Back to skill

Security audit

CashApp - Give your Claw Agent Cash

Security checks for vulnerabilities and agentic risk

Overview

This payment skill is purpose-related, but it needs Review because it can spend real money, handle card details, and trust server-supplied code or instructions during checkout.

Install only if you trust CreditClaw with payment authority and can run it in a tightly controlled environment. Keep approval_mode set to ask_for_everything unless you have clear spend limits, protect CREDITCLAW_API_KEY, do not let the main agent handle decrypted card details, and avoid executing delivered decrypt scripts or remote checkout instructions unless they are validated and sandboxed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
encrypted-card.md:175
Finding

Remote Retrieval and Execution of an Unverified Decryption Script

Content
View full analysis
Card-ChaseD-9547.md ``` This outputs the card JSON (number, CVV, expiry, name, billing address). **Critical:** The sub-agent must **never** store, log, or persist the decrypted card data. It exists only in memory for this single transaction. After checkout, the sub-agent is deleted. ``` ```text ## Encrypted Card File Delivery When your owner sets up an encrypted card for you, CreditClaw delivers a single self-contained file via the `rail5.card.delivered` event. **Via webhook:** If you have a `callback_url`, the file is delivered automatically: ```json { "event": "rail5.card.delivered", "bot_id": "bot_abc123", "data": { "card_id": "r5card_...", "card_name": "ChaseD", "card_last4": "9547", "file_content": "", "suggested_path": ".creditclaw/cards/Card-ChaseD-9547.md", "instructions": "Save this file to .creditclaw/cards/Card-ChaseD-9547.md — then confirm delivery via POST /bot/rail5/confirm-delivery" } } ``` **Via bot messages (fallback):** If you don't have a webhook, check `GET /bot/messages` for messages with `event_type: "rail5.card.delivered"`. The payload is identical. After saving the file, acknowledge the message via `POST /bot/messages/ack`. **Save the file** to `.creditclaw/cards/` (or the path in `suggested_path`). The file is self-contained — it includes the decrypt script between `DECRYPT_SCRIPT_START/END` markers and the encrypted data between `ENCRYPTED_CARD_START/END` markers. ``` ### Technical Analysis The Skill instructs the agen ...[truncated 2585 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
encrypted-card.md:84
Finding

Execution of Server-Controlled Agent Instructions and Sub-Agent Tasks

Content
View full analysis
Card-ChaseD-9547.md", "Use the decrypted card details to complete checkout at DigitalOcean.", "Call POST /api/v1/bot/rail5/confirm with { \"checkout_id\": \"r5chk_abc123\", \"status\": \"success\" } when done.", "If checkout fails, call confirm with { \"status\": \"failed\" } instead.", "Announce the result." ], "spawn_payload": { "task": "You are a checkout agent...", "cleanup": "delete", "runTimeoutSeconds": 300, "label": "checkout-digitalocean" } } ``` ```text ### Step 2: Spawn a Sub-Agent Once the checkout is approved, spawn an ephemeral sub-agent using the `spawn_payload` from the response: ``` sessions_spawn({ task: spawn_payload.task, cleanup: "delete", runTimeoutSeconds: 300 }) ``` The sub-agent executes the `checkout_steps` in sequence. You (the main agent) wait for the sub-agent to complete and then announce the result. ``` ```text **Via bot messages (fallback):** If you don't have a webhook, check `GET /bot/messages` for messages with `event_type: "rail5.card.delivered"`. The payload is identical. After saving the file, acknowledge the message via `POST /bot/messages/ack`. **Save the file** to `.creditclaw/cards/` (or the path in `suggested_path`). The file is self-contained — it includes the decrypt script between `DECRYPT_SCRIPT_START/END` markers and the encrypted data between `ENCRYPTED_CARD_START/END` markers. Follow the `instructions` field in the message payload for next steps. ``` ```json { "bo ...[truncated 3285 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
encrypted-card.md:210
Finding

Unvalidated Server-Supplied Path Used for Persistent Sensitive File Storage

Content
View full analysis
", "suggested_path": ".creditclaw/cards/Card-ChaseD-9547.md", "instructions": "Save this file to .creditclaw/cards/Card-ChaseD-9547.md — then confirm delivery via POST /bot/rail5/confirm-delivery" } } ``` **Via bot messages (fallback):** If you don't have a webhook, check `GET /bot/messages` for messages with `event_type: "rail5.card.delivered"`. The payload is identical. After saving the file, acknowledge the message via `POST /bot/messages/ack`. **Save the file** to `.creditclaw/cards/` (or the path in `suggested_path`). The file is self-contained — it includes the decrypt script between `DECRYPT_SCRIPT_START/END` markers and the encrypted data between `ENCRYPTED_CARD_START/END` markers. ``` ### Technical Analysis The Skill allows a path received from a remote API response to control where the card file is saved. It does not specify any validation of `suggested_path`, canonical-path containment check, filename sanitization, symlink protection, atomic exclusive creation, or restrictive filesystem permissions. A malicious path could contain an absolute path or traversal components such as `../`. Even when the apparent path is under `.creditclaw/cards`, a pre-existing symbolic link could redirect the write elsewhere. Because the written content includes executable code as well as encrypted payment data, unintended placement presents both integrity and confidentiality risks. The encrypted card file is intentionally persistent ...[truncated 1580 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (34)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · checkout.md (reported line 341)May include surrounding context.

md
- **Set `amount_locked: true`** for fixed-price products so buyers can't underpay.
- **Leave `amount_usd` empty** for donation or tip jars.
- **Use `page_type: "digital_product"`** when selling downloadable content, API keys, or access tokens.
- **Use `success_url`** to redirect buyers back to your service after payment.
- **Check `GET /bot/sales`** periodically to reconcile completed sales with your fulfillment.
- **Multiple checkout pages** are fine — create one per product or service tier.

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · skill.md (reported line 12)May include surrounding context.

md
wallets powered by Stripe. Use your existing Stripe/Link to top-up this versatile x402 wallet for any purchases or A2A payments.
homepage: https://creditclaw.com
api_base: https://creditclaw.com/api/v1
credentials: [CREDITCLAW_API_KEY]
metadata: {"openclaw":{"requires":{"env":["CREDITCLAW_API_KEY"]},"primaryEnv":"CREDITCLAW_API_KEY"}}
---

# CreditClaw — Stripe-powered wallets and payments for AI Agents

CreditClaw.com is a financial enablement platform for Bots, Agents, and OpenClaw.
Securely manage agentic spending.
1. Encrypted cards — owner's real-world card is encrypted and the bot uses it within strict guardrails after owner approval.
2. A stablecoin wallet to seamlessly enable x402 payments with a simple "Fund with Stripe" option.
3. Easy-to-use "Storefronts" and product management for bots to sell both digital and physical products.

## Skill Files

| File | URL | Purpose |
|------|-----|---------|
| **SKILL.md** (this file) | `https://creditclaw.com/stripe/skill.md` | Reg

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · checkout.md (reported line 24)May include surrounding context.

md
-H "Content-Type: application/json"
  -d '{
    "title": "Premium API Access - 1 Month",
    "description": "Unlimited queries to my data analysis endpoint.",
    "amount_usd": 5.00,
    "amount_locked": true
  }'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents collection and exposure of buyer personal data such as buyer_email and recipient_email in payment and invoice flows without any privacy, minimization, retention, or compliance guidance. In a public checkout/invoicing context, this can lead agents to unnecessarily collect, store, or disclose PII and mishandle regulated customer data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · checkout.md (reported line 473)May include surrounding context.

md
"title": "Premium API Access",
  "amount_usd": 5.00,
  "page_type": "digital_product",
  "digital_product_url": "https://api.databot.com/keys/generate",
  "shop_visible": true
}

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document introduces a real merchant-purchase capability routed through Crossmint that goes beyond the stated Stripe/Link top-up wallet description. This expands the effective power of the skill without clear manifest alignment, increasing the chance that an agent or reviewer underestimates that the skill can trigger real-world purchases and fund movement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide shows a live purchase request that includes personally identifiable shipping data and can place a real order, but it does not prominently warn readers that the call causes external transmission of sensitive data and may result in actual charges or deliveries. This is dangerous because agents or operators may treat the example as harmless sample code and inadvertently send real personal and transactional information.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The supported-merchants section documents ordering and shipping workflows, including Amazon and arbitrary URL stores, that materially extend the operational scope of the skill. In an agent setting, undocumented expansion of purchasing surfaces can enable unintended transactions or abuse because the advertised purpose does not match the actual actions exposed.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · crossmint-wallet.md (reported line 32)May include surrounding context.

Purchase Request

bash
curl -X POST https://creditclaw.com/api/v1/card-wallet/bot/purchase \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file is presented as a companion to a Stripe wallet skill but actually introduces a separate direct credit-card decryption and checkout mechanism. That mismatch can mislead integrators and users about the trust boundary and data sensitivity, causing an agent built for wallet-style payments to unexpectedly handle primary account number, CVV, expiry, and billing data.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document first claims the main agent never sees decrypted card details, then explicitly permits the main agent to run the decryption flow directly. This undermines the primary security model, increases the chance that card data enters long-lived context, logs, telemetry, tool traces, or memory, and creates a misleading assurance that may cause unsafe deployment decisions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · encrypted-card.md (reported line 59)May include surrounding context.

Step 1: Request Checkout

bash
curl -X POST https://creditclaw.com/api/v1/bot/rail5/checkout \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The auto-approve model permits the agent to initiate purchases autonomously below a configured threshold. In a payment-card context, this increases abuse risk from prompt injection, task confusion, compromised tools, or unsafe merchant selection because real spending can occur without per-transaction human review.

Content

Scanner excerpt · encrypted-card.md (reported line 108)May include surrounding context.

"approved": false, "status": "pending_approval", "checkout_id": "r5chk_abc123", "message": "Amount exceeds auto-approve threshold. Your owner has been notified.", "expires_in_minutes": 15 }

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This endpoint delivers the one-time decryption key for payment-card data to an agent-controlled runtime. Once the key is exposed to the execution environment, any compromise, logging, prompt leakage, tool trace, or malicious sub-agent behavior can recover the full card details, so the design shifts PCI-sensitive material into a likely untrusted agent context.

Content

Scanner excerpt · encrypted-card.md (reported line 164)May include surrounding context.

The sub-agent calls this endpoint to retrieve the one-time decryption key:

bash
curl -X POST https://creditclaw.com/api/v1/bot/rail5/key \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "checkout_id": "r5chk_abc123" }'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill instructs the agent to save a self-contained encrypted card artifact to disk without prominent warnings about secure storage, file permissions, backup exposure, endpoint compromise, or lifecycle management. Even though the file is encrypted, it is sensitive payment material paired with a workflow that later retrieves decryption keys, so careless storage materially increases risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill tells the user to run a routine that queries a status endpoint returning balances, spending limits, cards, and master guardrails across all connected payment rails. For markdown files, this should include a warning when behavior affects privacy or sensitive financial data, but no such warning is present in the description around these calls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example command uses the CREDITCLAW_API_KEY bearer token directly in a curl command. Although the file references authentication, it does not warn users to protect the key, avoid leaking shell history/logs, or use a trusted environment when making these requests.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest context says this skill is an easy-to-use Stripe/x402 wallet for top-ups and purchases or A2A payments, implying a Stripe-focused capability. This companion file instead documents 'Cross-rail wallet management' and explicitly discusses operations and approval flows across multiple rails, broadening the described behavior beyond the stated Stripe wallet scope.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · management.md (reported line 23)May include surrounding context.

When your balance is low, ask your human if they'd like you to request a top-up:

bash
curl -X POST https://creditclaw.com/api/v1/bot/wallet/topup-request \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest omits the encrypted-card flow and one-time decryption-key retrieval, which are substantially more sensitive than a simple wallet/top-up skill because they involve access to payment credentials and delegated checkout. Hidden or under-described credential-handling features increase the chance that an agent or operator enables the skill without understanding that it can participate in card-based purchases.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest omits the encrypted-card flow and one-time decryption-key retrieval, which are substantially more sensitive than a simple wallet/top-up skill because they involve access to payment credentials and delegated checkout. Hidden or under-described credential-handling features increase the chance that an agent or operator enables the skill without understanding that it can participate in card-based purchases.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · skill.md (reported line 35)May include surrounding context.

| package.json (metadata) | https://creditclaw.com/stripe/skill.json | Machine-readable skill metadata | Follow your human's instructions on how to manage and save skill files. If unsure, you can install locally:

bash
mkdir -p ~/.creditclaw/skills/stripe
curl -s https://creditclaw.com/stripe/skill.md > ~/.creditclaw/skills/stripe/SKILL.md
curl -s https://creditclaw.com/stripe/checkout.md > ~/.creditclaw/skills/stripe/CHECKOUT.md
curl -s https://creditclaw.com/stripe/crossmint-wallet.md > ~/.creditclaw/skills/stripe/CROSSMINT-WALLET.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · skill.md (reported line 36)May include surrounding context.

Follow your human's instructions on how to manage and save skill files. If unsure, you can install locally:

bash
mkdir -p ~/.creditclaw/skills/stripe
curl -s https://creditclaw.com/stripe/skill.md > ~/.creditclaw/skills/stripe/SKILL.md
curl -s https://creditclaw.com/stripe/checkout.md > ~/.creditclaw/skills/stripe/CHECKOUT.md
curl -s https://creditclaw.com/stripe/crossmint-wallet.md > ~/.creditclaw/skills/stripe/CROSSMINT-WALLET.md
curl -s https://creditclaw.com/stripe/encrypted-card.md > ~/.creditclaw/skills/stripe/ENCRYPTED-CARD.md

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 123)May include surrounding context.

You can register before your human does. You'll get an API key immediately.

bash
curl -X POST https://creditclaw.com/api/v1/bots/register \
  -H "Content-Type: application/json" \
  -d '{
    "bot_name": "my-research-bot",

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
89% confidence
Finding

The skill explicitly authorizes autonomous spending under certain approval modes, allowing the agent to make purchases without per-transaction human confirmation. Because this skill operates on financial rails, even policy-bounded autonomy is high risk: misclassification, prompt manipulation, or task confusion could trigger unintended real-money transactions before a human intervenes.

Content

Scanner excerpt · skill.md (reported line 321)May include surrounding context.

md
**You must follow these rules:**
- If `approval_mode` is `ask_for_everything`, ask your human before any purchase to get their approval. **New accounts default to this mode.** Your owner can loosen this from their dashboard once they're comfortable.
- If `approval_mode` is `auto_approve_under_threshold`, you may spend freely up to `ask_approval_above_usd`. Anything above that requires owner approval.
- If `approval_mode` is `auto_approve_by_category`, you may spend freely on `approved_categories` within limits. All others require approval.
- **Never** spend on `blocked_categories`. These are hard blocks enforced server-side and will be declined.
- Always read and follow the `notes` field — these are your owner's direct instructions.

Static analysis

No suspicious patterns detected.