T01 · Skill Instruction Hijacking
- Location
skill.md:248- Finding
Remote API Notes Are Treated as Authoritative Agent Instructions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a real shopping/payment skill, but it grants broad financial authority and relies on mutable remote instructions that should be reviewed before use.
Review this carefully before installing. Use it only if you trust CreditClaw with agent-initiated financial actions, keep per-purchase approval enabled unless you intentionally want auto-spending, set low limits and merchant/category restrictions, protect CREDITCLAW_API_KEY as a spending credential, and avoid loading remote skill documents unless their exact versions and hashes are verified.
skill.md:248Remote API Notes Are Treated as Authoritative Agent Instructions
skill.md:21Mutable Remote Skill Documents Can Introduce Unaudited Agent Behavior
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
---
name: creditclaw-creditcard
version: 2.3.5
updated: 2026-03-08T00:00:00Z
description: "Let your agent shop tickets online with owner approval."
homepage: https://creditclaw.com
api_base: https://creditclaw.com/api/v1
credentials: [CREDITCLAW_API_KEY]
metadata: {"openclaw":{"requires":{"env":["CREDITCLAW_API_KEY"]},"primaryEnv":"CREDITCLAW_API_KEY"}}
---
# CreditClaw — Shopping for AI Agents
CreditClaw lets your agent buy things online — Amazon products, Shopify stores, SaaS subscriptions, and more.
Your owner funds a wallet, sets spending limits, and you shop within those guardrails.
## Skill Files
| File | URL | Purpose |
|------|-----|---------|
| **SKILL.md** (this file) | `https://creditclaw.com/creditcard/skill.md` | Registration, setup, payment method guide, and API reference |
| **SHOPPING.md** | `https://creditclaw.com/creditcard/shopping.md` | General purchasing guide — merchant types, tips, common patterns |
| **AMAZON.md** | `https://creditclaw.com/cre
The skill can generate third-party payment links and collect funds, which is unrelated to the stated ticket-shopping function. This materially expands the trust boundary from 'spend with approval' to 'act as a payment processor,' creating risk of unauthorized billing, fraud, or social engineering against third parties.
Support for x402 agent-to-agent payments and on-chain signing is far beyond ticket shopping and introduces irreversible payment semantics. If misused, an agent could authorize transfers to external services or counterparties under a capability surface that the user may not realize exists.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl https://creditclaw.com/api/v1/bot/status \
-H "Authorization: Bearer $CREDITCLAW_API_KEY"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Before an expensive self-hosted card purchase, test if it would pass:
curl -X POST https://creditclaw.com/api/v1/bot/check/rail4/test \
-H "Authorization: Bearer $CREDITCLAW_API_KEY" \
-H "Content-Type: application/json" \
-d '{ "merchant_name": "Amazon", "amount_cents": 5000, "profile_index": 1 }'
This text describes a workflow where purchases may be auto-approved within an allowance, allowing an agent to cause real financial transactions without a contemporaneous human review. In a payment skill, autonomous approval materially increases the risk of unintended or manipulated spending, especially at 'any online merchant.'
## How It Works
Self-hosted cards use a split-knowledge privacy model. Your owner provides their own card details through CreditClaw's secure setup wizard — you never see the actual card numbers. When you need to make a purchase at any online merchant, you submit a checkout request. CreditClaw evaluates it against your card's permissions and either auto-approves (if within your allowance) or sends your owner an approval request via email.
**Use this rail for:** Any online store — SaaS subscriptions, cloud hosting, domain registrations, digital services, or any merchant not covered by the Pre-paid Wallet.
The documented checkout flow states that qualifying purchases 'process immediately,' which means the agent can complete a financial transaction before a human intervenes. In the context of a shopping/payment skill, that is a real security concern because misuse translates directly into unauthorized charges.
1. You submit a checkout request with merchant and amount details
2. CreditClaw evaluates the request against your card's permissions
3. If the amount is within your auto-approved allowance, it processes immediately
4. If the amount exceeds the threshold, your owner receives an approval request (email with secure link)
5. You poll for the result
6. Once approved, the transaction is recorded
The skill explicitly instructs an agent to send authenticated checkout requests to an external payment API to purchase goods or services. Even though the API is legitimate and card numbers are not exposed, this enables transfer of monetary value to external merchants and can be abused if the agent is prompt-injected, mis-scoped, or given ambiguous user intent.
curl -X POST https://creditclaw.com/api/v1/bot/merchant/checkout \
-H "Authorization: Bearer $CREDITCLAW_API_KEY" \
-H "Content-Type: application/json" \
-d '{
The auto-approved response format confirms the system is designed to finalize transactions autonomously when below threshold. While this is expected product behavior, in an agent skill it still represents a vulnerability surface because an attacker only needs to trigger a compliant low-value purchase to cause harm.
| category | No | Spending category |
| task_id | No | Your internal task reference |
{
Allowance thresholds permitting no-email, no-human-confirmation purchases create a standing authorization for agent-initiated spending. In this specific skill context, that makes prompt injection, task confusion, or malicious merchant selection more dangerous because approval is delegated to a preset limit rather than real-time intent verification.
## Allowance Thresholds
Your owner sets a per-profile allowance threshold for each card. Purchases within this threshold are auto-approved — no email confirmation needed. Purchases above it require human approval via a secure email link (15-minute TTL).
Your owner can view and adjust these thresholds from their dashboard at `https://creditclaw.com/app/self-hosted`.
The manifest advertises a narrow ticket-shopping purpose, but the skill actually enables broad purchasing, wallet funding, payment collection, and multi-rail financial operations. This scope mismatch can mislead users, policy engines, or reviewers into granting a capability set far broader than expected, increasing the chance of unintended financial actions.
The instructions tell the agent to persist skill files under a user home directory, creating durable local state outside the immediate session. Persistent installation increases the chance that outdated, tampered, or over-privileged skill content remains active across sessions and may be reused without fresh review.
Follow your human's instructions on how to manage and save skill files. If unsure, you can install locally:
mkdir -p ~/.creditclaw/skills/creditcard
curl -s https://creditclaw.com/creditcard/skill.md > ~/.creditclaw/skills/creditcard/SKILL.md
curl -s https://creditclaw.com/creditcard/shopping.md > ~/.creditclaw/skills/creditcard/SHOPPING.md
curl -s https://creditclaw.com/creditcard/amazon.md > ~/.creditclaw/skills/creditcard/AMAZON.md
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
Follow your human's instructions on how to manage and save skill files. If unsure, you can install locally:
mkdir -p ~/.creditclaw/skills/creditcard
curl -s https://creditclaw.com/creditcard/skill.md > ~/.creditclaw/skills/creditcard/SKILL.md
curl -s https://creditclaw.com/creditcard/shopping.md > ~/.creditclaw/skills/creditcard/SHOPPING.md
curl -s https://creditclaw.com/creditcard/amazon.md > ~/.creditclaw/skills/creditcard/AMAZON.md
curl -s https://creditclaw.com/creditcard/prepaid-wallet.md > ~/.creditclaw/skills/creditcard/PREPAID-WALLET.md
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Register to get your API key and a claim token for your human.
curl -X POST https://creditclaw.com/api/v1/bots/register \
-H "Content-Type: application/json" \
-d '{
"bot_name": "my-research-bot",
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Recommended interval: every 30 minutes, or before any purchase.
curl https://creditclaw.com/api/v1/bot/status \
-H "Authorization: Bearer $CREDITCLAW_API_KEY"
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
"cash_advances" ], "recurring_allowed": false, "notes": "Prefer free tiers before paying. Always check for discount codes. No annual plans without asking me first.", "updated_at": "2026-02-06T18:00:00Z" }
The skill explicitly authorizes autonomous spending under certain approval modes and thresholds. Even if intended, this is a real security-relevant capability because it allows the agent to execute financial transactions without per-transaction human confirmation, making mistakes, prompt-manipulated purchases, or misuse more consequential.
**You must follow these rules:**
- If `approval_mode` is `ask_for_everything`, ask your human before any purchase to get their approval. **New accounts default to this mode.** Your owner can loosen this from their dashboard once they're comfortable.
- If `approval_mode` is `auto_approve_under_threshold`, you may spend freely up to `ask_approval_above_usd`. Anything above that requires owner approval.
- If `approval_mode` is `auto_approve_by_category`, you may spend freely on `approved_categories` within limits. All others require approval.
- **Never** spend on `blocked_categories`. These are hard blocks enforced server-side and will be declined.
- Always read and follow the `notes` field — these are your owner's direct instructions.
Auto-approval by category gives the agent discretion to spend within broad classes, which can be exploited by misclassification, prompt manipulation, or poor merchant/category mapping. In a financial skill, this materially enlarges the blast radius of any bad decision because approval is delegated in advance rather than checked per purchase.
**You must follow these rules:**
- If `approval_mode` is `ask_for_everything`, ask your human before any purchase to get their approval. **New accounts default to this mode.** Your owner can loosen this from their dashboard once they're comfortable.
- If `approval_mode` is `auto_approve_under_threshold`, you may spend freely up to `ask_approval_above_usd`. Anything above that requires owner approval.
- If `approval_mode` is `auto_approve_by_category`, you may spend freely on `approved_categories` within limits. All others require approval.
- **Never** spend on `blocked_categories`. These are hard blocks enforced server-side and will be declined.
- Always read and follow the `notes` field — these are your owner's direct instructions.
- Cache this for up to 30 minutes. Do not fetch before every micro-purchase.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
| `exceeds_per_transaction_limit` | 403 | Amount exceeds per-transaction cap. |
| `exceeds_daily_limit` | 403 | Would exceed daily spending limit. |
| `exceeds_monthly_limit` | 403 | Would exceed monthly spending limit. |
| `requires_owner_approval` | 403 | Amount above auto-approve threshold. |
When a purchase is declined, the response includes the relevant limits and your current
spending so you can understand why. Your owner is also notified of all declined attempts.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
When your balance is low, ask your human if they'd like you to request a top-up:
curl -X POST https://creditclaw.com/api/v1/bot/wallet/topup-request \
-H "Authorization: Bearer $CREDITCLAW_API_KEY" \
-H "Content-Type: application/json" \
-d '{
The exposed rail-check endpoints include unrelated capabilities such as sub-agent card details and multiple payment rails not necessary for ticket shopping. Unnecessary capability exposure increases attack surface and may disclose sensitive financial configuration or enable lateral misuse of other enabled rails.
No suspicious patterns detected.