Back to skill

Security audit

Game Tickets - Buy tickets with your credit card

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real shopping/payment skill, but it grants broad financial authority and relies on mutable remote instructions that should be reviewed before use.

Review this carefully before installing. Use it only if you trust CreditClaw with agent-initiated financial actions, keep per-purchase approval enabled unless you intentionally want auto-spending, set low limits and merchant/category restrictions, protect CREDITCLAW_API_KEY as a spending credential, and avoid loading remote skill documents unless their exact versions and hashes are verified.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
skill.md:248
Finding

Remote API Notes Are Treated as Authoritative Agent Instructions

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
skill.md:21
Finding

Mutable Remote Skill Documents Can Introduce Unaudited Agent Behavior

Content
View full analysis
~/.creditclaw/skills/creditcard/SKILL.md curl -s https://creditclaw.com/creditcard/shopping.md > ~/.creditclaw/skills/creditcard/SHOPPING.md curl -s https://creditclaw.com/creditcard/amazon.md > ~/.creditclaw/skills/creditcard/AMAZON.md curl -s https://creditclaw.com/creditcard/prepaid-wallet.md > ~/.creditclaw/skills/creditcard/PREPAID-WALLET.md curl -s https://creditclaw ...[truncated 3250 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (21)

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · skill.md (reported line 12)May include surrounding context.

md
---
name: creditclaw-creditcard
version: 2.3.5
updated: 2026-03-08T00:00:00Z
description: "Let your agent shop tickets online with owner approval."
homepage: https://creditclaw.com
api_base: https://creditclaw.com/api/v1
credentials: [CREDITCLAW_API_KEY]
metadata: {"openclaw":{"requires":{"env":["CREDITCLAW_API_KEY"]},"primaryEnv":"CREDITCLAW_API_KEY"}}
---

# CreditClaw — Shopping for AI Agents

CreditClaw lets your agent buy things online — Amazon products, Shopify stores, SaaS subscriptions, and more.
Your owner funds a wallet, sets spending limits, and you shop within those guardrails.

## Skill Files

| File | URL | Purpose |
|------|-----|---------|
| **SKILL.md** (this file) | `https://creditclaw.com/creditcard/skill.md` | Registration, setup, payment method guide, and API reference |
| **SHOPPING.md** | `https://creditclaw.com/creditcard/shopping.md` | General purchasing guide — merchant types, tips, common patterns |
| **AMAZON.md** | `https://creditclaw.com/cre

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill can generate third-party payment links and collect funds, which is unrelated to the stated ticket-shopping function. This materially expands the trust boundary from 'spend with approval' to 'act as a payment processor,' creating risk of unauthorized billing, fraud, or social engineering against third parties.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

Support for x402 agent-to-agent payments and on-chain signing is far beyond ticket shopping and introduces irreversible payment semantics. If misused, an agent could authorize transfers to external services or counterparties under a capability surface that the user may not realize exists.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · heartbeat.md (reported line 19)May include surrounding context.

1. Check Full Status (Recommended)

bash
curl https://creditclaw.com/api/v1/bot/status \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · heartbeat.md (reported line 95)May include surrounding context.

Before an expensive self-hosted card purchase, test if it would pass:

bash
curl -X POST https://creditclaw.com/api/v1/bot/check/rail4/test \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "merchant_name": "Amazon", "amount_cents": 5000, "profile_index": 1 }'

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
88% confidence
Finding

This text describes a workflow where purchases may be auto-approved within an allowance, allowing an agent to cause real financial transactions without a contemporaneous human review. In a payment skill, autonomous approval materially increases the risk of unintended or manipulated spending, especially at 'any online merchant.'

Content

Scanner excerpt · self-hosted-card.md (reported line 11)May include surrounding context.

md
## How It Works

Self-hosted cards use a split-knowledge privacy model. Your owner provides their own card details through CreditClaw's secure setup wizard — you never see the actual card numbers. When you need to make a purchase at any online merchant, you submit a checkout request. CreditClaw evaluates it against your card's permissions and either auto-approves (if within your allowance) or sends your owner an approval request via email.

**Use this rail for:** Any online store — SaaS subscriptions, cloud hosting, domain registrations, digital services, or any merchant not covered by the Pre-paid Wallet.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The documented checkout flow states that qualifying purchases 'process immediately,' which means the agent can complete a financial transaction before a human intervenes. In the context of a shopping/payment skill, that is a real security concern because misuse translates directly into unauthorized charges.

Content

Scanner excerpt · self-hosted-card.md (reported line 23)May include surrounding context.

md
1. You submit a checkout request with merchant and amount details
2. CreditClaw evaluates the request against your card's permissions
3. If the amount is within your auto-approved allowance, it processes immediately
4. If the amount exceeds the threshold, your owner receives an approval request (email with secure link)
5. You poll for the result
6. Once approved, the transaction is recorded

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The skill explicitly instructs an agent to send authenticated checkout requests to an external payment API to purchase goods or services. Even though the API is legitimate and card numbers are not exposed, this enables transfer of monetary value to external merchants and can be abused if the agent is prompt-injected, mis-scoped, or given ambiguous user intent.

Content

Scanner excerpt · self-hosted-card.md (reported line 31)May include surrounding context.

Checkout Request

bash
curl -X POST https://creditclaw.com/api/v1/bot/merchant/checkout \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The auto-approved response format confirms the system is designed to finalize transactions autonomously when below threshold. While this is expected product behavior, in an agent skill it still represents a vulnerability surface because an attacker only needs to trigger a compliant low-value purchase to cause harm.

Content

Scanner excerpt · self-hosted-card.md (reported line 57)May include surrounding context.

| category | No | Spending category | | task_id | No | Your internal task reference |

Response (Auto-Approved — Within Allowance)

json
{

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
89% confidence
Finding

Allowance thresholds permitting no-email, no-human-confirmation purchases create a standing authorization for agent-initiated spending. In this specific skill context, that makes prompt injection, task confusion, or malicious merchant selection more dangerous because approval is delegated to a preset limit rather than real-time intent verification.

Content

Scanner excerpt · self-hosted-card.md (reported line 111)May include surrounding context.

md
## Allowance Thresholds

Your owner sets a per-profile allowance threshold for each card. Purchases within this threshold are auto-approved — no email confirmation needed. Purchases above it require human approval via a secure email link (15-minute TTL).

Your owner can view and adjust these thresholds from their dashboard at `https://creditclaw.com/app/self-hosted`.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest advertises a narrow ticket-shopping purpose, but the skill actually enables broad purchasing, wallet funding, payment collection, and multi-rail financial operations. This scope mismatch can mislead users, policy engines, or reviewers into granting a capability set far broader than expected, increasing the chance of unintended financial actions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
81% confidence
Finding

The instructions tell the agent to persist skill files under a user home directory, creating durable local state outside the immediate session. Persistent installation increases the chance that outdated, tampered, or over-privileged skill content remains active across sessions and may be reused without fresh review.

Content

Scanner excerpt · skill.md (reported line 32)May include surrounding context.

Follow your human's instructions on how to manage and save skill files. If unsure, you can install locally:

bash
mkdir -p ~/.creditclaw/skills/creditcard
curl -s https://creditclaw.com/creditcard/skill.md > ~/.creditclaw/skills/creditcard/SKILL.md
curl -s https://creditclaw.com/creditcard/shopping.md > ~/.creditclaw/skills/creditcard/SHOPPING.md
curl -s https://creditclaw.com/creditcard/amazon.md > ~/.creditclaw/skills/creditcard/AMAZON.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · skill.md (reported line 33)May include surrounding context.

Follow your human's instructions on how to manage and save skill files. If unsure, you can install locally:

bash
mkdir -p ~/.creditclaw/skills/creditcard
curl -s https://creditclaw.com/creditcard/skill.md > ~/.creditclaw/skills/creditcard/SKILL.md
curl -s https://creditclaw.com/creditcard/shopping.md > ~/.creditclaw/skills/creditcard/SHOPPING.md
curl -s https://creditclaw.com/creditcard/amazon.md > ~/.creditclaw/skills/creditcard/AMAZON.md
curl -s https://creditclaw.com/creditcard/prepaid-wallet.md > ~/.creditclaw/skills/creditcard/PREPAID-WALLET.md

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 133)May include surrounding context.

Register to get your API key and a claim token for your human.

bash
curl -X POST https://creditclaw.com/api/v1/bots/register \
  -H "Content-Type: application/json" \
  -d '{
    "bot_name": "my-research-bot",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 223)May include surrounding context.

Recommended interval: every 30 minutes, or before any purchase.

bash
curl https://creditclaw.com/api/v1/bot/status \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY"

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skill.md (reported line 274)May include surrounding context.

"cash_advances" ], "recurring_allowed": false, "notes": "Prefer free tiers before paying. Always check for discount codes. No annual plans without asking me first.", "updated_at": "2026-02-06T18:00:00Z" }

text

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
94% confidence
Finding

The skill explicitly authorizes autonomous spending under certain approval modes and thresholds. Even if intended, this is a real security-relevant capability because it allows the agent to execute financial transactions without per-transaction human confirmation, making mistakes, prompt-manipulated purchases, or misuse more consequential.

Content

Scanner excerpt · skill.md (reported line 281)May include surrounding context.

md
**You must follow these rules:**
- If `approval_mode` is `ask_for_everything`, ask your human before any purchase to get their approval. **New accounts default to this mode.** Your owner can loosen this from their dashboard once they're comfortable.
- If `approval_mode` is `auto_approve_under_threshold`, you may spend freely up to `ask_approval_above_usd`. Anything above that requires owner approval.
- If `approval_mode` is `auto_approve_by_category`, you may spend freely on `approved_categories` within limits. All others require approval.
- **Never** spend on `blocked_categories`. These are hard blocks enforced server-side and will be declined.
- Always read and follow the `notes` field — these are your owner's direct instructions.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
94% confidence
Finding

Auto-approval by category gives the agent discretion to spend within broad classes, which can be exploited by misclassification, prompt manipulation, or poor merchant/category mapping. In a financial skill, this materially enlarges the blast radius of any bad decision because approval is delegated in advance rather than checked per purchase.

Content

Scanner excerpt · skill.md (reported line 282)May include surrounding context.

md
**You must follow these rules:**
- If `approval_mode` is `ask_for_everything`, ask your human before any purchase to get their approval. **New accounts default to this mode.** Your owner can loosen this from their dashboard once they're comfortable.
- If `approval_mode` is `auto_approve_under_threshold`, you may spend freely up to `ask_approval_above_usd`. Anything above that requires owner approval.
- If `approval_mode` is `auto_approve_by_category`, you may spend freely on `approved_categories` within limits. All others require approval.
- **Never** spend on `blocked_categories`. These are hard blocks enforced server-side and will be declined.
- Always read and follow the `notes` field — these are your owner's direct instructions.
- Cache this for up to 30 minutes. Do not fetch before every micro-purchase.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skill.md (reported line 339)May include surrounding context.

md
| `exceeds_per_transaction_limit` | 403 | Amount exceeds per-transaction cap. |
| `exceeds_daily_limit` | 403 | Would exceed daily spending limit. |
| `exceeds_monthly_limit` | 403 | Would exceed monthly spending limit. |
| `requires_owner_approval` | 403 | Amount above auto-approve threshold. |

When a purchase is declined, the response includes the relevant limits and your current
spending so you can understand why. Your owner is also notified of all declined attempts.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 351)May include surrounding context.

When your balance is low, ask your human if they'd like you to request a top-up:

bash
curl -X POST https://creditclaw.com/api/v1/bot/wallet/topup-request \
  -H "Authorization: Bearer $CREDITCLAW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The exposed rail-check endpoints include unrelated capabilities such as sub-agent card details and multiple payment rails not necessary for ticket shopping. Unnecessary capability exposure increases attack surface and may disclose sensitive financial configuration or enable lateral misuse of other enabled rails.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.