pop-pay

Installation
SKILL.md

What This Skill Does

Gives your OpenClaw agent the ability to pay at any online store using your own existing credit card — no account to create, no SaaS subscription, no external service to trust.

Your card number is stored in your local system keychain and is never placed in the agent's context window. When payment is approved, credentials are injected directly into the browser's payment form via CDP (Chrome DevTools Protocol — an open protocol maintained by Google) in a separate process — the agent never sees them. If your agent is compromised by a prompt injection attack, the attacker cannot steal your card.


Privacy & Data Flow

All payment logic runs on your machine. There are no Point One Percent servers involved in the payment path.

Component Default Data stays
Card credentials Local system keychain Your machine only
Spend policy ~/.config/pop-pay/.env Your machine only
Guardrail engine keyword mode (zero API calls) Your machine only
Guardrail engine (optional) llm mode — uses your own API key Your API provider
Webhook notifications Disabled by default — only active if POP_WEBHOOK_URL is set Your chosen endpoint
Installs
2
First Seen
Apr 23, 2026
pop-pay from skills.volces.com