pop-pay
Installation
SKILL.md
What This Skill Does
Gives your OpenClaw agent the ability to pay at any online store using your own existing credit card — no account to create, no SaaS subscription, no external service to trust.
Your card number is stored in your local system keychain and is never placed in the agent's context window. When payment is approved, credentials are injected directly into the browser's payment form via CDP (Chrome DevTools Protocol — an open protocol maintained by Google) in a separate process — the agent never sees them. If your agent is compromised by a prompt injection attack, the attacker cannot steal your card.
Privacy & Data Flow
All payment logic runs on your machine. There are no Point One Percent servers involved in the payment path.
| Component | Default | Data stays |
|---|---|---|
| Card credentials | Local system keychain | Your machine only |
| Spend policy | ~/.config/pop-pay/.env |
Your machine only |
| Guardrail engine | keyword mode (zero API calls) |
Your machine only |
| Guardrail engine (optional) | llm mode — uses your own API key |
Your API provider |
| Webhook notifications | Disabled by default — only active if POP_WEBHOOK_URL is set |
Your chosen endpoint |