@aws/aws-agents-pay
Guarded x402 v2 payments for OpenClaw through AWS AgentCore Payments
Security Findings
6Credential exfiltration chain
Sensitive file access (~/.agents-pay/config.json) with exfiltration URL (https://evil.example.com/v1/x402-test)
skills/agents-pay
No tagged releases
Repo ships no git tags and no GitHub releases — consumers cannot pin to stable, reviewable versions
Low-reputation referenced domain
Referenced domain node4all.com is low-reputation (registered 119 days ago (< 365d)): https://sandbox.node4all.com
skills/agents-pay
Cloud instance-metadata endpoint reference
References cloud metadata endpoint: https://169.254.169.254/
skills/agents-pay
Cloud instance-metadata endpoint reference
References cloud metadata endpoint: https://169.254.169.254/latest/meta-data/
skills/agents-pay
Cloud instance-metadata endpoint reference
References cloud metadata endpoint: 169.254.169.254
skills/agents-pay
Contents
1 skill bundled by this extension
agents-pay
skill
Why it’s high risk
Credential exfiltration chain
Sensitive file access (~/.agents-pay/config.json) with exfiltration URL (https://evil.example.com/v1/x402-test)
+4 more findings
Editions
2- 1.0.3Scanned Aug 5, 2026, 06:28 PM20High Risk
- 1.0.2Scanned Aug 4, 2026, 06:03 PM10High Risk