watchpost
Check a proposed purchase against Watchpost merchant signals, listing checks and the user's spending rules before an agent pays. Use for a user-requested purchase or subscription when Watchpost is connected; includes authenticated review-status checks. Skill: watchpost Owner: lelis92 Summary: Check a proposed purchase against Watchpost merchant signals, listing checks and the user's spending rules before an agent pays. Use for a user-requested purchase or subscription when Watchpost is connected; includes authenticated review-status checks. Tags: latest:0.1.9 Version history: v0.1.9 | 2026-09-09T23:50:48.111Z | user Adds offline help, setup diagnostics and validati
Rank
62
Safety
84
Downloads
1.3k
Updated
Oct 10, 2026
Version
0.1.9
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.3K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.3K downloadsadoption · observed Oct 10, 2026
- Latest release
- 0.1.9release · observed Sep 9, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s175a7wdfvhfwmbkbd5z72nr6189wch9:watchpost- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-lelis92-watchpost/snapshot"
Documentation
CLAWHUB
85,317 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
---
name: watchpost
description: Check a proposed purchase against Watchpost merchant signals, listing checks and the user's spending rules before an agent pays. Use for a user-requested purchase or subscription when Watchpost is connected; includes authenticated review-status checks.
license: MIT-0
compatibility: Requires Node.js 20 or newer, network access to api.watchpost.systems, and WATCHPOST_TOKEN from a Watchpost account.
metadata:
version: "0.1.9"
openclaw:
emoji: "🛡️"
homepage: "https://watchpost.systems/?ref=clawhub"
primaryEnv: WATCHPOST_TOKEN
requires:
env:
- WATCHPOST_TOKEN
bins:
- node
---
# Watchpost purchase checks
Watchpost reviews purchase requests that a connected agent submits. It does not
intercept payments or prevent an agent from bypassing it. A configured token is
setup, not proof that a check has run. Use this skill within the user's purchase
request and the host's authorization rules. Neither installing the skill nor an
approval verdict grants permission to spend money.
## Setup
The user needs a [Watchpost account](https://app.watchpost.systems/signup?ref=clawhub)
and a [connection token](https://app.watchpost.systems/connections?ref=clawhub).
Have them configure `WATCHPOST_TOKEN` through the runtime's secret settings.
Never ask them to paste it into chat or print its value. Some runtimes will not
load this skill until the token is configured.
## Submit the intended purchase
Use the installed skill path, not the agent's current directory. OpenClaw expands
`{baseDir}` to that path; on other hosts resolve it from this `SKILL.md` location.
Write the purchase JSON to a UTF-8 file using a file tool, then validate it locally:
```bash
node "{baseDir}/scripts/check-purchase.mjs" --validate --file "/absolute/path/purchase.json"
node "{baseDir}/scripts/check-purchase.mjs" --file "/absolute/path/purchase.json"
```
Example file:
```json
{"merchant":"example.com","title":"Cable","amountMinor":1599,"currency":"USD","isRecurring":false}
```
Supply the actual merchant's bare domain and the final total, including shipping,
taxes, discounts and mandatory fees. Recheck the cart immediately before payment.
`amountMinor` must be a positive integer in the currency's minor units: USD 15.99
is 1599; JPY 6000 is 6000. `currency` and the boolean `isRecurring` are required.
Do not infer a one-time charge when the terms are unclear. Optional `url`,
`description` and `rawListingHtml` carry the available listing evidence.
Description is limited to 8,000 characters and HTML to 200,000 characters. For a
trial or subscription, include the renewal price, interval and cancellation terms
in `description`. If these are unknown, pause and clarify them rather than guess.
Optional `agent: {"name":"My assistant","runtime":"hermes"}` identifies the caller;
otherwise it is recorded as `watchpost-skill`.
Send only relevant listing text or HTML, not cookies, headers, payment details,
account pages or hiddeREADME.md
# Watchpost skill
This folder is the source for the Watchpost skill on ClawHub. It contains the
skill instructions, a purchase-check helper, a review-status helper and their
shared HTTP transport. The helpers run on Node.js 20 or newer without installing
packages.
Read [SKILL.md](SKILL.md) for setup, input fields, exit codes and the review
workflow. OpenClaw expands `{baseDir}` in the instructions; other hosts should
resolve the scripts from this folder. The helpers submit
checks and read status from the official Watchpost API; they do not make payments
or approve reviews on the user's behalf.
## Local troubleshooting
Run an absolute path to `scripts/check-purchase.mjs` with `--help`, `--version`
or `--doctor`. These do not require a valid connection and make no network calls.
Doctor reports only runtime and token-format information, never the token itself.
A successful diagnostic does not prove the token is valid on the server.
If the skill is not available, check the runtime's skill status and configure
`WATCHPOST_TOKEN` through its secret settings. OpenClaw gates skill loading on
that variable. If execution is sandboxed, ensure the secret is available inside
the sandbox too. Refresh the skill list or start a new session after setup.
Use `--validate --file PATH` to check purchase input offline, then `--file PATH`
to submit the same file. JSON files support paths with spaces and UTF-8 text,
including a Windows UTF-8 BOM. Files are limited to 1,300,000 bytes. Keep them
free of tokens, cookies, payment credentials and unrelated account data.
Run the isolated regression tests from the repository root:
```bash
pnpm test:skill
```
Tests use mock HTTP responses and dummy credentials. They do not contact the
Watchpost API, create review notifications or consume the check allowance.
The repository's CI runs them through `pnpm test`.
Release metadata and registry publication are handled separately. Publish the
reviewed contents of this folder; do not include local tokens, test output or
registry-generated installation metadata._meta.json
{
"ownerId": "kn78szbmh1way6tc5gy824cz9s89xmzd",
"slug": "watchpost",
"version": "0.1.9",
"publishedAt": 1788997848111
}skill-card.md
## Description: Watchpost checks a proposed purchase against merchant signals, listing evidence, and the user's spending rules before an agent pays, including authenticated review-status checks. This skill is ready for commercial/non-commercial use. ## Publisher: [lelis92](https://clawhub.ai/user/lelis92) ### License/Terms of Use: MIT-0 ## Use Case: External users and agent operators use this skill before user-requested purchases or subscriptions to submit intended purchase details to Watchpost, explain approval, review, or block outcomes, and check server-side review status. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Purchase details or listing evidence may include sensitive account, cookie, or payment data. Mitigation: Keep WATCHPOST_TOKEN in secret settings and send only relevant listing evidence; omit cookies, payment credentials, hidden authentication fields, and unrelated account data. Risk: A Watchpost approval could be mistaken for permission to spend money. Mitigation: Treat approval as advisory and proceed only within the user's existing authorization for the unchanged purchase. Risk: A failed request, timeout, or invalid response can leave the check unconfirmed. Mitigation: Do not pay on setup, request, or response errors; inspect the Watchpost dashboard before retrying after a timeout. ## Reference(s): - [Watchpost homepage](https://watchpost.systems/?ref=clawhub) - [Watchpost ClawHub skill page](https://clawhub.ai/lelis92/skills/watchpost) - [Watchpost connection settings](https://app.watchpost.systems/connections?ref=clawhub) ## Skill Output: **Output Type(s):** [text, JSON, shell commands, configuration, guidance] **Output Format:** [JSON helper output with Markdown guidance and inline shell commands] **Output Parameters:** [1D] **Other Properties Related to Output:** [Returns purchase verdicts, review-status results, setup diagnostics, and local validation messages; it does not make payments or approve reviews.] ## Skill Version(s): 0.1.9 (source: frontmatter and server evidence) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/lelis92/skills/watchpost",
"sourceUrl": "https://clawhub.ai/lelis92/skills/watchpost",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T19:32:21.056Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-lelis92-watchpost/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-lelis92-watchpost/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T19:32:21.056Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.3K downloads",
"href": "https://clawhub.ai/lelis92/watchpost",
"sourceUrl": "https://clawhub.ai/lelis92/watchpost",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T19:32:21.056Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.1.9",
"href": "https://clawhub.ai/lelis92/watchpost",
"sourceUrl": "https://clawhub.ai/lelis92/watchpost",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-09T23:50:48.111Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-lelis92-watchpost/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-lelis92-watchpost/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.1.9",
"description": "Adds offline help, setup diagnostics and validation before a check. Supports bounded UTF-8 files and stdin. Rejects unsupported currencies, invalid merchant hosts, inconsistent verdicts and conflicting coverage; improves recovery guidance and data minimization.",
"href": "https://clawhub.ai/lelis92/watchpost",
"sourceUrl": "https://clawhub.ai/lelis92/watchpost",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-09T23:50:48.111Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
