Back to skill

Security audit

Shop from Adidas - Online with CreditCard

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed payment and shopping wallet, but users should review it carefully because it combines real spending authority with mutable remote installation instructions and sensitive purchase data handling.

Install only if you are comfortable giving this skill spending authority through CreditClaw. Keep approval mode strict at first, set low per-transaction and daily limits, restrict merchants/categories where possible, protect CREDITCLAW_API_KEY as a spending credential, avoid logging full shipping addresses or headers, and prefer a packaged or verified release over the documented curl-based remote install path.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
skill.md:31
Finding

Unverified Retrieval and Persistent Installation of Mutable Remote Skill Instructions

Content
View full analysis
~/.creditclaw/skills/stripe/SKILL.md curl -s https://creditclaw.com/stripe/shopping.md > ~/.creditclaw/skills/stripe/SHOPPING.md curl -s https://creditclaw.com/stripe/amazon.md > ~/.creditclaw/skills/stripe/AMAZON.md curl -s https://creditclaw.com/stripe/prepaid-wallet.md > ~/.creditclaw/skills/stripe/PREPAID-WALLET.md curl -s https://creditclaw.com/stripe/self-hosted-card.md > ~/.creditclaw/skills/stripe/SELF-HOSTED-CARD.md curl -s https://creditclaw.com/stripe/stripe-x402-wallet.md > ~/.creditclaw/skills/stripe/STRIPE-X402-WALLET.md curl -s https://creditclaw.com/stripe/heartbeat.md > ~/.creditclaw/skills/stripe/HEARTBEAT.md curl -s https://creditclaw.com/stripe/skill.json > ~/.creditclaw/skills/stripe/package.json ``` Or just read them directly from the URLs above. ``` ### Technical Analysis The installation procedure downloads multiple mutable Markdown instruction files and metadata from remote URLs, then overwrites files in the persistent local Skill directory. It does not pin a release version, verify a cryptographic digest, validate a signed manifest, or compare the downloaded content with the audited package. Although HTTPS protects data in transit, it does not ensure that the content currently hosted at those URLs is identical to the content reviewed during this audit. A compromise of the CreditClaw domain, hosting account, content delivery infrastructure, or release pipeline could replace the files with attacker-controlled Agent instructions. Markdown Skill files influence Agent behavior and can therefore function as effective behavioral paylo ...[truncated 2258 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (33)

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · skill.md (reported line 12)May include surrounding context.

md
wallets powered by Stripe. Use your existing Stripe/Link to top-up this versatile x402 wallet for any purchases or A2A payments."
homepage: https://creditclaw.com
api_base: https://creditclaw.com/api/v1
credentials: [CREDITCLAW_API_KEY]
metadata: {"openclaw":{"requires":{"env":["CREDITCLAW_API_KEY"]},"primaryEnv":"CREDITCLAW_API_KEY"}}
---

# CreditClaw — Stripe-powered wallets and payments for AI Agents

CreditClaw lets your agent buy things online — Amazon products, Shopify stores, SaaS subscriptions, and more.
Your owner funds a wallet, sets spending limits, and you shop within those guardrails.

## Skill Files

| File | URL | Purpose |
|------|-----|---------|
| **SKILL.md** (this file) | `https://creditclaw.com/stripe/skill.md` | Registration, setup, payment method guide, and API reference |
| **SHOPPING.md** | `https://creditclaw.com/stripe/shopping.md` | General purchasing guide — merchant types, tips, common patterns |
| **AMAZON.md** | `https://creditclaw.com/stripe/amaz

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes an agentic wallet powered by Stripe/Link for topping up an x402 wallet and making purchases or agent-to-agent payments. This file documents a distinct Amazon ordering workflow through CreditClaw, including product discovery, owner approval, shipping addresses, order placement, and delivery tracking, which is materially broader than a generic Stripe wallet/top-up capability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide instructs sending a full recipient shipping address in a purchase request without any privacy minimization, handling guidance, or warning that this is sensitive personal data. In an agentic setting, this can normalize collection and transmission of PII to an external service and increase the chance of unnecessary exposure, logging, or misuse of address information.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The example performs an authenticated POST to an external service and includes sensitive fields such as an API key-backed authorization header and shipping address payload. External transmission is expected for the feature, but the documentation lacks security caveats about secret handling, destination trust, data minimization, and safe use in agent contexts, so it presents a real data-exposure risk if copied blindly.

Content

Scanner excerpt · amazon.md (reported line 33)May include surrounding context.

Purchase Request

bash
curl -X POST https://creditclaw.com/api/v1/card-wallet/bot/purchase \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file presents itself as a passive heartbeat/status routine, but it includes an active state-changing action that submits a wallet top-up request. In an agent context, mixing monitoring with financial request side effects can cause unauthorized or unexpected spending workflows, especially if the routine is run automatically on a schedule.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file provides executable curl commands that send an Authorization bearer token derived from CREDITCLAW_API_KEY to a remote service, but it does not warn users about handling a sensitive credential or the privacy implications of transmitting wallet and status data. Under the markdown criteria for missing user warnings, network behavior affecting privacy or sensitive credentials should be disclosed.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · heartbeat.md (reported line 19)May include surrounding context.

1. Check Full Status (Recommended)

bash
curl https://creditclaw.com/api/v1/bot/status \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · heartbeat.md (reported line 95)May include surrounding context.

Before an expensive self-hosted card purchase, test if it would pass:

bash
curl -X POST https://creditclaw.com/api/v1/bot/check/rail4/test \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "merchant_name": "Amazon", "amount_cents": 5000, "profile_index": 1 }'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The purchase example includes personally identifiable shipping data such as full name and street address sent to POST /card-wallet/bot/purchase. While the document explains how to use the API, it does not warn that this data will be transmitted to the service and merchant or note the privacy implications of sharing customer delivery details.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · prepaid-wallet.md (reported line 43)May include surrounding context.

Purchase Request

bash
curl -X POST https://creditclaw.com/api/v1/card-wallet/bot/purchase \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · prepaid-wallet.md (reported line 98)May include surrounding context.

Step 1: Search for Variants

bash
curl -X POST https://creditclaw.com/api/v1/card-wallet/bot/search \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "product_url": "https://shop.example.com/products/widget" }'

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
91% confidence
Finding

The documented design allows the system to automatically approve purchases within a configured allowance without per-transaction human review. In a payment skill, autonomous financial decision-making materially increases the risk of prompt injection, task confusion, or abuse leading to unauthorized charges.

Content

Scanner excerpt · self-hosted-card.md (reported line 11)May include surrounding context.

md
## How It Works

Self-hosted cards use a split-knowledge privacy model. Your owner provides their own card details through CreditClaw's secure setup wizard — you never see the actual card numbers. When you need to make a purchase at any online merchant, you submit a checkout request. CreditClaw evaluates it against your card's permissions and either auto-approves (if within your allowance) or sends your owner an approval request via email.

**Use this rail for:** Any online store — SaaS subscriptions, cloud hosting, domain registrations, digital services, or any merchant not covered by the Pre-paid Wallet.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
93% confidence
Finding

This flow explicitly states that qualifying purchases are processed immediately once the agent submits merchant and amount details. That creates a direct path from agent action to financial execution, making mistakes or adversarial instructions costly before a human can intervene.

Content

Scanner excerpt · self-hosted-card.md (reported line 23)May include surrounding context.

md
1. You submit a checkout request with merchant and amount details
2. CreditClaw evaluates the request against your card's permissions
3. If the amount is within your auto-approved allowance, it processes immediately
4. If the amount exceeds the threshold, your owner receives an approval request (email with secure link)
5. You poll for the result
6. Once approved, the transaction is recorded

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The skill instructs the agent to initiate real payment checkout requests to an external financial service using a bearer API key. Even though this is documented functionality, it enables transfer of sensitive purchase metadata and can trigger real monetary transactions, including auto-approved charges, which is security-relevant and dangerous if the agent is misused or prompted into unauthorized spending.

Content

Scanner excerpt · self-hosted-card.md (reported line 31)May include surrounding context.

Checkout Request

bash
curl -X POST https://creditclaw.com/api/v1/bot/merchant/checkout \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
88% confidence
Finding

The auto-approved response format confirms that a purchase may complete solely based on allowance logic. While this is consistent with the product design, exposing and normalizing immediate approval behavior in agent instructions increases the likelihood that agents will treat spending as routine and execute without adequate safeguards.

Content

Scanner excerpt · self-hosted-card.md (reported line 57)May include surrounding context.

| category | No | Spending category | | task_id | No | Your internal task reference |

Response (Auto-Approved — Within Allowance)

json
{

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
92% confidence
Finding

Allowance thresholds that permit no-confirmation spending are inherently risky in an agentic wallet context because they create standing delegated authority. If the agent is manipulated, misaligned, or operates on ambiguous instructions, repeated low-value transactions can still cause substantial financial loss.

Content

Scanner excerpt · self-hosted-card.md (reported line 111)May include surrounding context.

md
## Allowance Thresholds

Your owner sets a per-profile allowance threshold for each card. Purchases within this threshold are auto-approved — no email confirmation needed. Purchases above it require human approval via a secure email link (15-minute TTL).

Your owner can view and adjust these thresholds from their dashboard at `https://creditclaw.com/app/self-hosted`.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · shopping.md (reported line 51)May include surrounding context.

  1. Check wallet & spending permissions
  2. Confirm purchase details with the user
  3. Submit purchase/checkout request
  4. Handle approval (auto-approved or pending owner approval)
  5. Poll for result if pending
  6. Report outcome to user (tracking info, confirmation, or error)
text

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skill.md (reported line 339)May include surrounding context.

  1. Check wallet & spending permissions
  2. Confirm purchase details with the user
  3. Submit purchase/checkout request
  4. Handle approval (auto-approved or pending owner approval)
  5. Poll for result if pending
  6. Report outcome to user (tracking info, confirmation, or error)
text

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest and description present this as a Stripe/x402 wallet skill, but the body exposes much broader capabilities: shopping across merchants, self-hosted card checkout, and payment-link generation. This scope expansion can mislead operators and downstream policy engines, causing them to grant the skill more trust or permissions than intended.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · skill.md (reported line 32)May include surrounding context.

Follow your human's instructions on how to manage and save skill files. If unsure, you can install locally:

bash
mkdir -p ~/.creditclaw/skills/stripe
curl -s https://creditclaw.com/stripe/skill.md > ~/.creditclaw/skills/stripe/SKILL.md
curl -s https://creditclaw.com/stripe/shopping.md > ~/.creditclaw/skills/stripe/SHOPPING.md
curl -s https://creditclaw.com/stripe/amazon.md > ~/.creditclaw/skills/stripe/AMAZON.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · skill.md (reported line 33)May include surrounding context.

Follow your human's instructions on how to manage and save skill files. If unsure, you can install locally:

bash
mkdir -p ~/.creditclaw/skills/stripe
curl -s https://creditclaw.com/stripe/skill.md > ~/.creditclaw/skills/stripe/SKILL.md
curl -s https://creditclaw.com/stripe/shopping.md > ~/.creditclaw/skills/stripe/SHOPPING.md
curl -s https://creditclaw.com/stripe/amazon.md > ~/.creditclaw/skills/stripe/AMAZON.md
curl -s https://creditclaw.com/stripe/prepaid-wallet.md > ~/.creditclaw/skills/stripe/PREPAID-WALLET.md

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 133)May include surrounding context.

Register to get your API key and a claim token for your human.

bash
curl -X POST https://creditclaw.com/api/v1/bots/register \
  -H "Content-Type: application/json" \
  -d '{
    "bot_name": "my-research-bot",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 223)May include surrounding context.

Recommended interval: every 30 minutes, or before any purchase.

bash
curl https://creditclaw.com/api/v1/bot/status \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY"

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skill.md (reported line 274)May include surrounding context.

"cash_advances" ], "recurring_allowed": false, "notes": "Prefer free tiers before paying. Always check for discount codes. No annual plans without asking me first.", "updated_at": "2026-02-06T18:00:00Z" }

text

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The skill explicitly authorizes autonomous spending under certain approval modes and thresholds. Even with server-side guardrails, enabling delegated financial decisions creates meaningful risk if the agent is prompt-injected, misclassifies a purchase, or the owner misunderstands the configured policy.

Content

Scanner excerpt · skill.md (reported line 281)May include surrounding context.

md
**You must follow these rules:**
- If `approval_mode` is `ask_for_everything`, ask your human before any purchase to get their approval. **New accounts default to this mode.** Your owner can loosen this from their dashboard once they're comfortable.
- If `approval_mode` is `auto_approve_under_threshold`, you may spend freely up to `ask_approval_above_usd`. Anything above that requires owner approval.
- If `approval_mode` is `auto_approve_by_category`, you may spend freely on `approved_categories` within limits. All others require approval.
- **Never** spend on `blocked_categories`. These are hard blocks enforced server-side and will be declined.
- Always read and follow the `notes` field — these are your owner's direct instructions.

Static analysis

No suspicious patterns detected.