Conto
PassAudited by ClawScan on Apr 6, 2026.
Overview
The skill's code, instructions, and requested environment access are coherent with a payment policy-enforcement tool; nothing requests unrelated credentials or installs arbitrary code.
This skill appears to do what it says: query Conto before payments. Before installing, confirm you understand which SDK key you will provide: use a Standard (least-privilege) key for runtime approvals and only use an Admin key if you intentionally want the agent to create/manage policies and agents. Store the SDK key in a secure place (openclaw config or secret manager) and prefer HTTPS (the docs require https in production). Be aware the agent will need access to the wallet address it controls; ensure the registered address in Conto matches the wallet the agent actually uses. If you have concerns about giving the agent administrative capabilities, rotate keys and use fine-grained keys (Standard) or scoped credentials.
