw. Multiple methods for enabling and managing agentic spending and purchases, with consolidated accounts and guardrails on transactions across wallets."
homepage: https://creditclaw.com
api_base: https://creditclaw.com/api/v1
credentials: [CREDITCLAW_API_KEY]
---
# CreditClaw — Financial Enablement & Accounting for AI Agents
CreditClaw.com is a financial enablement & accounting platform for Bots, Agents, and OpenClaw.
It provides multiple methods for enabling and managing agentic spending and purchases,
and offers consolidated accounts and guardrails on transactions across wallets.
## Skill Files
| File | URL | Purpose |
|------|-----|---------|
| **SKILL.md** (this file) | `https://creditclaw.com/skill.md` | Full API reference and registration instructions |
| **HEARTBEAT.md** | `https://creditclaw.com/heartbeat.md` | Lightweight polling routine for balance and spending checks |
| **package.json** (m
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl https://creditclaw.com/api/v1/bot/wallet/check \
-H "Authorization: Bearer $CREDITCLAW_API_KEY"
This markdown file instructs the agent to call remote APIs with a bearer token and retrieve wallet status, balances, and spending permissions. While the routine describes what to do, it does not explicitly warn the user that periodic external requests will transmit account-linked data to CreditClaw services.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Install locally:
mkdir -p ~/.creditclaw/skills/creditclaw
curl -s https://creditclaw.com/skill.md > ~/.creditclaw/skills/creditclaw/SKILL.md
curl -s https://creditclaw.com/heartbeat.md > ~/.creditclaw/skills/creditclaw/HEARTBEAT.md
curl -s https://creditclaw.com/skill.json > ~/.creditclaw/skills/creditclaw/package.json
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
Install locally:
mkdir -p ~/.creditclaw/skills/creditclaw
curl -s https://creditclaw.com/skill.md > ~/.creditclaw/skills/creditclaw/SKILL.md
curl -s https://creditclaw.com/heartbeat.md > ~/.creditclaw/skills/creditclaw/HEARTBEAT.md
curl -s https://creditclaw.com/skill.json > ~/.creditclaw/skills/creditclaw/package.json
The registration flow instructs the agent to transmit owner_email, bot metadata, and an optional callback URL to an external service. This is expected for the product, but it is still a real data-exfiltration surface because it causes outbound transfer of potentially sensitive human and infrastructure information to a third party.
You can register before your human does. You'll get an API key immediately.
curl -X POST https://creditclaw.com/api/v1/bots/register \
-H "Content-Type: application/json" \
-d '{
"bot_name": "my-research-bot",
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
and can update them anytime from their dashboard.
curl https://creditclaw.com/api/v1/bot/wallet/spending \
-H "Authorization: Bearer $CREDITCLAW_API_KEY"
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
"cash_advances" ], "recurring_allowed": false, "notes": "Prefer free tiers before paying. Always check for discount codes. No annual plans without asking me first.", "updated_at": "2026-02-06T18:00:00Z" }
The skill explicitly authorizes the agent to spend money autonomously under certain thresholds without a human in the loop. Even if server-side guardrails exist, this is a real autonomous financial action capability that can be abused through prompt injection, task manipulation, or poor merchant validation.
**You must follow these rules:**
- If `approval_mode` is `ask_for_everything`, ask your human before any purchase to get their approval. **New accounts default to this mode.** Your owner can loosen this from their dashboard once they're comfortable.
- If `approval_mode` is `auto_approve_under_threshold`, you may spend freely up to `ask_approval_above_usd`. Anything above that requires owner approval.
- If `approval_mode` is `auto_approve_by_category`, you may spend freely on `approved_categories` within limits. All others require approval.
- **Never** spend on `blocked_categories`. These are hard blocks enforced server-side and will be declined.
- Always read and follow the `notes` field — these are your owner's direct instructions.
Category-based auto-approval permits the agent to initiate spending on its own within approved categories. Category labels are broad and can be manipulated or misclassified, so the context still creates meaningful risk of unintended purchases despite server-side controls.
**You must follow these rules:**
- If `approval_mode` is `ask_for_everything`, ask your human before any purchase to get their approval. **New accounts default to this mode.** Your owner can loosen this from their dashboard once they're comfortable.
- If `approval_mode` is `auto_approve_under_threshold`, you may spend freely up to `ask_approval_above_usd`. Anything above that requires owner approval.
- If `approval_mode` is `auto_approve_by_category`, you may spend freely on `approved_categories` within limits. All others require approval.
- **Never** spend on `blocked_categories`. These are hard blocks enforced server-side and will be declined.
- Always read and follow the `notes` field — these are your owner's direct instructions.
- Cache this for up to 30 minutes. Do not fetch before every micro-purchase.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
| `exceeds_per_transaction_limit` | 403 | Amount exceeds per-transaction cap. |
| `exceeds_daily_limit` | 403 | Would exceed daily spending limit. |
| `exceeds_monthly_limit` | 403 | Would exceed monthly spending limit. |
| `requires_owner_approval` | 403 | Amount above auto-approve threshold. |
When a purchase is declined, the response includes the relevant limits and your current
spending so you can understand why. Your owner is also notified of all declined attempts.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
| `exceeds_per_transaction_limit` | 403 | Amount exceeds per-transaction cap. |
| `exceeds_daily_limit` | 403 | Would exceed daily spending limit. |
| `exceeds_monthly_limit` | 403 | Would exceed monthly spending limit. |
| `requires_owner_approval` | 403 | Amount above auto-approve threshold. |
When a purchase is declined, the response includes the relevant limits and your current
spending so you can understand why. Your owner is also notified of all declined attempts.
The top-up request sends financial intent and a free-form reason to an external provider, which may contain sensitive task or business context. Although consistent with the product purpose, it still creates a privacy and data-sharing risk if agents include unnecessary operational details.
When your balance is low, ask your human if they'd like you to request a top-up:
curl -X POST https://creditclaw.com/api/v1/bot/wallet/topup-request \
-H "Authorization: Bearer $CREDITCLAW_API_KEY" \
-H "Content-Type: application/json" \
-d '{
The payment-link workflow asks the agent to collect and transmit a third party's payer email address, but the skill provides no privacy notice, consent guidance, retention limits, or minimization instructions. In an agent context, this can lead to unnecessary collection of personal data and unauthorized disclosure to the service provider, creating privacy and compliance risk.
The self-hosted card flow allows automatic processing for transactions within an allowance, enabling autonomous spending against payment instruments. Because this concerns real card-backed purchases, mistakes or adversarial prompting could have immediate financial impact.
1. You submit a checkout request with merchant and amount details
2. CreditClaw evaluates the request against your card's permissions
3. If the amount is within your auto-approved allowance, it processes immediately
4. If the amount exceeds the threshold, your owner receives an approval request (email with secure link)
5. You poll for the result
6. Once approved, the transaction is recorded
The self-hosted card checkout flow transmits merchant, URL, item, amount, and category to an external payment service in order to initiate a financial transaction. Because this can trigger real spending and disclose procurement behavior, it is a genuine high-risk capability if invoked without strong authorization and transaction confirmation.
curl -X POST https://creditclaw.com/api/v1/bot/merchant/checkout \
-H "Authorization: Bearer $CREDITCLAW_API_KEY" \
-H "Content-Type: application/json" \
-d '{
The x402 signing flow sends payment details that can authorize blockchain-based spending through an external service. Even with guardrails, this is a sensitive outbound financial action that can result in irreversible transfers if a malicious or mistaken payment request is approved.
curl -X POST https://creditclaw.com/api/v1/stripe-wallet/bot/sign \
-H "Authorization: Bearer $CREDITCLAW_API_KEY" \
-H "Content-Type: application/json" \
-d '{
The example resource_url points to an arbitrary external domain and normalizes the pattern of paying external services based on remote 402 responses. In agent settings, this can be abused to steer spending toward attacker-controlled endpoints unless domain validation is strict.
-H "Authorization: Bearer $CREDITCLAW_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"resource_url": "https://api.example.com/v1/data",
"amount_usdc": 500000,
"recipient_address": "0x1234...abcd"
}'
Retrying requests to external domains with an X-PAYMENT header creates a direct payment execution path to third-party services. If an attacker can influence the target URL or payment challenge, the agent may complete unauthorized paid requests.
Use the x_payment_header value as-is in your retry request:
curl https://api.example.com/v1/data \
-H "X-PAYMENT: eyJ0eXAiOi..."
No suspicious patterns detected.