Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Agent Commerce Foundations: 6-Guide Bundle for Building Autonomous Transaction Systems

v1.3.1

The complete foundation for agent-to-agent commerce. Covers B2B transactions, API migration, security hardening, payment rails, pricing strategy, and multi-a...

0· 112·0 current·0 all-time
Security Scan
Capability signals
CryptoCan make purchasesRequires sensitive credentials
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
high confidence
!
Purpose & Capability
The SKILL.md is a set of guides (documentation) about agent commerce; a pure guide bundle does not need runtime access to GREENHELIX_API_KEY, AGENT_SIGNING_KEY, or STRIPE_API_KEY. Requesting those secrets is disproportionate to the stated purpose and suggests either misconfiguration or potential misuse.
!
Instruction Scope
The runtime instructions are purely metadata and descriptive; they contain no commands or steps that would require reading or using environment credentials. This mismatch (no runtime usage while creds are declared required) is a red flag.
Install Mechanism
No install spec and no code files are present, which minimizes on-disk execution risk; the skill is instruction-only.
!
Credentials
Three sensitive variables are required: a platform API key (GREENHELIX_API_KEY), a signing key (AGENT_SIGNING_KEY), and a payment provider key (STRIPE_API_KEY). None are justified by the content. In particular, AGENT_SIGNING_KEY and STRIPE_API_KEY are high-sensitivity secrets that should not be requested by a documentation-only bundle.
Persistence & Privilege
The skill is not always-enabled and uses default autonomous invocation; it does not request system-wide configuration or modify other skills. No elevated persistence or cross-skill access is declared.
What to consider before installing
Do not supply real secrets to this skill. Ask the publisher why a documentation bundle requires GREENHELIX_API_KEY, AGENT_SIGNING_KEY, and STRIPE_API_KEY; legitimate answers would include explicit runtime features that need those keys (which are not present in SKILL.md). If you must test, use isolated/sandboxed environment and minimal-privilege or test API keys (never your Stripe production keys or private signing keys). Prefer a version of the bundle that does not declare required credentials or that documents exactly when and why each secret is needed.

Like a lobster shell, security has layers — review code before you run it.

Runtime requirements

EnvGREENHELIX_API_KEY, AGENT_SIGNING_KEY, STRIPE_API_KEY
Primary envGREENHELIX_API_KEY
agent-commercevk97epgs8s8jp0kkb9e0eb9378n84xs3zai-agentvk97epgs8s8jp0kkb9e0eb9378n84xs3zbundlevk97epgs8s8jp0kkb9e0eb9378n84xs3zgreenhelixvk97epgs8s8jp0kkb9e0eb9378n84xs3zguidevk97epgs8s8jp0kkb9e0eb9378n84xs3zlatestvk97epgs8s8jp0kkb9e0eb9378n84xs3zmulti-agentvk97epgs8s8jp0kkb9e0eb9378n84xs3zopenclawvk97epgs8s8jp0kkb9e0eb9378n84xs3zpaymentsvk97epgs8s8jp0kkb9e0eb9378n84xs3zpricingvk97epgs8s8jp0kkb9e0eb9378n84xs3zsecurityvk97epgs8s8jp0kkb9e0eb9378n84xs3z
112downloads
0stars
5versions
Updated 4d ago
v1.3.1
MIT-0

Agent Commerce Foundations: 6-Guide Bundle for Building Autonomous Transaction Systems

Included Guides

GuideIndividual Price
Agent-to-Agent Commerce: Build Autonomous B2B Transactions$29.00
Agent Commerce Migration Guide: Retrofit Your REST APIs for Autonomous Agent Buyers$39.00
Locking Down Agent Commerce: The OWASP-Aligned Security Guide for Autonomous AI Agents on GreenHelix$29.00
The Agent Payment Rails Playbook$29.00
The Agent Pricing & Monetization Playbook$29.00
The Multi-Agent Commerce Cookbook: Orchestrating Agent Teams That Discover, Negotiate, Pay, and Verify Each Other$29.00

Total Value: $184.00 | Bundle Price: $149.00

Comments

Loading comments...