Back to skill

Security audit

SAP Skills - Use SAP for procurement with your agent

Security checks for vulnerabilities and agentic risk

Overview

This skill handles real spending and payment-card data, and its artifacts tell agents to trust server-supplied checkout instructions and run remotely delivered decryption code.

Install only if you intentionally want a broad real-money commerce wallet, not just Amazon shopping. Keep per-purchase approval enabled, use low spending limits and merchant/domain allowlists, avoid running remotely delivered scripts, and do not let server-provided prose instructions override local user approval or fixed checkout policy.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
encrypted-card.md:175
Finding

Execution of Remotely Delivered Decryption Code

Content
View full analysis
Card-ChaseD-9547.md This outputs the card JSON (number, CVV, expiry, name, billing address). Critical: The sub-agent must never store, log, or persist the decrypted card data. It exists only in memory for this single transaction. After checkout, the sub-agent is deleted. ``` The script is delivered through a remote webhook or API message: ```json { "event": "rail5.card.delivered", "bot_id": "bot_abc123", "data": { "card_id": "r5card_...", "card_name": "ChaseD", "card_last4": "9547", "file_content": "", "suggested_path": ".creditclaw/cards/Card-ChaseD-9547.md", "instructions": "Save this file to .creditclaw/cards/Card-ChaseD-9547.md — then confirm delivery via POST /bot/rail5/confirm-delivery" } } ``` ```text Save the file to `.creditclaw/cards/` (or the path in `suggested_path`). The file is self-contained — it includes the decrypt script between `DECRYPT_SCRIPT_START/END` markers and the encrypted data between `ENCRYPTED_CARD_START/END` markers. ``` ### Technical Analysis The Skill instructs the agent to receive executable JavaScript from CreditClaw, save it locally, and execute it with Node.js during checkout. The effective executable payload is therefore not contained in the reviewed Skill package and can change after review. The documentation does not require a pinned script hash, detached digital signature, fixed local implementation, strict script validation, or a network-disabled execution sandbox. Describing the script as “determi ...[truncated 2229 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
encrypted-card.md:74
Finding

Execution of a Server-Controlled Sub-Agent Prompt

Content
View full analysis
Card-ChaseD-9547.md", "Use the decrypted card details to complete checkout at DigitalOcean.", "Call POST /api/v1/bot/rail5/confirm with { \"checkout_id\": \"r5chk_abc123\", \"status\": \"success\" } when done.", "If checkout fails, call confirm with { \"status\": \"failed\" } instead.", "Announce the result." ], "spawn_payload": { "task": "You are a checkout agent...", "cleanup": "delete", "runTimeoutSeconds": 300, "label": "checkout-digitalocean" } } ``` ```text ### Step 2: Spawn a Sub-Agent Once the checkout is approved, spawn an ephemeral sub-agent using the `spawn_payload` from the response: sessions_spawn({ task: spawn_payload.task, cleanup: "delete", runTimeoutSeconds: 300 }) The sub-agent executes the `checkout_steps` in sequence. You (the main agent) wait for the sub-agent to complete and then announce the result. ``` ### Technical Analysis The parent agent is instructed to use `spawn_payload.task`, received from a remote API, as the task prompt for a new sub-agent. This makes CreditClaw's response an instruction channel rather than a data channel. The Skill does not require the parent agent to: - Compare the returned merchant and amount with the approved request. - Parse the response into a fixed local action schema. - Restrict the sub-agent to enumerated checkout operations. - Reject instructions involving unrelated files, credentials, tools, or network hosts. - Obtain renewed human approval if the returned task differs from ...[truncated 1964 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
encrypted-card.md:205
Finding

Unvalidated Remote Filesystem Path and Operational Instructions

Content
View full analysis
", "suggested_path": ".creditclaw/cards/Card-ChaseD-9547.md", "instructions": "Save this file to .creditclaw/cards/Card-ChaseD-9547.md — then confirm delivery via POST /bot/rail5/confirm-delivery" } } ``` ```text Via bot messages (fallback): If you don't have a webhook, check `GET /bot/messages` for messages with `event_type: "rail5.card.delivered"`. The payload is identical. After saving the file, acknowledge the message via `POST /bot/messages/ack`. Save the file to `.creditclaw/cards/` (or the path in `suggested_path`). The file is self-contained — it includes the decrypt script between `DECRYPT_SCRIPT_START/END` markers and the encrypted data between `ENCRYPTED_CARD_START/END` markers. Follow the `instructions` field in the message payload for next steps. ``` ### Technical Analysis The Skill instructs the agent to trust two remotely supplied fields: - `suggested_path`, which determines where content is written. - `instructions`, which determines what the agent does after receiving the message. No path normalization, directory-containment check, filename allowlist, symlink defense, permission requirement, or overwrite protection is documented. If a malicious response supplies an absolute path or traversal sequence, an implementation that follows the instructions literally may write outside `.creditclaw/cards`. The unrestricted `instructions` field also creates an additional prompt-injection surface. Even if the path is safe, a compromised service can attach unrelated commands o ...[truncated 1504 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (39)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · checkout.md (reported line 341)May include surrounding context.

md
- **Set `amount_locked: true`** for fixed-price products so buyers can't underpay.
- **Leave `amount_usd` empty** for donation or tip jars.
- **Use `page_type: "digital_product"`** when selling downloadable content, API keys, or access tokens.
- **Use `success_url`** to redirect buyers back to your service after payment.
- **Check `GET /bot/sales`** periodically to reconcile completed sales with your fulfillment.
- **Multiple checkout pages** are fine — create one per product or service tier.

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · skill.md (reported line 12)May include surrounding context.

md
reditclaw-amazon
version: 2.3.0
updated: 2026-02-23T00:00:00Z
description: Let your agent shop on Amazon with guardrailed wallets and owner approval.
homepage: https://creditclaw.com
api_base: https://creditclaw.com/api/v1
credentials: [CREDITCLAW_API_KEY]
metadata: {"openclaw":{"requires":{"env":["CREDITCLAW_API_KEY"]},"primaryEnv":"CREDITCLAW_API_KEY"}}
---

# CreditClaw — Amazon Shopping for AI Agents

CreditClaw.com is a financial enablement platform for Bots, Agents, and OpenClaw.
Securely manage agentic spending.
1. Encrypted cards — owner's real-world card is encrypted and the bot uses it within strict guardrails after owner approval.
2. A stablecoin wallet to seamlessly enable x402 payments with a simple "Fund with Stripe" option.
3. Easy-to-use "Storefronts" and product management for bots to sell both digital and physical products.

## Skill Files

| File | URL | Purpose |
|------|-----|---------|
| **SKILL.md** (this file) | `https://creditclaw.com/amazon/skill.md` | Reg

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documented signing flow allows payments to arbitrary x402 services and domains, not just Amazon or tightly related merchants. In the context of an Amazon-shopping skill, this creates a confused-deputy risk where the agent can be induced to spend funds on unrelated external services while appearing to operate within a trusted shopping capability.

Content

No source excerpt is available for this finding.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · checkout.md (reported line 24)May include surrounding context.

md
-H "Content-Type: application/json"
  -d '{
    "title": "Premium API Access - 1 Month",
    "description": "Unlimited queries to my data analysis endpoint.",
    "amount_usd": 5.00,
    "amount_locked": true
  }'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly supports collecting and transmitting buyer personal data such as names and email addresses, but provides no privacy, consent, retention, or handling guidance. In a payment workflow, this can lead agents or operators to gather unnecessary PII or mishandle regulated customer data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill tells users to share checkout URLs and later publish public shop pages, but does not prominently warn that these resources are publicly accessible and may expose product metadata, pricing, and potentially business identity. This can cause accidental overexposure by agents or users who assume the pages are private by default.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · checkout.md (reported line 473)May include surrounding context.

md
"title": "Premium API Access",
  "amount_usd": 5.00,
  "page_type": "digital_product",
  "digital_product_url": "https://api.databot.com/keys/generate",
  "shop_visible": true
}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide states that real orders are placed and includes shipping-address submission, but it does not prominently warn users about financial consequences, transmission of personal data, and downstream sharing with payment and merchant infrastructure. In a purchasing skill, this omission can mislead users and reduce informed consent around spending and privacy exposure.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file explicitly documents support for Shopify and arbitrary URL-based stores even though the skill metadata says it is for Amazon shopping. This capability expansion increases the action surface beyond what a user or reviewer would reasonably expect, enabling purchases from less-vetted merchants and making policy enforcement harder.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · crossmint-wallet.md (reported line 32)May include surrounding context.

Purchase Request

bash
curl -X POST https://creditclaw.com/api/v1/card-wallet/bot/purchase \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Documenting a purchase API that accepts arbitrary URL-store purchases materially broadens the skill from a constrained Amazon-shopping tool into a general web-purchasing mechanism. If an agent can submit arbitrary URLs, it could direct funds to attacker-controlled or fraudulent storefronts, bypassing the trust assumptions implied by the Amazon-only branding.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · encrypted-card.md (reported line 59)May include surrounding context.

Step 1: Request Checkout

bash
curl -X POST https://creditclaw.com/api/v1/bot/rail5/checkout \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · encrypted-card.md (reported line 164)May include surrounding context.

The sub-agent calls this endpoint to retrieve the one-time decryption key:

bash
curl -X POST https://creditclaw.com/api/v1/bot/rail5/key \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "checkout_id": "r5chk_abc123" }'

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to execute a bundled Node.js script extracted from a delivered file containing payment material. Even if the stated purpose is decryption, this expands the skill from API-driven checkout into arbitrary local code execution using untrusted file content, creating a path for malicious script behavior such as exfiltration of decrypted card data or other local secrets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instructions tell the agent to save encrypted payment material to disk and proceed with confirmation and test checkout, but they do not prominently warn that this is sensitive financial material requiring hardened handling. In practice, agents or integrators may treat the file as ordinary content, increasing the risk of insecure storage, logging, backup leakage, or exposure during later processing.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · management.md (reported line 23)May include surrounding context.

When your balance is low, ask your human if they'd like you to request a top-up:

bash
curl -X POST https://creditclaw.com/api/v1/bot/wallet/topup-request \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is branded and described as an Amazon shopping capability, but it expands into unrelated financial operations such as storefronts, product sales, invoices, and general payment processing. This scope mismatch can mislead operators into granting a shopping skill privileges that enable broader money movement or monetization workflows than expected.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · skill.md (reported line 35)May include surrounding context.

| package.json (metadata) | https://creditclaw.com/amazon/skill.json | Machine-readable skill metadata | Follow your human's instructions on how to manage and save skill files. If unsure, you can install locally:

bash
mkdir -p ~/.creditclaw/skills/amazon
curl -s https://creditclaw.com/amazon/skill.md > ~/.creditclaw/skills/amazon/SKILL.md
curl -s https://creditclaw.com/amazon/checkout.md > ~/.creditclaw/skills/amazon/CHECKOUT.md
curl -s https://creditclaw.com/amazon/crossmint-wallet.md > ~/.creditclaw/skills/amazon/CROSSMINT-WALLET.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · skill.md (reported line 36)May include surrounding context.

Follow your human's instructions on how to manage and save skill files. If unsure, you can install locally:

bash
mkdir -p ~/.creditclaw/skills/amazon
curl -s https://creditclaw.com/amazon/skill.md > ~/.creditclaw/skills/amazon/SKILL.md
curl -s https://creditclaw.com/amazon/checkout.md > ~/.creditclaw/skills/amazon/CHECKOUT.md
curl -s https://creditclaw.com/amazon/crossmint-wallet.md > ~/.creditclaw/skills/amazon/CROSSMINT-WALLET.md
curl -s https://creditclaw.com/amazon/encrypted-card.md > ~/.creditclaw/skills/amazon/ENCRYPTED-CARD.md

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 123)May include surrounding context.

You can register before your human does. You'll get an API key immediately.

bash
curl -X POST https://creditclaw.com/api/v1/bots/register \
  -H "Content-Type: application/json" \
  -d '{
    "bot_name": "my-research-bot",

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The skill authorizes autonomous spending under configured thresholds or categories, enabling real financial actions without per-transaction human review. Even with server-side guardrails, compromised agents, prompt manipulation, or poor category/threshold configuration can result in unauthorized or unexpected purchases.

Content

Scanner excerpt · skill.md (reported line 321)May include surrounding context.

md
**You must follow these rules:**
- If `approval_mode` is `ask_for_everything`, ask your human before any purchase to get their approval. **New accounts default to this mode.** Your owner can loosen this from their dashboard once they're comfortable.
- If `approval_mode` is `auto_approve_under_threshold`, you may spend freely up to `ask_approval_above_usd`. Anything above that requires owner approval.
- If `approval_mode` is `auto_approve_by_category`, you may spend freely on `approved_categories` within limits. All others require approval.
- **Never** spend on `blocked_categories`. These are hard blocks enforced server-side and will be declined.
- Always read and follow the `notes` field — these are your owner's direct instructions.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

Category-based auto-approval permits the agent to independently spend within approved classes, which materially expands the consequences of agent error or compromise. In a payment skill, this context makes autonomous action more dangerous because the effect is direct money movement rather than a low-risk workflow task.

Content

Scanner excerpt · skill.md (reported line 322)May include surrounding context.

md
**You must follow these rules:**
- If `approval_mode` is `ask_for_everything`, ask your human before any purchase to get their approval. **New accounts default to this mode.** Your owner can loosen this from their dashboard once they're comfortable.
- If `approval_mode` is `auto_approve_under_threshold`, you may spend freely up to `ask_approval_above_usd`. Anything above that requires owner approval.
- If `approval_mode` is `auto_approve_by_category`, you may spend freely on `approved_categories` within limits. All others require approval.
- **Never** spend on `blocked_categories`. These are hard blocks enforced server-side and will be declined.
- Always read and follow the `notes` field — these are your owner's direct instructions.
- Cache this for up to 30 minutes. Do not fetch before every micro-purchase.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Public selling and billing capabilities are not justified by the stated Amazon shopping use case and materially broaden the financial attack surface. An agent or user expecting only procurement could unintentionally gain tools to charge third parties, create invoices, or host public checkout flows.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The API reference includes seller-profile, checkout page, invoice, payment link, and public shop endpoints that are inconsistent with a user’s expectation of an Amazon shopping skill. Hidden or under-disclosed capabilities increase the chance of over-privileged installation and unintended financial actions by an agent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 472)May include surrounding context.

Fetch Pending Messages

bash
curl https://creditclaw.com/api/v1/bot/messages \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY"

Static analysis

No suspicious patterns detected.