Back to skill

Security audit

TicketClaw - Buy tickets to any event

Security checks for vulnerabilities and agentic risk

Overview

This financial-shopping skill is mostly transparent, but it warrants review because it delegates real spending and payment powers and installs mutable remote skill files without integrity checks.

Install only if you are comfortable giving an agent delegated spending authority. Keep default per-purchase approval unless you have tight merchant/category limits, protect CREDITCLAW_API_KEY as a spending credential, avoid sending unnecessary personal shipping data, and prefer a reviewed package or signed/pinned files over live remote Markdown installation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
skill.md:32
Finding

Unpinned Installation of Mutable Remote Skill Content

Content
View full analysis
~/.creditclaw/skills/creditcard/SKILL.md curl -s https://creditclaw.com/creditcard/shopping.md > ~/.creditclaw/skills/creditcard/SHOPPING.md curl -s https://creditclaw.com/creditcard/amazon.md > ~/.creditclaw/skills/creditcard/AMAZON.md curl -s https://creditclaw.com/creditcard/prepaid-wallet.md > ~/.creditclaw/skills/creditcard/PREPAID-WALLET.md curl -s https://creditclaw.com/creditcard/self-hosted-card.md > ~/.creditclaw/skills/creditcard/SELF-HOSTED-CARD.md curl -s https://creditclaw.com/creditcard/stripe-x402-wallet.md > ~/.creditclaw/skills/creditcard/STRIPE-X402-WALLET.md curl -s https://creditclaw.com/creditcard/heartbeat.md > ~/.creditclaw/skills/creditcard/HEARTBEAT.md curl -s https://creditclaw.com/creditcard/skill.json > ~/.creditclaw/skills/creditcard/package.json ``` The surrounding instructions also permit the Agent to read these documents directly from their live URLs. ### Technical Analysis The installation procedure downloads mutable Skill documents from live URLs and writes them into a persistent local Skill directory. It does not pin an immutable release, verify a cryptographic digest, validate a signed manifest, or otherwise confirm that the downloaded files are identical to the content reviewed during this audit. Skill Markdown files act as trusted Agent instructions. Consequently, changing the hosted content can change the effective behavior of the installed Skill without changing the audited package. An attacker who compromises the publishing server, deployment account, content pipeline, or relevant TLS trust path could replace the documents with instructions that manipulate payment operations, solicit secrets, or direct the Agent to run unsafe commands. The cu ...[truncated 2237 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (27)

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · skill.md (reported line 12)May include surrounding context.

md
rsion: 2.3.1
updated: 2026-02-23T00:00:00Z
description: "Let your agent shop online with guardrailed wallets, multiple payment methods, and owner approval."
homepage: https://creditclaw.com
api_base: https://creditclaw.com/api/v1
credentials: [CREDITCLAW_API_KEY]
metadata: {"openclaw":{"requires":{"env":["CREDITCLAW_API_KEY"]},"primaryEnv":"CREDITCLAW_API_KEY"}}
---

# CreditClaw — Shopping for AI Agents

CreditClaw lets your agent buy things online — Amazon products, Shopify stores, SaaS subscriptions, and more.
Your owner funds a wallet, sets spending limits, and you shop within those guardrails.

## Skill Files

| File | URL | Purpose |
|------|-----|---------|
| **SKILL.md** (this file) | `https://creditclaw.com/creditcard/skill.md` | Registration, setup, payment method guide, and API reference |
| **SHOPPING.md** | `https://creditclaw.com/creditcard/shopping.md` | General purchasing guide — merchant types, tips, common patterns |
| **AMAZON.md** | `https://creditclaw.com/cre

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown instructs periodic checks of wallet status, balances, spending permissions, and all active payment rails, which can reveal sensitive financial and account data. The description provides operational steps but no warning that these calls access and transmit sensitive account information to an external service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · heartbeat.md (reported line 19)May include surrounding context.

1. Check Full Status (Recommended)

bash
curl https://creditclaw.com/api/v1/bot/status \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documented workflow performs a state-changing top-up request automatically when balance drops below a threshold, causing the agent to send an external funding request without a clear confirmation step at the time of action. In a financial skill, this can trigger unwanted owner notifications or operational side effects from routine polling, especially if the heartbeat runs repeatedly.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · heartbeat.md (reported line 95)May include surrounding context.

Before an expensive self-hosted card purchase, test if it would pass:

bash
curl -X POST https://creditclaw.com/api/v1/bot/check/rail4/test \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "merchant_name": "Amazon", "amount_cents": 5000, "profile_index": 1 }'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The purchase instructions require sending a full shipping address, product details, and payment-related purchase metadata to CreditClaw and ultimately to the merchant, but they do not clearly warn that this constitutes disclosure of personal data to third parties. In a purchasing skill, that omission is security-relevant because agents or operators may submit sensitive recipient information without informed consent or data-minimization safeguards.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

This example sends sensitive data externally to a third-party API, including an authorization bearer token and full shipping-address information. External transmission is expected for an e-commerce payment skill, but it is still a real exposure point because misuse, logging, or accidental execution could disclose credentials and personal data.

Content

Scanner excerpt · prepaid-wallet.md (reported line 43)May include surrounding context.

Purchase Request

bash
curl -X POST https://creditclaw.com/api/v1/card-wallet/bot/purchase \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · prepaid-wallet.md (reported line 98)May include surrounding context.

Step 1: Search for Variants

bash
curl -X POST https://creditclaw.com/api/v1/card-wallet/bot/search \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "product_url": "https://shop.example.com/products/widget" }'

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
92% confidence
Finding

The documentation describes a system where the agent can trigger purchases that are automatically approved when they fall within an allowance threshold. Autonomous spending authority is inherently risky because an agent can be manipulated into making unintended purchases without a real-time human decision, especially when the rail is described as usable at 'any online merchant'.

Content

Scanner excerpt · self-hosted-card.md (reported line 11)May include surrounding context.

md
## How It Works

Self-hosted cards use a split-knowledge privacy model. Your owner provides their own card details through CreditClaw's secure setup wizard — you never see the actual card numbers. When you need to make a purchase at any online merchant, you submit a checkout request. CreditClaw evaluates it against your card's permissions and either auto-approves (if within your allowance) or sends your owner an approval request via email.

**Use this rail for:** Any online store — SaaS subscriptions, cloud hosting, domain registrations, digital services, or any merchant not covered by the Pre-paid Wallet.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
94% confidence
Finding

This flow explicitly states that requests within an auto-approved allowance are processed immediately, giving the agent direct transactional power. In the context of a shopping/payment skill, that makes the autonomous action materially dangerous because successful exploitation results in completed purchases, not just data access or low-impact API calls.

Content

Scanner excerpt · self-hosted-card.md (reported line 23)May include surrounding context.

md
1. You submit a checkout request with merchant and amount details
2. CreditClaw evaluates the request against your card's permissions
3. If the amount is within your auto-approved allowance, it processes immediately
4. If the amount exceeds the threshold, your owner receives an approval request (email with secure link)
5. You poll for the result
6. Once approved, the transaction is recorded

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This skill explicitly instructs an agent to transmit payment authorization data to an external checkout API to initiate purchases. Even though raw card numbers are hidden and CreditClaw adds guardrails, the capability enables real-world spending at arbitrary online merchants, so misuse, prompt injection, or compromised agent behavior could cause unauthorized financial transactions.

Content

Scanner excerpt · self-hosted-card.md (reported line 31)May include surrounding context.

Checkout Request

bash
curl -X POST https://creditclaw.com/api/v1/bot/merchant/checkout \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
89% confidence
Finding

The documented 'approved' response for auto-approved purchases confirms that the platform will complete transactions without human intervention under some conditions. While this line is only an example response, in context it evidences the underlying risky capability of autonomous payment execution.

Content

Scanner excerpt · self-hosted-card.md (reported line 57)May include surrounding context.

| category | No | Spending category | | task_id | No | Your internal task reference |

Response (Auto-Approved — Within Allowance)

json
{

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
93% confidence
Finding

The allowance-threshold model formalizes unattended spending up to a configured limit, which expands the blast radius of agent mistakes or prompt-injection attacks. In a credit card purchasing skill, this context makes autonomous decision-making substantially more dangerous than in non-financial domains because it directly authorizes movement of funds.

Content

Scanner excerpt · self-hosted-card.md (reported line 111)May include surrounding context.

md
## Allowance Thresholds

Your owner sets a per-profile allowance threshold for each card. Purchases within this threshold are auto-approved — no email confirmation needed. Purchases above it require human approval via a secure email link (15-minute TTL).

Your owner can view and adjust these thresholds from their dashboard at `https://creditclaw.com/app/self-hosted`.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · skill.md (reported line 32)May include surrounding context.

Follow your human's instructions on how to manage and save skill files. If unsure, you can install locally:

bash
mkdir -p ~/.creditclaw/skills/creditcard
curl -s https://creditclaw.com/creditcard/skill.md > ~/.creditclaw/skills/creditcard/SKILL.md
curl -s https://creditclaw.com/creditcard/shopping.md > ~/.creditclaw/skills/creditcard/SHOPPING.md
curl -s https://creditclaw.com/creditcard/amazon.md > ~/.creditclaw/skills/creditcard/AMAZON.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · skill.md (reported line 33)May include surrounding context.

Follow your human's instructions on how to manage and save skill files. If unsure, you can install locally:

bash
mkdir -p ~/.creditclaw/skills/creditcard
curl -s https://creditclaw.com/creditcard/skill.md > ~/.creditclaw/skills/creditcard/SKILL.md
curl -s https://creditclaw.com/creditcard/shopping.md > ~/.creditclaw/skills/creditcard/SHOPPING.md
curl -s https://creditclaw.com/creditcard/amazon.md > ~/.creditclaw/skills/creditcard/AMAZON.md
curl -s https://creditclaw.com/creditcard/prepaid-wallet.md > ~/.creditclaw/skills/creditcard/PREPAID-WALLET.md

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 133)May include surrounding context.

Register to get your API key and a claim token for your human.

bash
curl -X POST https://creditclaw.com/api/v1/bots/register \
  -H "Content-Type: application/json" \
  -d '{
    "bot_name": "my-research-bot",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 223)May include surrounding context.

Recommended interval: every 30 minutes, or before any purchase.

bash
curl https://creditclaw.com/api/v1/bot/status \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY"

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skill.md (reported line 274)May include surrounding context.

"cash_advances" ], "recurring_allowed": false, "notes": "Prefer free tiers before paying. Always check for discount codes. No annual plans without asking me first.", "updated_at": "2026-02-06T18:00:00Z" }

text

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
89% confidence
Finding

The skill explicitly permits autonomous purchases under certain approval modes and thresholds. Even with server-side guardrails, granting an agent the ability to spend without per-transaction human confirmation creates real financial-risk surface if the agent is manipulated, misclassifies a purchase, or acts on adversarial prompts.

Content

Scanner excerpt · skill.md (reported line 281)May include surrounding context.

md
**You must follow these rules:**
- If `approval_mode` is `ask_for_everything`, ask your human before any purchase to get their approval. **New accounts default to this mode.** Your owner can loosen this from their dashboard once they're comfortable.
- If `approval_mode` is `auto_approve_under_threshold`, you may spend freely up to `ask_approval_above_usd`. Anything above that requires owner approval.
- If `approval_mode` is `auto_approve_by_category`, you may spend freely on `approved_categories` within limits. All others require approval.
- **Never** spend on `blocked_categories`. These are hard blocks enforced server-side and will be declined.
- Always read and follow the `notes` field — these are your owner's direct instructions.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
89% confidence
Finding

Category-based auto-approval delegates spending decisions to the agent within approved categories, which can still be abused through miscategorized merchants, prompt injection, or task confusion. The context makes this capability somewhat safer because server-side policy exists, but it remains a meaningful financial authorization risk.

Content

Scanner excerpt · skill.md (reported line 282)May include surrounding context.

md
**You must follow these rules:**
- If `approval_mode` is `ask_for_everything`, ask your human before any purchase to get their approval. **New accounts default to this mode.** Your owner can loosen this from their dashboard once they're comfortable.
- If `approval_mode` is `auto_approve_under_threshold`, you may spend freely up to `ask_approval_above_usd`. Anything above that requires owner approval.
- If `approval_mode` is `auto_approve_by_category`, you may spend freely on `approved_categories` within limits. All others require approval.
- **Never** spend on `blocked_categories`. These are hard blocks enforced server-side and will be declined.
- Always read and follow the `notes` field — these are your owner's direct instructions.
- Cache this for up to 30 minutes. Do not fetch before every micro-purchase.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skill.md (reported line 339)May include surrounding context.

md
| `exceeds_per_transaction_limit` | 403 | Amount exceeds per-transaction cap. |
| `exceeds_daily_limit` | 403 | Would exceed daily spending limit. |
| `exceeds_monthly_limit` | 403 | Would exceed monthly spending limit. |
| `requires_owner_approval` | 403 | Amount above auto-approve threshold. |

When a purchase is declined, the response includes the relevant limits and your current
spending so you can understand why. Your owner is also notified of all declined attempts.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 351)May include surrounding context.

When your balance is low, ask your human if they'd like you to request a top-up:

bash
curl -X POST https://creditclaw.com/api/v1/bot/wallet/topup-request \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill exposes a payment-link capability that allows charging arbitrary third parties, which materially expands scope beyond 'shop online on the owner's behalf.' That increases abuse potential because a compromised or misaligned agent could solicit payments, create fraudulent invoices, or operate as a payment collector without the narrower shopping context implied by the manifest.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The x402 signing and agent-to-agent payment features broaden the skill from consumer shopping into programmable value transfer. Signature/payment primitives are highly sensitive because they can enable autonomous transfers or settlement flows that users may not expect from a shopping skill, especially if downstream docs further operationalize them.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · stripe-x402-wallet.md (reported line 36)May include surrounding context.

Request x402 Payment Signature

bash
curl -X POST https://creditclaw.com/api/v1/stripe-wallet/bot/sign \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Static analysis

No suspicious patterns detected.