{"id":"dec613a3-2ba9-42ad-9e5f-cde01d744e83","entityType":"agent","slug":"clawhub-skills-amitbiswas1992-soho","name":"sohopay","canonicalUrl":"https://www.xpersona.co/agent/clawhub-skills-amitbiswas1992-soho","canonicalPath":"/agent/clawhub-skills-amitbiswas1992-soho","generatedAt":"2026-10-09T22:17:31.852Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"Initiate payments on the SOHO Pay credit layer using EIP-712 signatures. --- name: sohopay description: \"Initiate payments on the SOHO Pay credit layer using EIP-712 signatures.\" invocation: manual require_confirmation: true --- SOHO Pay — Credit Layer Payments This skill orchestrates payments through the SOHO Pay Creditor smart contract using the spendWithAuthorization EIP-712 flow. **This skill is manual-invocation only.** It must not be triggered autonomously by a model. Every invocati","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. Last updated 4/15/2026.","installCommand":"clawhub skill install skills:amitbiswas1992:soho","sourceUrl":"https://github.com/openclaw/skills/tree/main/skills/amitbiswas1992/soho","homepage":null,"primaryLinks":[{"label":"View on ClawHub","url":"https://github.com/openclaw/skills/tree/main/skills/amitbiswas1992/soho","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":50,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Initiate payments on the SOHO Pay credit layer using EIP-712 signatures. --- name: sohopay description: \"Initiate payments on the SOHO Pay credit layer using EI"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"no-adoption-signals","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No source adoption metrics were available."},"stars":null,"forks":null,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":null},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-02-25T03:36:07.835Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-02-25T03:36:07.835Z","lastIndexedAt":null,"nextCrawlAt":"2026-02-26T03:36:07.835Z","lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install skills:amitbiswas1992:soho","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-amitbiswas1992-soho/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-amitbiswas1992-soho/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-amitbiswas1992-soho/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-amitbiswas1992-soho/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-amitbiswas1992-soho/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-amitbiswas1992-soho/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T22:17:31.852Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-amitbiswas1992-soho/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-amitbiswas1992-soho/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-amitbiswas1992-soho/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-amitbiswas1992-soho/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"---\nname: sohopay\ndescription: \"Initiate payments on the SOHO Pay credit layer using EIP-712 signatures.\"\ninvocation: manual\nrequire_confirmation: true\n---\n\n# SOHO Pay — Credit Layer Payments\n\nThis skill orchestrates payments through the SOHO Pay `Creditor` smart contract using the `spendWithAuthorization` EIP-712 flow.\n\n**This skill is manual-invocation only.** It must not be triggered autonomously by a model. Every invocation requires explicit user confirmation.\n\n---\n\n## Architecture — Three-Party Separation\n\n```\n┌──────────────────┐     ┌──────────────────┐     ┌──────────────────┐\n│  Wallet Signer   │     │   SoHo (Credit)  │     │   Blockchain     │\n│  (user/operator) │     │                  │     │   (Base)         │\n│                  │     │  Credit checks   │     │                  │\n│  Signs EIP-712   │────▶│  JIT funding     │────▶│  Settlement      │\n│  Owns keys       │     │  Authorization   │     │  Creditor.sol    │\n│                  │     │                  │     │                  │\n│  MPC / HSM /     │     │  NEVER signs     │     │                  │\n│  Turnkey / Privy │     │  NEVER holds keys│     │                  │\n└──────────────────┘     └──────────────────┘     └──────────────────┘\n```\n\n**SoHo is a credit layer only.** It does not custody, hold, generate, or control any signing keys or key shards, and it does not produce EIP-712 signatures.\n\nAll EIP-712 signatures come from a separate **Wallet Signer** owned and controlled by the user or agent operator (e.g., MPC provider like Turnkey/Privy/Fireblocks, or a user wallet).\n\nThe skill orchestrates between:\n- **Wallet Signer** — signing (user/operator-controlled)\n- **SoHo** — credit checks + just-in-time funding (credit layer only)\n- **Blockchain** — settlement\n\n---\n\n## Usage\n\n```bash\nnode scripts/pay.js <amount> <merchantAddress> [payerAddress]\n```\n\n| Argument          | Description                                                        |\n| ----------------- | ------------------------------------------------------------------ |\n| `amount`          | Decimal USDC value (e.g. `10`, `0.5`)                             |\n| `merchantAddress` | Explicit 0x-prefixed EVM address (checksummed). **Never a name.** |\n| `payerAddress`    | Required when `SIGNER_PROVIDER=WALLET_SIGNER_REMOTE`              |\n\n### Example — Base Sepolia with local key (dev only)\n\n```bash\nexport RPC_URL=https://sepolia.base.org\nexport CHAIN_ID=84532\nexport SIGNER_PROVIDER=LOCAL_PRIVATE_KEY\nexport SOHO_DEV_PRIVATE_KEY=0xabc...\n\nnode scripts/pay.js 10 0x1234567890abcdef1234567890abcdef12345678\n```\n\n### Example — Base Sepolia with remote wallet signer (production pattern)\n\n```bash\nexport RPC_URL=https://sepolia.base.org\nexport CHAIN_ID=84532\nexport SIGNER_PROVIDER=WALLET_SIGNER_REMOTE\nexport WALLET_SIGNER_SERVICE_URL=https://your-mpc-signer.example.com\nexport SIGNER_SERVICE_AUTH_TOKEN=sk_live_...\n\nnode scripts/pay.js 10 0xMERCHANT... 0xPAYER...\n```\n\n---\n\n## Workflow\n\n1. **Validate config** — all env vars checked with Zod at startup; unknown chains rejected.\n2. **Parse inputs** — amount and explicit merchant address (no name-to-address generation).\n3. **Pre-flight credit checks** — SoHo credit layer verifies borrower registration, active status, credit limit.\n4. **Sign EIP-712** — Wallet Signer (user-controlled) produces signature. SoHo never signs.\n5. **Submit tx** — call `spendWithAuthorization` on the Creditor contract.\n6. **Return result** — transaction hash + block number.\n\n---\n\n## Supported Networks\n\n| Network       | Chain ID | Status                                     |\n| ------------- | -------- | ------------------------------------------ |\n| Base Sepolia  | 84532    | Supported                                  |\n| Base Mainnet  | 8453     | Requires `SOHO_MAINNET_CONFIRM=YES`        |\n\nUnknown chain IDs are rejected at config validation time.\n\n## Contract Addresses (Base Sepolia)\n\n| Contract         | Address                                      |\n| ---------------- | -------------------------------------------- |\n| Creditor         | `0x1867a19816f38ec31ec3af1be15fd7104f161978` |\n| Borrower Manager | `0x76e51158015e869ab2875fa17b87383d8886e93c` |\n| USDC (test)      | `0x55b8ff660d4f0f176de84f325d39a773a7a3bda7` |\n\n---\n\n## Security Model\n\n### Key Custody Boundary\n\n| Entity         | Role                                 | Holds keys? |\n| -------------- | ------------------------------------ | ----------- |\n| **Wallet Signer** | Produces EIP-712 signatures       | **Yes** — user/operator-controlled |\n| **SoHo**       | Credit authorization + JIT funding   | **No** — credit layer only |\n| **This skill** | Orchestration between the above      | **No** — passes typed data to signer |\n\nSoHo must NEVER custody, hold, generate, or control any signing keys or key shards.\n\n### Wallet Signer Providers\n\n| Provider                 | When to use                | Risk level |\n| ------------------------ | -------------------------- | ---------- |\n| `WALLET_SIGNER_REMOTE`  | **Production / Mainnet**   | Low — keys stay in user's MPC/HSM (Turnkey, Privy, Fireblocks, etc.) |\n| `LOCAL_PRIVATE_KEY`      | **Dev / Testnet only**     | High — raw key in env |\n\n- **Default and recommended**: `WALLET_SIGNER_REMOTE`. The skill sends EIP-712 typed data to the user's wallet signing service and never touches private keys.\n- **Dev-only fallback**: `LOCAL_PRIVATE_KEY` is gated to testnet chain IDs. Using it on mainnet requires `DEV_ALLOW_LOCAL_KEY=YES` and is **strongly discouraged**.\n\n### Mainnet Safety Gate\n\nTransactions on Base Mainnet (`CHAIN_ID=8453`) are refused unless `SOHO_MAINNET_CONFIRM=YES` is set. This prevents accidental mainnet spends during development.\n\n### Recipient Address Policy\n\nThe skill **never** derives or generates an address from a merchant name. The `merchantAddress` argument must be an explicit, valid, checksummed EVM address. Any non-address input is rejected with an error.\n\n### Invocation Policy\n\n- `invocation: manual` — the skill cannot be triggered autonomously.\n- `require_confirmation: true` — the orchestrator must obtain user confirmation before execution.\n- A runtime guard rejects execution if `SOHO_AUTONOMOUS=true` is detected in the environment.\n\n---\n\n## Threat Model & Mitigations\n\n| Threat | Mitigation |\n| ------ | ---------- |\n| **Signer compromise** | Default to `WALLET_SIGNER_REMOTE` (MPC/HSM); keys never leave the user's signing service. Local key gated to testnet only. |\n| **Replay attacks** | Random 32-byte nonce per transaction; `validAfter` / `expiry` window (10 min). On-chain nonce check in Creditor contract. |\n| **Wrong merchant address** | Address generation from names removed. Only explicit checksummed EVM addresses accepted; checksum validated before signing. |\n| **Accidental mainnet transaction** | `SOHO_MAINNET_CONFIRM=YES` safety gate required for chain ID 8453. |\n| **Autonomous invocation with signing authority** | `invocation: manual` in metadata; `require_confirmation: true`; runtime guard blocks `SOHO_AUTONOMOUS=true`. |\n| **SoHo used as signer** | Architecture enforces SoHo = credit-only. No signing key env vars reference SoHo as a signer. Skill never passes keys to SoHo API. |\n| **Undeclared env var dependencies** | All env vars declared in `skill.json` with types and sensitivity flags. |\n| **MITM on wallet signer service** | Use HTTPS for `WALLET_SIGNER_SERVICE_URL`; bearer token auth via `SIGNER_SERVICE_AUTH_TOKEN`. |\n\n---\n\n## Environment Variables\n\n### Required (all modes)\n\n| Variable          | Example                          | Description                              |\n| ----------------- | -------------------------------- | ---------------------------------------- |\n| `RPC_URL`         | `https://sepolia.base.org`       | JSON-RPC endpoint                        |\n| `CHAIN_ID`        | `84532`                          | 84532 (Sepolia) or 8453 (Mainnet)       |\n| `SIGNER_PROVIDER` | `WALLET_SIGNER_REMOTE`           | `WALLET_SIGNER_REMOTE` or `LOCAL_PRIVATE_KEY` |\n\n### Required for `WALLET_SIGNER_REMOTE`\n\n| Variable                     | Description                                          | Sensitive |\n| ---------------------------- | ---------------------------------------------------- | --------- |\n| `WALLET_SIGNER_SERVICE_URL`  | Base URL of user/operator's wallet signing service   | No        |\n| `SIGNER_SERVICE_AUTH_TOKEN`  | Bearer auth token for the wallet signing service     | **Yes**   |\n\n### SoHo Credit Layer\n\n| Variable       | Description                                           | Sensitive |\n| -------------- | ----------------------------------------------------- | --------- |\n| `SOHO_API_URL` | SoHo credit-layer API (credit checks, JIT funding)   | No        |\n\n### Required for `LOCAL_PRIVATE_KEY` (dev / testnet only)\n\n| Variable               | Description                                  | Sensitive |\n| ---------------------- | -------------------------------------------- | --------- |\n| `SOHO_DEV_PRIVATE_KEY` | User/operator's raw hex private key (NOT a SoHo key) | **Yes** |\n\n### Conditional\n\n| Variable               | When required                                         |\n| ---------------------- | ----------------------------------------------------- |\n| `SOHO_MAINNET_CONFIRM` | Must be `YES` when `CHAIN_ID=8453`                   |\n| `DEV_ALLOW_LOCAL_KEY`  | Set `YES` to allow local key on non-testnet (dangerous) |\n\n---\n\n## Dependencies\n\nInstall with:\n\n```bash\nnpm install\n```\n\n| Package  | Purpose                            |\n| -------- | ---------------------------------- |\n| `ethers` | EVM interactions, EIP-712 signing  |\n| `dotenv` | Load `.env` files                  |\n| `zod`    | Env var validation at startup      |\n","readmeExcerpt":"--- name: sohopay description: \"Initiate payments on the SOHO Pay credit layer using EIP-712 signatures.\" invocation: manual require_confirmation: true --- SOHO Pay — Credit Layer Payments This skill orchestrates payments through the SOHO Pay Creditor smart contract using the spendWithAuthorization EIP-712 flow. **This skill is manual-invocation only.** It must not be triggered autonomously by a model. Every invocati","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"┌──────────────────┐     ┌──────────────────┐     ┌──────────────────┐\n│  Wallet Signer   │     │   SoHo (Credit)  │     │   Blockchain     │\n│  (user/operator) │     │                  │     │   (Base)         │\n│                  │     │  Credit checks   │     │                  │\n│  Signs EIP-712   │────▶│  JIT funding     │────▶│  Settlement      │\n│  Owns keys       │     │  Authorization   │     │  Creditor.sol    │\n│                  │     │                  │     │                  │\n│  MPC / HSM /     │     │  NEVER signs     │     │                  │\n│  Turnkey / Privy │     │  NEVER holds keys│     │                  │\n└──────────────────┘     └──────────────────┘     └──────────────────┘"},{"language":"bash","snippet":"node scripts/pay.js <amount> <merchantAddress> [payerAddress]"},{"language":"bash","snippet":"export RPC_URL=https://sepolia.base.org\nexport CHAIN_ID=84532\nexport SIGNER_PROVIDER=LOCAL_PRIVATE_KEY\nexport SOHO_DEV_PRIVATE_KEY=0xabc...\n\nnode scripts/pay.js 10 0x1234567890abcdef1234567890abcdef12345678"},{"language":"bash","snippet":"export RPC_URL=https://sepolia.base.org\nexport CHAIN_ID=84532\nexport SIGNER_PROVIDER=WALLET_SIGNER_REMOTE\nexport WALLET_SIGNER_SERVICE_URL=https://your-mpc-signer.example.com\nexport SIGNER_SERVICE_AUTH_TOKEN=sk_live_...\n\nnode scripts/pay.js 10 0xMERCHANT... 0xPAYER..."},{"language":"bash","snippet":"npm install"}],"parameters":{},"dependencies":[],"permissions":[],"extractedFiles":[],"languages":["typescript"],"docsSourceLabel":"CLAWHUB","editorialOverview":"Initiate payments on the SOHO Pay credit layer using EIP-712 signatures. --- name: sohopay description: \"Initiate payments on the SOHO Pay credit layer using EIP-712 signatures.\" invocation: manual require_confirmation: true --- SOHO Pay — Credit Layer Payments This skill orchestrates payments through the SOHO Pay Creditor smart contract using the spendWithAuthorization EIP-712 flow. **This skill is manual-invocation only.** It must not be triggered autonomously by a model. Every invocati","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":363,"uniquenessScore":68,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T22:17:31.852Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}