All skills
aws avatar

/agents-pay

@9766f27

Use when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits. Covers payment setup, policy, session budgets, and troubleshooting. Triggers on: "my agent hit a 402 while calling an API", "a tool call returned 402 Payment Required", "my agent needs to pay for x402-protected content", "let the agent pay for content, capped at $5 per session", "set a spend limit for the agent", "ProcessPayment failed", or "why did my agent refuse to pay". Not for BUILDING payment capability for end users, including wallets and framework middleware; use agents-build and references/payments.md. For non-paid APIs via Gateway use agents-connect. For inbound auth use agents-harden. For project scaffolding use agents-get-started.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/agents-pay

This session only. Nothing lands on disk.

packagesopenclawPUBLISHING.md

≈786 tokens on demand. Your agent reads this file only when SKILL.md points to it.

OpenClaw Package Publishing

This directory is the canonical source for the @aws/aws-agents-pay OpenClaw package. The published artifact also contains the canonical agents-pay skill staged from the parent skill directory.

Release versions

  • Initial release: 1.0.0
  • Scoped install compatibility fix: 1.0.1
  • Bundled canonical skill and external setup guidance: 1.0.2
  • Setup discoverability improvements: 1.0.5
  • AgentCore CLI 0.26.x compat and flag clarity: 1.0.6
  • Clean-install onboarding and generated-config safety: 1.0.7

Do not publish until the package has passed the checks below and the publisher has given explicit approval.

Reproducible build and tests

cd plugins/aws-agents/skills/agents-pay/packages/openclaw
npm ci
npm test
npm audit --audit-level=moderate

The committed lockfile pins the complete dependency graph. OpenClaw is an optional peer because the package is loaded by an existing OpenClaw host.

Validate and pack

Use the pinned ClawHub CLI release:

npx --yes clawhub@0.23.1 package validate . \
  --runtime --allow-execute --json

npx --yes clawhub@0.23.1 package pack . \
  --pack-destination ./artifacts --json

For inspection against a local OpenClaw checkout, add:

--openclaw /absolute/path/to/sample-OpenClaw-on-AWS-with-Bedrock

Record the generated tarball SHA-256 and verify it before publication:

shasum -a 256 artifacts/*.tgz
npx --yes clawhub@0.23.1 package verify artifacts/*.tgz \
  --sha256 <recorded-sha256> --json

Smoke-test installation against the minimum supported OpenClaw version:

OPENCLAW_TEST_HOME=$(mktemp -d)
HOME="$OPENCLAW_TEST_HOME" npx --yes openclaw@2026.3.24 \
  plugins install artifacts/*.tgz

Publication dry run

Run this before requesting publication approval:

npx --yes clawhub@0.23.1 package publish . \
  --family code-plugin \
  --name @aws/aws-agents-pay \
  --version 1.0.7 \
  --tags latest \
  --source-repo aws/agent-toolkit-for-aws \
  --source-commit <release-commit-sha> \
  --source-ref <release-branch-or-tag> \
  --source-path plugins/aws-agents/skills/agents-pay/packages/openclaw \
  --dry-run --json

Stop after the dry run. Publishing, creating a payment session, and spending testnet funds each require separate explicit approval.

Post-publication validation

Install the release on the supplied OpenClaw deployment and validate x402 v2 only:

  1. Confirm the package version and the two-tool runtime inventory.
  2. Confirm paid replay uses PAYMENT-SIGNATURE.
  3. Refuse unapproved recipient, value, asset, scheme, network, origin, SSRF, and redirect cases before ProcessPayment; separately verify explicit allowAnyRecipient mode retains every non-recipient control.
  4. Confirm signed proofs and paid response bodies never appear in tool output or gateway logs.
  5. Complete one approved Base Sepolia payment.
  6. Roll back to the prior plugin and configuration.

Apply any validation fix to this canonical directory first and rerun the checks. The consuming package uses the published artifact and does not carry a source snapshot.

Source: SKILL.md on GitHub

1 alert1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill provides a secure framework for AI agents to settle x402-protected payment challenges using AWS AgentCore. It includes robust security measures such as SSRF protection, strict IAM role separation, and content isolation to prevent prompt injection from paid external resources.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: CRITICAL · 3 issues

Signed by skilld at 9766f27. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "type": "skill",
  "version": "1.0.0",
  "author": "aws-agentcore"
}
All 1 allowed tools
Read Bash

README badge

README badge for aws/agent-toolkit-for-aws/agents-pay