Checkout Friction Audit

PassAudited by ClawScan on May 1, 2026.

Overview

This instruction-only checkout audit skill is coherent and low risk, with the main caution being its optional use of a live or current browser session for observation.

This skill appears safe to install as an instruction-only checkout audit helper. If using browser observation, use staging or test data where possible, and confirm before allowing the agent to interact with a live checkout or current logged-in browser session.

Findings (1)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

If enabled, the agent may view checkout pages as they appear in the user's existing browser session.

Why it was flagged

Inspecting a current Chrome session can involve authenticated pages or session state. The instruction is disclosed and scoped to explicit user intent, so this is a notice rather than a concern.

Skill content
Use Browser Relay only when the user explicitly wants to inspect their current Chrome session.
Recommendation

Prefer staging or the managed browser when possible, and only use the current Chrome session for pages/accounts the user intentionally wants inspected.