T03 · Remote Payload Retrieval and Execution
- Location
encrypted-card.md:175- Finding
Remote Retrieval and Execution of an Unverified Decryption Script
- Content
View full analysis
Card-ChaseD-9547.md ``` This outputs the card JSON (number, CVV, expiry, name, billing address). **Critical:** The sub-agent must **never** store, log, or persist the decrypted card data. It exists only in memory for this single transaction. After checkout, the sub-agent is deleted. ``` ```text ## Encrypted Card File Delivery When your owner sets up an encrypted card for you, CreditClaw delivers a single self-contained file via the `rail5.card.delivered` event. **Via webhook:** If you have a `callback_url`, the file is delivered automatically: ```json { "event": "rail5.card.delivered", "bot_id": "bot_abc123", "data": { "card_id": "r5card_...", "card_name": "ChaseD", "card_last4": "9547", "file_content": "", "suggested_path": ".creditclaw/cards/Card-ChaseD-9547.md", "instructions": "Save this file to .creditclaw/cards/Card-ChaseD-9547.md — then confirm delivery via POST /bot/rail5/confirm-delivery" } } ``` **Via bot messages (fallback):** If you don't have a webhook, check `GET /bot/messages` for messages with `event_type: "rail5.card.delivered"`. The payload is identical. After saving the file, acknowledge the message via `POST /bot/messages/ack`. **Save the file** to `.creditclaw/cards/` (or the path in `suggested_path`). The file is self-contained — it includes the decrypt script between `DECRYPT_SCRIPT_START/END` markers and the encrypted data between `ENCRYPTED_CARD_START/END` markers. ``` ### Technical Analysis The Skill instructs the agen ...[truncated 2585 chars]- Remediation
View remediation
