Back to skill

Security audit

Buy any shopify product with your claw

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly transparent about shopping with guarded wallets, but it needs review because it gives agents sensitive financial authority beyond a simple shopping description.

Install only if you intentionally want an agent to handle real purchases and payment flows. Keep the default ask-for-everything mode, set low spending limits, restrict merchants/categories/domains, protect CREDITCLAW_API_KEY as a spending credential, and review payment-link or x402 use separately before enabling it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (34)

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · skill.md (reported line 12)May include surrounding context.

md
rsion: 2.3.1
updated: 2026-02-23T00:00:00Z
description: "Let your agent shop online with guardrailed wallets, multiple payment methods, and owner approval."
homepage: https://creditclaw.com
api_base: https://creditclaw.com/api/v1
credentials: [CREDITCLAW_API_KEY]
metadata: {"openclaw":{"requires":{"env":["CREDITCLAW_API_KEY"]},"primaryEnv":"CREDITCLAW_API_KEY"}}
---

# CreditClaw — Shopping for AI Agents

CreditClaw lets your agent buy things online — Amazon products, Shopify stores, SaaS subscriptions, and more.
Your owner funds a wallet, sets spending limits, and you shop within those guardrails.

## Skill Files

| File | URL | Purpose |
|------|-----|---------|
| **SKILL.md** (this file) | `https://creditclaw.com/creditcard/skill.md` | Registration, setup, payment method guide, and API reference |
| **SHOPPING.md** | `https://creditclaw.com/creditcard/shopping.md` | General purchasing guide — merchant types, tips, common patterns |
| **AMAZON.md** | `https://creditclaw.com/cre

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · amazon.md (reported line 33)May include surrounding context.

Purchase Request

bash
curl -X POST https://creditclaw.com/api/v1/card-wallet/bot/purchase \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · prepaid-wallet.md (reported line 43)May include surrounding context.

Purchase Request

bash
curl -X POST https://creditclaw.com/api/v1/card-wallet/bot/purchase \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill shows authenticated curl requests using CREDITCLAW_API_KEY and sends wallet status data to a remote service, but the document does not warn about credential sensitivity, remote transmission, or privacy implications. Under the markdown criteria, behaviors affecting user data or privacy should include warnings.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · heartbeat.md (reported line 19)May include surrounding context.

1. Check Full Status (Recommended)

bash
curl https://creditclaw.com/api/v1/bot/status \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example performs a state-changing financial action by submitting a top-up request, but it is presented as routine operational guidance without an explicit caution that this triggers an external workflow and may notify or prompt the owner. In an agent skill context, normalized examples for financial actions can cause unintended real-world actions if reused automatically or without clear confirmation boundaries.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · heartbeat.md (reported line 95)May include surrounding context.

Before an expensive self-hosted card purchase, test if it would pass:

bash
curl -X POST https://creditclaw.com/api/v1/bot/check/rail4/test \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "merchant_name": "Amazon", "amount_cents": 5000, "profile_index": 1 }'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide instructs sending full shipping address data to a remote purchase API but does not mention data minimization, retention, logging, or privacy handling. While transmitting an address is functionally necessary for fulfillment, the omission increases the risk of oversharing sensitive personal information and using the API without informed safeguards.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · prepaid-wallet.md (reported line 98)May include surrounding context.

Step 1: Search for Variants

bash
curl -X POST https://creditclaw.com/api/v1/card-wallet/bot/search \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "product_url": "https://shop.example.com/products/widget" }'

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
94% confidence
Finding

The text explicitly allows purchases to be auto-approved within an allowance, meaning an agent can cause real spending without a human in the loop for each transaction. In a shopping/payment skill, autonomous approval is particularly risky because compromised prompts, malicious merchant flows, or agent mistakes can directly convert into monetary loss.

Content

Scanner excerpt · self-hosted-card.md (reported line 11)May include surrounding context.

md
## How It Works

Self-hosted cards use a split-knowledge privacy model. Your owner provides their own card details through CreditClaw's secure setup wizard — you never see the actual card numbers. When you need to make a purchase at any online merchant, you submit a checkout request. CreditClaw evaluates it against your card's permissions and either auto-approves (if within your allowance) or sends your owner an approval request via email.

**Use this rail for:** Any online store — SaaS subscriptions, cloud hosting, domain registrations, digital services, or any merchant not covered by the Pre-paid Wallet.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document instructs an agent to make purchases at online merchants but does not prominently warn that these actions can create real financial charges. In an agent-skill context, missing explicit spend-risk disclosure increases the chance of unintended or overly broad autonomous purchasing by downstream users or orchestrators.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
95% confidence
Finding

This workflow states that transactions within the allowance process immediately, creating a direct path from agent decision to completed charge. The danger is amplified by the skill's broad intended use at 'any online merchant,' which increases exposure to unintended purchases and abuse from adversarial instructions.

Content

Scanner excerpt · self-hosted-card.md (reported line 23)May include surrounding context.

md
1. You submit a checkout request with merchant and amount details
2. CreditClaw evaluates the request against your card's permissions
3. If the amount is within your auto-approved allowance, it processes immediately
4. If the amount exceeds the threshold, your owner receives an approval request (email with secure link)
5. You poll for the result
6. Once approved, the transaction is recorded

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill demonstrates transmitting purchase details and an authorization bearer token to an external payment API, enabling real-world financial actions. While expected for the feature, external transmission of payment instructions is security-sensitive because misuse, prompt injection, or poor policy wrapping could trigger unauthorized charges.

Content

Scanner excerpt · self-hosted-card.md (reported line 31)May include surrounding context.

Checkout Request

bash
curl -X POST https://creditclaw.com/api/v1/bot/merchant/checkout \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
92% confidence
Finding

The documented 'approved' response for auto-approved transactions confirms that the system can finalize charges without additional human review. This is a real security concern in an agent skill because it normalizes silent completion of financial actions and may be integrated without sufficient surrounding controls.

Content

Scanner excerpt · self-hosted-card.md (reported line 57)May include surrounding context.

| category | No | Spending category | | task_id | No | Your internal task reference |

Response (Auto-Approved — Within Allowance)

json
{

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
94% confidence
Finding

The allowance-threshold section formalizes a policy where some purchases are automatically approved with no email confirmation needed. In context, this is dangerous because the skill is specifically designed for day-to-day online purchasing, so any weakness in agent control, task validation, or prompt isolation can be monetized directly.

Content

Scanner excerpt · self-hosted-card.md (reported line 111)May include surrounding context.

md
## Allowance Thresholds

Your owner sets a per-profile allowance threshold for each card. Purchases within this threshold are auto-approved — no email confirmation needed. Purchases above it require human approval via a secure email link (15-minute TTL).

Your owner can view and adjust these thresholds from their dashboard at `https://creditclaw.com/app/self-hosted`.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · shopping.md (reported line 51)May include surrounding context.

  1. Check wallet & spending permissions
  2. Confirm purchase details with the user
  3. Submit purchase/checkout request
  4. Handle approval (auto-approved or pending owner approval)
  5. Poll for result if pending
  6. Report outcome to user (tracking info, confirmation, or error)
text

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skill.md (reported line 339)May include surrounding context.

  1. Check wallet & spending permissions
  2. Confirm purchase details with the user
  3. Submit purchase/checkout request
  4. Handle approval (auto-approved or pending owner approval)
  5. Poll for result if pending
  6. Report outcome to user (tracking info, confirmation, or error)
text

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · skill.md (reported line 32)May include surrounding context.

Follow your human's instructions on how to manage and save skill files. If unsure, you can install locally:

bash
mkdir -p ~/.creditclaw/skills/creditcard
curl -s https://creditclaw.com/creditcard/skill.md > ~/.creditclaw/skills/creditcard/SKILL.md
curl -s https://creditclaw.com/creditcard/shopping.md > ~/.creditclaw/skills/creditcard/SHOPPING.md
curl -s https://creditclaw.com/creditcard/amazon.md > ~/.creditclaw/skills/creditcard/AMAZON.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · skill.md (reported line 33)May include surrounding context.

Follow your human's instructions on how to manage and save skill files. If unsure, you can install locally:

bash
mkdir -p ~/.creditclaw/skills/creditcard
curl -s https://creditclaw.com/creditcard/skill.md > ~/.creditclaw/skills/creditcard/SKILL.md
curl -s https://creditclaw.com/creditcard/shopping.md > ~/.creditclaw/skills/creditcard/SHOPPING.md
curl -s https://creditclaw.com/creditcard/amazon.md > ~/.creditclaw/skills/creditcard/AMAZON.md
curl -s https://creditclaw.com/creditcard/prepaid-wallet.md > ~/.creditclaw/skills/creditcard/PREPAID-WALLET.md

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 133)May include surrounding context.

Register to get your API key and a claim token for your human.

bash
curl -X POST https://creditclaw.com/api/v1/bots/register \
  -H "Content-Type: application/json" \
  -d '{
    "bot_name": "my-research-bot",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 223)May include surrounding context.

Recommended interval: every 30 minutes, or before any purchase.

bash
curl https://creditclaw.com/api/v1/bot/status \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY"

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skill.md (reported line 274)May include surrounding context.

"cash_advances" ], "recurring_allowed": false, "notes": "Prefer free tiers before paying. Always check for discount codes. No annual plans without asking me first.", "updated_at": "2026-02-06T18:00:00Z" }

text

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The skill explicitly permits autonomous spending under certain approval modes and thresholds. Even with server-side guardrails, this grants the agent authority to commit funds without per-transaction human review, which is a genuine risk if the agent is manipulated, makes poor decisions, or encounters prompt-injection during shopping tasks.

Content

Scanner excerpt · skill.md (reported line 281)May include surrounding context.

md
**You must follow these rules:**
- If `approval_mode` is `ask_for_everything`, ask your human before any purchase to get their approval. **New accounts default to this mode.** Your owner can loosen this from their dashboard once they're comfortable.
- If `approval_mode` is `auto_approve_under_threshold`, you may spend freely up to `ask_approval_above_usd`. Anything above that requires owner approval.
- If `approval_mode` is `auto_approve_by_category`, you may spend freely on `approved_categories` within limits. All others require approval.
- **Never** spend on `blocked_categories`. These are hard blocks enforced server-side and will be declined.
- Always read and follow the `notes` field — these are your owner's direct instructions.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Category-based auto-approval allows the agent to spend freely within approved classes, which can still be broad enough to enable harmful or unintended purchases. This increases risk because an attacker or erroneous workflow can frame a purchase as belonging to an approved category and trigger real financial loss before a human notices.

Content

Scanner excerpt · skill.md (reported line 282)May include surrounding context.

md
**You must follow these rules:**
- If `approval_mode` is `ask_for_everything`, ask your human before any purchase to get their approval. **New accounts default to this mode.** Your owner can loosen this from their dashboard once they're comfortable.
- If `approval_mode` is `auto_approve_under_threshold`, you may spend freely up to `ask_approval_above_usd`. Anything above that requires owner approval.
- If `approval_mode` is `auto_approve_by_category`, you may spend freely on `approved_categories` within limits. All others require approval.
- **Never** spend on `blocked_categories`. These are hard blocks enforced server-side and will be declined.
- Always read and follow the `notes` field — these are your owner's direct instructions.
- Cache this for up to 30 minutes. Do not fetch before every micro-purchase.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 351)May include surrounding context.

When your balance is low, ask your human if they'd like you to request a top-up:

bash
curl -X POST https://creditclaw.com/api/v1/bot/wallet/topup-request \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Static analysis

No suspicious patterns detected.