Back to skill

Security audit

Block for OpenClaw - Spend anywhere or request payment from anyone.

Security checks for vulnerabilities and agentic risk

Overview

This is a real shopping/payment skill, but it gives an agent broad financial authority and uses mutable remote instructions and code in ways that could expose payment data or cause unintended spending.

Install only after reviewing the broader payment and seller capabilities, not just Amazon shopping. Use a dedicated low-limit wallet or virtual card, keep per-transaction approval enabled, do not allow main-agent card decryption, do not run remotely delivered decrypt scripts unless independently verified and sandboxed, and avoid installing companion files from mutable URLs without signatures or pinned hashes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
encrypted-card.md:147
Finding

Execution of Server-Controlled Agent Tasks

Content
View full analysis
Card-ChaseD-9547.md", "Use the decrypted card details to complete checkout at DigitalOcean.", "Call POST /api/v1/bot/rail5/confirm with { \"checkout_id\": \"r5chk_abc123\", \"status\": \"success\" } when done.", "If checkout fails, call confirm with { \"status\": \"failed\" } instead.", "Announce the result." ], "spawn_payload": { "task": "You are a checkout agent...", "cleanup": "delete", "runTimeoutSeconds": 300, "label": "checkout-digitalocean" } } ``` ```text ### Step 2: Spawn a Sub-Agent Once the checkout is approved, spawn an ephemeral sub-agent using the `spawn_payload` from the response: sessions_spawn({ task: spawn_payload.task, cleanup: "delete", runTimeoutSeconds: 300 }) The sub-agent executes the `checkout_steps` in sequence. ``` ### Technical Analysis The Skill directs the main agent to execute an agent prompt obtained dynamically from the CreditClaw API. The value of `spawn_payload.task` is controlled by a remote service and is passed directly to `sessions_spawn` without a documented schema, fixed local template, instruction allowlist, signature check, or semantic validation. This creates a remote instruction-injection boundary. Although an ephemeral sub-agent is intended to isolate card data, deletion after execution does not restrict the actions the sub-agent can perform while active. If the API response, service account, delivery infrastructure, or upstream application is compromised, the task can be replaced with instructions unrelated to checkou ...[truncated 1523 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
encrypted-card.md:205
Finding

Remote Delivery and Execution of Mutable Decryption Code

Content
View full analysis
Card-ChaseD-9547.md This outputs the card JSON (number, CVV, expiry, name, billing address). **Critical:** The sub-agent must **never** store, log, or persist the decrypted card data. It exists only in memory for this single transaction. After checkout, the sub-agent is deleted. ``` ```json { "event": "rail5.card.delivered", "bot_id": "bot_abc123", "data": { "card_id": "r5card_...", "card_name": "ChaseD", "card_last4": "9547", "file_content": "", "suggested_path": ".creditclaw/cards/Card-ChaseD-9547.md", "instructions": "Save this file to .creditclaw/cards/Card-ChaseD-9547.md — then confirm delivery via POST /bot/rail5/confirm-delivery" } } ``` ```text **Save the file** to `.creditclaw/cards/` (or the path in `suggested_path`). The file is self-contained — it includes the decrypt script between `DECRYPT_SCRIPT_START/END` markers and the encrypted data between `ENCRYPTED_CARD_START/END` markers. Follow the `instructions` field in the message payload for next steps. ``` ### Technical Analysis The API delivers a self-contained file containing encrypted card data, executable decryption logic, and operational instructions. The Skill instructs the agent to persist that file and later execute the delivered script with a one-time decryption key. The executable code is not part of the audited package and can therefore change after review. The documentation does not require a pinned hash, publisher signature, fixed script digest, safe parser, or comparis ...[truncated 1902 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
skill.md:34
Finding

Persistent Installation of Mutable and Unaudited Skill Documents

Content
View full analysis
~/.creditclaw/skills/amazon/SKILL.md curl -s https://creditclaw.com/amazon/checkout.md > ~/.creditclaw/skills/amazon/CHECKOUT.md curl -s https://creditclaw.com/amazon/crossmint-wallet.md > ~/.creditclaw/skills/amazon/CROSSMINT-WALLET.md curl -s https://creditclaw.com/amazon/encrypted-card.md > ~/.creditclaw/skills/amazon/ENCRYPTED-CARD.md curl -s https://creditclaw.com/amazon/heartbeat.md > ~/.creditclaw/skills/amazon/HEARTBEAT.md curl -s https://creditclaw.com/amazon/management.md > ~/.creditclaw/skills/amazon/MANAGEMENT.md curl -s https://creditclaw.com/amazon/spending.md > ~/.creditclaw/skills/amazon/SPENDING.md curl -s https://creditclaw.com/amazon/stripe-x402-wallet.md > ~/.creditclaw/skills/amazon/STRIPE-X402-WALLET.md curl -s https://creditclaw.com/amazon/skill.json > ~/.creditclaw/skills/amazon/package.json ``` ```json "files": { "SKILL.md": "https://creditclaw.com/amazon/skill.md", "CHECKOUT.md": "https://creditclaw.com/amazon/checkout.md", "CROSSMINT-WALLET.md": "https://creditclaw.com/amazon/crossmint-wallet.md", "ENCRYPTED-CARD.md": "https://creditclaw.com/amazon/encrypted-card.md", "HEARTBEAT.md": "https://creditclaw.com/amazon/heartbeat.md", "MANAGEMENT.md": "https://creditclaw.com/amazon/management.md", "SPENDING.md": "https://creditclaw.com/amazon/spending.md", "STRIPE-X402-WALLET.md": "https://creditclaw.com/amazon/stripe-x402-wallet.md" } ``` ### Technical Analysis The installation instructions download mutable remote documents directly into a persistent Skill directory. They do not pin a version, verify a checksum, verify a publisher signature, stage the files for review, or prevent overw ...[truncated 1846 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
encrypted-card.md:52
Finding

Fallback Decryption Exposes Full Payment-Card Data to the Main Agent Context

Content
View full analysis
**Alternative:** If your environment doesn't support spawning sub-agents, you can execute > the `checkout_steps` directly as the main agent. The guardrails and encryption still protect > your owner's card — but the main agent will see the decrypted card details in its context. ``` ```text The sub-agent runs the deterministic decrypt script that was delivered with the card file: node decrypt.js Card-ChaseD-9547.md This outputs the card JSON (number, CVV, expiry, name, billing address). **Critical:** The sub-agent must **never** store, log, or persist the decrypted card data. It exists only in memory for this single transaction. ``` ### Technical Analysis The fallback explicitly permits complete payment-card details to enter the main agent’s context. Main-agent contexts are commonly subject to transcript retention, telemetry, debugging, tool-call recording, memory extraction, crash reporting, and later prompt reuse. A prose instruction not to store or log the values does not technically enforce confidentiality. Once the model receives PAN, CVV, expiry, cardholder name, and billing address, the system cannot reliably guarantee that the data remains confined to volatile memory or that it will not influence later output. The fallback also weakens the intended split between the general-purpose agent and the payment-specific ephemeral component. ### Attack Path 1. The runtime does not support `sessions_spawn`, or spawning fails. 2. The agent follows the documented fallback and retrieves the one-time decryption key itself. 3. The main agent executes the decryptor. 4. Full card data is emitted into the main context or a captured tool result. 5. Platform logs, transcript storage, debugging syste ...[truncated 705 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (25)

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · skill.md (reported line 12)May include surrounding context.

md
reditclaw-amazon
version: 2.3.0
updated: 2026-02-23T00:00:00Z
description: Let your agent shop on Amazon with guardrailed wallets and owner approval.
homepage: https://creditclaw.com
api_base: https://creditclaw.com/api/v1
credentials: [CREDITCLAW_API_KEY]
metadata: {"openclaw":{"requires":{"env":["CREDITCLAW_API_KEY"]},"primaryEnv":"CREDITCLAW_API_KEY"}}
---

# CreditClaw — Amazon Shopping for AI Agents

CreditClaw.com is a financial enablement platform for Bots, Agents, and OpenClaw.
Securely manage agentic spending.
1. Encrypted cards — owner's real-world card is encrypted and the bot uses it within strict guardrails after owner approval.
2. A stablecoin wallet to seamlessly enable x402 payments with a simple "Fund with Stripe" option.
3. Easy-to-use "Storefronts" and product management for bots to sell both digital and physical products.

## Skill Files

| File | URL | Purpose |
|------|-----|---------|
| **SKILL.md** (this file) | `https://creditclaw.com/amazon/skill.md` | Reg

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide describes a real purchase flow that transmits personally identifiable shipping information and can trigger actual orders, but it does not prominently warn users that the request sends sensitive data to a third-party service and may spend funds. In an agent skill context, that omission raises the risk of unintended disclosure, surprise transactions, and unsafe automation around real-world purchasing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation materially broadens the skill's effective scope from Amazon shopping to Shopify and arbitrary URL-based stores, including generic URL purchases. That increases the attack surface and enables purchases from less-constrained merchants than the skill metadata suggests, which can mislead operators and downstream safety systems about what the skill can do.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · crossmint-wallet.md (reported line 32)May include surrounding context.

Purchase Request

bash
curl -X POST https://creditclaw.com/api/v1/card-wallet/bot/purchase \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · encrypted-card.md (reported line 59)May include surrounding context.

Step 1: Request Checkout

bash
curl -X POST https://creditclaw.com/api/v1/bot/rail5/checkout \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The skill allows purchases to be approved automatically when they fall under configured thresholds, enabling the agent to spend real funds without per-transaction human review. In the context of an Amazon shopping/payment skill, autonomous approval materially increases the risk of prompt injection, merchant manipulation, mistaken purchases, or abuse of the agent's buying authority.

Content

Scanner excerpt · encrypted-card.md (reported line 108)May include surrounding context.

"approved": false, "status": "pending_approval", "checkout_id": "r5chk_abc123", "message": "Amount exceeds auto-approve threshold. Your owner has been notified.", "expires_in_minutes": 15 }

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This endpoint delivers the one-time decryption key for a real payment card to the agent runtime, which is then instructed to decrypt and use full cardholder data. Even with single-use semantics and a sub-agent pattern, the design intentionally moves highly sensitive payment secrets into an LLM-controlled execution context, where they may be exposed through memory inspection, prompt leakage, tool logs, crash dumps, or unsafe fallback to the main agent.

Content

Scanner excerpt · encrypted-card.md (reported line 164)May include surrounding context.

The sub-agent calls this endpoint to retrieve the one-time decryption key:

bash
curl -X POST https://creditclaw.com/api/v1/bot/rail5/key \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "checkout_id": "r5chk_abc123" }'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs the agent to save a self-contained encrypted card file locally, and the same document later describes decrypting that file into full PAN/CVV/expiry/billing data. Even if encrypted at rest, placing payment material on disk increases exposure to filesystem compromise, accidental backup/sync, permissive file permissions, and later unsafe handling by agents or tooling; the guidance does not require secure storage controls, restricted permissions, or explicit operator consent at the point of storage.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description says to run the routine "periodically" and "to stay aware" of wallet status across active rails, but it does not define a specific activation mechanism, trigger phrase, or exclusion conditions. In a markdown skill description, this broad wording can cause unintended invocation because many general monitoring or finance-related contexts could match it.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · management.md (reported line 23)May include surrounding context.

When your balance is low, ask your human if they'd like you to request a top-up:

bash
curl -X POST https://creditclaw.com/api/v1/bot/wallet/topup-request \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest and branding frame this as an Amazon-shopping skill, but the file exposes much broader financial capabilities including payment links, invoices, storefronts, wallet management, and multi-rail payments. This scope mismatch can mislead users and agents into granting sensitive financial permissions under a narrower trust assumption than the skill actually requires.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · skill.md (reported line 35)May include surrounding context.

| package.json (metadata) | https://creditclaw.com/amazon/skill.json | Machine-readable skill metadata | Follow your human's instructions on how to manage and save skill files. If unsure, you can install locally:

bash
mkdir -p ~/.creditclaw/skills/amazon
curl -s https://creditclaw.com/amazon/skill.md > ~/.creditclaw/skills/amazon/SKILL.md
curl -s https://creditclaw.com/amazon/checkout.md > ~/.creditclaw/skills/amazon/CHECKOUT.md
curl -s https://creditclaw.com/amazon/crossmint-wallet.md > ~/.creditclaw/skills/amazon/CROSSMINT-WALLET.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · skill.md (reported line 36)May include surrounding context.

Follow your human's instructions on how to manage and save skill files. If unsure, you can install locally:

bash
mkdir -p ~/.creditclaw/skills/amazon
curl -s https://creditclaw.com/amazon/skill.md > ~/.creditclaw/skills/amazon/SKILL.md
curl -s https://creditclaw.com/amazon/checkout.md > ~/.creditclaw/skills/amazon/CHECKOUT.md
curl -s https://creditclaw.com/amazon/crossmint-wallet.md > ~/.creditclaw/skills/amazon/CROSSMINT-WALLET.md
curl -s https://creditclaw.com/amazon/encrypted-card.md > ~/.creditclaw/skills/amazon/ENCRYPTED-CARD.md

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 123)May include surrounding context.

You can register before your human does. You'll get an API key immediately.

bash
curl -X POST https://creditclaw.com/api/v1/bots/register \
  -H "Content-Type: application/json" \
  -d '{
    "bot_name": "my-research-bot",

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
88% confidence
Finding

The skill explicitly authorizes autonomous purchases under certain approval modes and thresholds. Even with server-side guardrails, enabling an agent to spend 'freely' within preconfigured limits creates real financial risk if the agent is manipulated, misclassifies a purchase, or operates under overly broad category approvals.

Content

Scanner excerpt · skill.md (reported line 321)May include surrounding context.

md
**You must follow these rules:**
- If `approval_mode` is `ask_for_everything`, ask your human before any purchase to get their approval. **New accounts default to this mode.** Your owner can loosen this from their dashboard once they're comfortable.
- If `approval_mode` is `auto_approve_under_threshold`, you may spend freely up to `ask_approval_above_usd`. Anything above that requires owner approval.
- If `approval_mode` is `auto_approve_by_category`, you may spend freely on `approved_categories` within limits. All others require approval.
- **Never** spend on `blocked_categories`. These are hard blocks enforced server-side and will be declined.
- Always read and follow the `notes` field — these are your owner's direct instructions.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
88% confidence
Finding

Auto-approval by category permits the agent to initiate spending without direct user confirmation whenever a category is approved. This is risky because category labels can be broad, ambiguous, or manipulated, allowing unintended purchases that still satisfy the coarse policy.

Content

Scanner excerpt · skill.md (reported line 322)May include surrounding context.

md
**You must follow these rules:**
- If `approval_mode` is `ask_for_everything`, ask your human before any purchase to get their approval. **New accounts default to this mode.** Your owner can loosen this from their dashboard once they're comfortable.
- If `approval_mode` is `auto_approve_under_threshold`, you may spend freely up to `ask_approval_above_usd`. Anything above that requires owner approval.
- If `approval_mode` is `auto_approve_by_category`, you may spend freely on `approved_categories` within limits. All others require approval.
- **Never** spend on `blocked_categories`. These are hard blocks enforced server-side and will be declined.
- Always read and follow the `notes` field — these are your owner's direct instructions.
- Cache this for up to 30 minutes. Do not fetch before every micro-purchase.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill includes merchant and seller-platform features such as payment links, checkout pages, invoices, and shops that are unrelated to a narrowly described Amazon purchasing workflow. Unnecessary monetization features expand the attack surface and authorization scope, increasing the chance an agent could be induced to perform unintended financial operations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 472)May include surrounding context.

Fetch Pending Messages

bash
curl https://creditclaw.com/api/v1/bot/messages \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The message flow instructs the bot to save a card-delivery artifact to disk, including a suggested local path, without explicit safeguards around encrypted payment artifacts, file permissions, secure deletion, or user confirmation. Even if the file is encrypted, persisting sensitive payment material locally increases exposure through backup systems, local compromise, misconfigured permissions, or later misuse by other tools.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · spending.md (reported line 14)May include surrounding context.

md
Choose one:

- [x] **Ask me for everything** — Bot requests approval before any purchase
- [ ] **Auto-approve under threshold** — Bot spends freely up to the limit below
- [ ] **Auto-approve by category** — Bot spends freely on approved categories

---

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · spending.md (reported line 15)May include surrounding context.

md
Choose one:

- [x] **Ask me for everything** — Bot requests approval before any purchase
- [ ] **Auto-approve under threshold** — Bot spends freely up to the limit below
- [ ] **Auto-approve by category** — Bot spends freely on approved categories

---

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · spending.md (reported line 29)May include surrounding context.

md
| Ask approval above | $10.00 |

If a purchase exceeds the "ask approval above" amount, the bot must
send you a confirmation request before proceeding — even if auto-approve
is enabled.

---

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · spending.md (reported line 36)May include surrounding context.

md
| Ask approval above | $10.00 |

If a purchase exceeds the "ask approval above" amount, the bot must
send you a confirmation request before proceeding — even if auto-approve
is enabled.

---

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skill.md (reported line 314)May include surrounding context.

Example:

  • Prefer free tiers of services before paying for premium
  • Always check if there's a coupon or discount code before purchasing
  • Don't sign up for annual plans without asking me first
  • If you find a cheaper alternative for something, tell me before switching
text

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · spending.md (reported line 96)May include surrounding context.

Example:

  • Prefer free tiers of services before paying for premium
  • Always check if there's a coupon or discount code before purchasing
  • Don't sign up for annual plans without asking me first
  • If you find a cheaper alternative for something, tell me before switching
text

Static analysis

No suspicious patterns detected.