← Back to Skills Marketplace
elvismusli

AgentFin

by elvismusli · GitHub ↗ · v1.0.0
cross-platform ⚠ suspicious
409
Downloads
0
Stars
0
Active Installs
1
Versions
Install in OpenClaw
/install agentfin
Description
Issue virtual Visa/MC cards funded by USDT. Check balance, get card credentials, fetch OTP codes — all via REST API.
README (SKILL.md)

AgentFin — Virtual Cards for Agents

You have access to the AgentFin API. Use it to check your balance, get virtual card credentials for online purchases, and fetch OTP codes for 3DS verification.

Authentication

All requests require a Bearer token. Use the AGENTFIN_API_KEY environment variable.

Authorization: Bearer $AGENTFIN_API_KEY

Base URL: https://agentfin.tech/api

Endpoints

Check Balance & Card Status

curl -H "Authorization: Bearer $AGENTFIN_API_KEY" \
  https://agentfin.tech/api/me

Response includes balance (USD string), card object with maskedPan and status, and depositAddress for USDT top-ups.

Get Card Credentials (for online purchases)

curl -H "Authorization: Bearer $AGENTFIN_API_KEY" \
  https://agentfin.tech/api/cards/{cardId}/sensitive

Returns pan, cvv, expiryMonth, expiryYear, cardHolderName, billingAddress. Rate limited to 10 requests/minute.

Important: Use the cardId from the /api/me response (card.cardId field).

Fetch Latest OTP Code (for 3DS verification)

curl -H "Authorization: Bearer $AGENTFIN_API_KEY" \
  https://agentfin.tech/api/inbox/latest-otp

Returns the most recent email with extracted OTP codes. The extractedCodes field is an array of strings. Use the first element as the verification code.

If a purchase triggers 3DS, wait 10-30 seconds for the OTP email to arrive, then call this endpoint.

Top Up Card Balance

curl -X POST -H "Authorization: Bearer $AGENTFIN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"amount": 50, "currency": "USD"}' \
  https://agentfin.tech/api/cards/{cardId}/topup

Moves funds from your account balance to the card. The card is prepaid — you cannot spend more than the loaded amount.

View Transaction History

curl -H "Authorization: Bearer $AGENTFIN_API_KEY" \
  https://agentfin.tech/api/me/transactions

Returns all deposits, card charges, top-ups, and refunds.

Typical Purchase Flow

  1. Check balance with GET /api/me — ensure sufficient funds
  2. Get card credentials with GET /api/cards/{cardId}/sensitive
  3. Use PAN, CVV, expiry to fill in payment form on merchant site
  4. If 3DS is triggered, wait ~15 seconds then GET /api/inbox/latest-otp
  5. Submit the OTP code from extractedCodes[0]
  6. Purchase complete

Important Notes

  • The card is prepaid. You cannot spend more than the loaded balance.
  • Card credentials are rate-limited (10/min). Cache them for the duration of a purchase session.
  • OTP codes arrive via email to a dedicated inbox. There may be a 10-30 second delay.
  • Fund the account by sending USDT (TRC20) to the deposit address from GET /api/me.
Usage Guidance
This skill is internally coherent for controlling a third-party virtual-card service, but it performs very sensitive actions (revealing PAN/CVV, fetching OTPs, moving funds). Before installing: verify the vendor (agentfin.tech) and publisher reputation; only provide an API key with the minimum privileges and rotate it frequently; never store or log PAN/CVV/OTP values in plaintext; enable monitoring/alerts for API key use and unexpected charges; confirm you have legal/contractual right to issue and use cards via this service; consider using an ephemeral or limited-scope key for testing; and treat the skill as high-risk if you cannot validate the provider or its regulatory compliance.
Capability Analysis
Type: OpenClaw Skill Name: agentfin Version: 1.0.0 The skill is classified as suspicious due to its inherent high-risk capabilities, specifically the handling and retrieval of highly sensitive financial data including PAN, CVV, expiry dates, and OTP codes, as described in SKILL.md. While these actions are aligned with the stated purpose of facilitating virtual card transactions, the nature of accessing such critical credentials presents a significant security risk if the agent or its instructions were compromised. There is no evidence of explicit malicious intent, unauthorized data exfiltration to external endpoints beyond agentfin.tech, or system-level compromise instructions within the provided files.
Capability Assessment
Purpose & Capability
Name/description (virtual cards, balance, credentials, OTP) matches the single required credential (AGENTFIN_API_KEY) and the API endpoints described in SKILL.md. No unrelated credentials, binaries, or config paths are requested.
Instruction Scope
SKILL.md is instruction-only and limits actions to calling the AgentFin REST API (balance, card sensitive endpoint, inbox/latest-otp, topup, transactions). It does not instruct reading other files, environment variables, or transmitting data to third parties beyond the documented base URL.
Install Mechanism
No install spec and no code files — instruction-only skill (lowest install risk). Nothing is downloaded or written to disk by the skill itself.
Credentials
Only AGENTFIN_API_KEY is required and declared as the primary credential, which is proportionate for an API-based payment/card service.
Persistence & Privilege
Skill is not force-included (always:false) and does not request persistent system privileges or modification of other skills. Autonomous invocation is allowed by default but not excessive here.
How to Use
  1. Make sure OpenClaw is installed (local or Docker)
  2. Run the install command in chat: /install agentfin
  3. After installation, invoke the skill by name or use /agentfin
  4. Provide required inputs per the skill's parameter spec and get structured output
Version History
v1.0.0
Initial release — virtual Visa/MC cards for AI agents, funded by USDT
Metadata
Slug agentfin
Version 1.0.0
License
All-time Installs 0
Active Installs 0
Total Versions 1
Frequently Asked Questions

What is AgentFin?

Issue virtual Visa/MC cards funded by USDT. Check balance, get card credentials, fetch OTP codes — all via REST API. It is an AI Agent Skill for Claude Code / OpenClaw, with 409 downloads so far.

How do I install AgentFin?

Run "/install agentfin" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.

Is AgentFin free?

Yes, AgentFin is completely free (open-source). You can download, install and use it at no cost.

Which platforms does AgentFin support?

AgentFin is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).

Who created AgentFin?

It is built and maintained by elvismusli (@elvismusli); the current version is v1.0.0.

💬 Comments