ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      codejika

      Safety Report

      Shop Paper - Give your Claw Agent a credit card

      @codejika

      Samsung Electronics skill. Browse and purchase Galaxy smartphones, TVs, home appliances, wearables, monitors, and more from the world's largest smartphone an...

      40Downloads
      0Installs
      0Stars
      1Versions
      Monitoring & Logging3,640

      Security Analysis

      medium confidence
      Suspicious0.04 risk

      The skill's embedded SKILL.md is a straightforward Samsung product/browsing document and requests no credentials, but the external name/label you provided ("Give your Claw Agent a credit card") does not match the skill contents — this mismatch warrants caution before installing or granting payment capabilities.

      Mar 11, 20261 files3 concerns
      Purpose & Capabilityconcern

      The SKILL.md clearly documents a Samsung product/browsing skill (api_base = https://www.samsung.com, no credentials requested). However the user-supplied name/title ("Give your Claw Agent a credit card") implies payment or card-storage functionality which is not reflected in the skill metadata or declared requirements. That mismatch between claimed capability and requested resources is inconsistent.

      Instruction Scopenote

      This is an instruction-only skill (no code, no install). The visible portion of SKILL.md is product information and metadata; it declares no credentials and no instructions to read local files or environment. Because the SKILL.md was truncated in the sample, you should inspect the remainder for any runtime instructions that request payment details, ask the agent to collect/store card data, or call endpoints other than Samsung.

      Install Mechanismok

      No install spec, no downloaded code, and no binaries required — lowest-risk installation model for on-disk changes.

      Credentialsconcern

      The skill declares no required environment variables or credentials (which is appropriate for a read/browse skill). But the external title suggesting the agent will be given a credit card is not supported by the declared env/credential model. If the skill is intended to handle payments, it should request and document the precise payment integration (and that is absent).

      Persistence & Privilegeok

      always:false and default model invocation settings — the skill is not force-enabled for all agents and does not request elevated persistent privileges.

      Guidance

      Do not install or give this skill payment permissions until you verify the full SKILL.md and source. Actions to take: (1) Open the entire SKILL.md and search for any steps that request credit card numbers, tokens, vaulting, or calls to non-Samsung endpoints; (2) Confirm the skill owner and source — the registry owner ID is unknown; prefer official publisher listing or verified developer identity; (3) If the skill will handle purchases, it should explicitly document the payment flow and any required environment variables (e.g., payment provider keys) — absence of that is a red flag; (4) If you decide to test, use a sandbox/test card and monitor for unexpected network activity; (5) If the skill asks the agent to store or persist payment data, decline or require explicit, narrowly scoped credentials and an auditable storage mechanism. If you want, provide the full SKILL.md (untruncated) and I can re-evaluate the instructions for any hidden requests or scope creep.

      Latest Release

      v1.0.5

      Samsung skill updated to version 2.6.0 with expanded product and feature details. - Comprehensive catalog of Samsung Galaxy smartphones, TVs, home appliances, wearables, monitors, and more, with latest 2026 product specs. - Detailed overview of Galaxy AI features and SmartThings ecosystem integration across devices. - Information on Bespoke AI appliances, Samsung Care+ protection plans, and buying channels. - Updated support resources, including live chat, repair services, and Samsung Members app.

      More by @codejika

      CreditClaw Amazon | Order & Checkout at Amazon.com securely

      4 stars

      ShopClaw | Give your claw shopping tasks with strict controls

      4 stars

      CreditClaw | Give your agent a wallet or credit card

      2 stars

      CashClaw | Give your agent a wallet or credit card

      1 stars

      BTC Bot | Give your agent a wallet or credit card

      0 stars

      Bank Claw | Give your agent a bank account

      0 stars

      Published by @codejika on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]