Real Skill packageSource verifiedClawHub registry

buy

Shop for the user through the `portage` CLI. Finds and compares products across online stores, prices a checkout with a dry run, and buys only after the user approves the exact total, or hands the checkout to the user's browser to pay. Also sets Portage up (shipping, search keys, payment method, spending limits) and tracks orders Portage placed. Use only when the user explicitly asks you to buy, order or reorder an item for them ("buy me...", "order...", "reorder...", "check this out for me"), to set Portage up fo…

Identity and source

Publisher attributionTom Whitbreadregistry owner unverified by skillvetai
Functional categoryAgent Engineering, Security & Governanceautomatically inferred · 58% rule confidence
Package forminstruction bundle5 recorded files
Canonical sourceClawHub registryclawhub:tomtom87:portage-buy
Open canonical source ↗

Platform declarations

These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.

OpenClawnative officialProvenance: registry distribution

Independent structural checks

These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.

Claude Codepasses structure
Checker 0.1.0 · agent-skills-2026-08-13+claude-code-docs-2026-08-13 · 10/1/2026.claude/skills/buy

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenAI Codexpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+codex-docs-2026-08-13 · 10/1/2026.agents/skills/buy

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenClawpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+openclaw-docs-2026-08-13 · 10/1/2026skills/buy

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

Installation and inspection

This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.

clawhub install @tomtom87/portage-buy
clawhub inspect @tomtom87/portage-buy --version 0.10.4

Security evidence

SkillVetAI static result: no findings detected

This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.

Status
completed
Coverage
full text content
Files
5 / 5 inspected as text
Checked
10/1/2026, 6:28:09 PM
Scanner
0.1.3
Policy
1.0.3
3 inferred permission indicators
  • network access — automatically inferred
  • filesystem write — automatically inferred
  • browser control — automatically inferred
2 dependency and API indicators
  • api: clawhub.ai
  • api: portage.readthedocs.io
External clawhub result: suspicious

This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.

Evidence checked
10/1/2026, 9:05:02 AM
Release binding
Matches this record
  • vt: clean
  • skillspector: suspicious
  • llm: suspicious

Recorded files

The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.

Package content hashsha256:7715fe93404c76945a7d08d9a8c220af89beab97ed70b5f07d42ecfbace538ef
Show up to 5 recorded paths
  • references/handoff-only.md
  • references/outcomes.md
  • references/raw-ucp.md
  • skill-card.md
  • SKILL.md

Source changelog

- Clarified the skill's scope: only handle explicit buy/order/reorder/setup/track requests for Portage purchases. - Updated environment variable descriptions for consistency and specificity. - Small corrections to terminology, e.g. specifying "Etsy OAuth token" instead of "Etsy access token". - Removed the redundant skill-card.md file.

Release security diff

mediumCompared fixed releases 0.10.0 and 0.10.4; 0 finding and 0 permission indicators were added.

Both fixed releases were scanned under the current scanner and policy, so finding, permission and dependency changes are available.

Change reasons and limitations
  • permission surface changed
  • dependency surface changed
  • file surface changed
  • content hash changed

Observed release history

These older immutable releases were observed by prior successful syncs. They remain recorded when a newer release becomes current.

0.10.010/1/2026sha256:c3abc9410bcac4f325d90d1b311e39aefc6f2f87ff023c9255cf222f6f7ee9b1