ClawAudit verdict
pop-pay
pop-pay-python
The skill accesses real credit card credentials from the system keychain and injects them into browser payment forms via CDP, which is a high-value target; while the privacy claims are reasonable and no exfiltration is evident, the capability to handle real payment credentials and execute real financial transactions is inherently elevated-risk.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
package_install
Findings (2)
Accesses system credential store
SKILL.md ยท code ยท keychain
References webhook/callback URL
SKILL.md ยท prose ยท downgraded ยท WEBHOOK_URL
Permissions & capabilities
No declared permissions โ minimal attack surface.
credential_storepackage_installnetwork_in Is this flag fair?
Thanks โ recorded.