PurposebotBLOCK
🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai
Overview
🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai
4f3b4a2a472eOBSERVED · 2026-10-08Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| cursor | mentioned | |
| openclaw | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: purposebot
description: "Agentic commerce with Stripe and x402 USDC payments. Discover tools, APIs, and WebMCP servers with trust scores. Create orders, escrow funds, settle payments on-chain or via Stripe Connect — the full agent transaction lifecycle."
version: v1.2.0
metadata:
openclaw:
requires:
env:
- PURPOSEBOT_API_KEY
- PURPOSEBOT_REPORTER_AGENT_ID
- PURPOSEBOT_JWKS_URL
- PURPOSEBOT_SIGNING_KID
- PURPOSEBOT_SIGNING_KEY_PEM
bins:
- curl
- jq
- python3
- openssl
primaryEnv: PURPOSEBOT_API_KEY
emoji: "\U0001F4B0"
homepage: https://purposebot.ai
---
# PurposeBot — Agentic Commerce, Payments & Trust
PurposeBot gives your agent a full commerce stack: discover tools and services, create orders, escrow funds via **Stripe** or **x402 (USDC on Base)**, verify fulfillment, settle payments, and build on-chain reputation — all through a single API.
**What you can do:**
- **Pay for things** — Stripe card payments or x402 USDC stablecoin, with escrow and dispute resolution
- **Sell things** — List services, receive payments via Stripe Connect or on-chain settlement
- **Discover tools** — Search WebMCP servers, MCP tools, API endpoints, and agent services with trust scoring
- **Build reputation** — Issue interaction contracts, report outcomes, accumulate trust scores
## API Basics
- **Base URL:** `https://api.purposebot.ai/v1`
- **Auth header:** `X-API-Key: $PURPOSEBOT_API_KEY`
- All responses are JSON.
## 0. Onboarding & Signing Prerequisites
Search and stats only require `PURPOSEBOT_API_KEY`.
Commerce orders, payment contracts, and interaction contracts require a **registered agent identity** with a signing key.
There are two onboarding paths: the **Dashboard flow** (recommended — fastest, keys hosted for you) and the **Manual CLI flow** (for headless agents that can't use a browser).
### Dashboard Flow (Recommended)
1. **Sign in** at [purposebot.ai](https://purposebot.ai) using Google or GitHub OAuth
2. Open **Trust Center** from the dashboard sidebar
3. Click **Create API Key** — choose an expiry (30 days, 90 days, 1 year, or no expiry). Copy the key immediately; it won't be shown again.
4. Click **Generate Signing Key** — PurposeBot generates an RS256 keypair, hosts the JWKS at a public URL, and registers your agent identity automatically. Copy the **private key PEM** and store it securely.
5. Your agent ID, key ID (kid), and JWKS URL are shown in the Trust Center. Set the environment variables:
```bash
export PURPOSEBOT_API_KEY="pb_live_..."
export PURPOSEBOT_REPORTER_AGENT_ID="<agent-id-from-trust-center>"
export PURPOSEBOT_JWKS_URL="https://api.purposebot.ai/v1/agents/keys/<kid>/jwks.json"
export PURPOSEBOT_SIGNING_KID="<kid-from-trust-center>"
export PURPOSEBOT_SIGNING_KEY_PEM="/path/to/agent_key.pem"
```
That's it — you're ready to sign contracts and make payments.
### Manual CLI Flow (Headless Agents)
Use this if your agent can't open a browser or you need fully programmatic setup.
#### Step 1: Get an API key
Create one from the PurposeBot dashboard, or use a bootstrap token if your operator provides one:
```bash
curl -s "https://api.purposebot.ai/v1/auth/agent-bootstrap" \
-H "Content-Type: application/json" \
-d '{"bootstrap_token": "<token>"}' | jq .
```
#### Step 2: Generate a signing keypair
```bash
# Generate an RS256 private key
openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048 -out agent_key.pem
# Extract the public key in JWK format
KID="agent-$(date +%s)"
python3 - "$KID" <<'PY'
import json, sys
from cryptography.hazmat.primitives.serialization import load_pem_private_key, Encoding, PublicFormat
from cryptography.hazmat.primitives.asymmetric.rsa import RSAPublicNumbers
import base64
kid = sys.argv[1]
with open("agent_key.pem", "rb") as f:
private_key = load_pem_private_key(f.read(), password=None)
pub = private_key.public_key().public_numbers()
def b64url(n, length):
return base64.urlsafe_b64encode(n.to_bytes(length, "big")).rstrip(b"=").decode()
jwk = {
"kty": "RSA", "alg": "RS256", "use": "sig", "kid": kid,
"n": b64url(pub.n, 256), "e": b64url(pub.e, 3),
}
jwks = {"keys": [jwk]}
with open("jwks.json", "w") as f:
json.dump(jwks, f, indent=2)
print(f"KID={kid}")
print("Wrote jwks.json — host this file at a public URL")
PY
```
#### Step 3: Host the JWKS
Upload `jwks.json` to a publicly accessible URL. Options:
- GitHub Gist (raw URL)
- Static file hosting (S3, Cloudflare R2, Vercel)
- Your own server at `/.well-known/jwks.json`
The URL must be HTTPS and return `Content-Type: application/json`.
#### Step 4: Register your agent identity
```bash
# Sign a registration proof JWT
REG_PROOF="$(python3 - "$PURPOSEBOT_SIGNING_KID" <<'PY'
import json, time, uuid, base64, sys
from cryptography.hazmat.primitives.serialization import load_pem_private_key
from cryptography.hazmat.primitives.hashing import SHA256
from cryptography.hazmat.primitives.asymmetric.padding import PKCS1v15
kid = sys.argv[1]
with open("agent_key.pem", "rb") as f:
key = load_pem_private_key(f.read(), password=None)
now = int(time.time())
header = {"alg": "RS256", "typ": "JWT", "kid": kid}
payload = {
"iss": "openclaw-agent",
"sub": "my-agent-instance",
"iat": now, "exp": now + 120,
"jti": str(uuid.uuid4()),
"nonce": uuid.uuid4().hex[:16],
}
def b64url(b):
return base64.urlsafe_b64encode(b).rstrip(b"=").decode()
segments = [
b64url(json.dumps(header, separators=(",", ":")).encode()),
b64url(json.dumps(payload, separators=(",", ":")).encode()),
]
signing_input = ".".join(segments).encode()
sig = key.sign(signing_input, PKCS1v15(), SHA256())
print(".".join(segments + [b64url(sig)]))
PY
)"
curl -s "https://api.purposebot.ai/v1/agents/identity/register" \
-H "X-API-Key: $PURPOSEBOT_API_KEY" \
-H "Content-Type: application/json" \
-d "{
\"auth_type\": \"jwks\",
\"issuer\": \"openclaw-agent\",
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (4)
private_key = load_pem_private_key(f.read(), password=None)
key = load_pem_private_key(f.read(), password=None)
key = load_pem_private_key(f.read(), password=None)
<key>k5Ey9KFlkqpj+SDkUw+5ED9lTA3En/qUi0zdrydUCH3kMWTE3Eh65NXnFCaxlY2omY2JHnlEoK7Li7oOEvM7eG5VPdcO/sFlMfoCRdnLYdepJ+uLzYwOWR8W4yQVve/clxVFTVRL4DFleKInGdpAxIbHZT2yi4ADAMENls1N1XSLojRuqXePXDeAT/4Mv4TTx0s
Gates applied: no_behavioural_pass.
4f3b4a2a472efull audit observations/trust-audit/skill/leoyeai__purposebot.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4f3b4a2a472e | BLOCK | D | 69 | first audit |
Questions
What does the Purposebot skill do?
🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai
Is Purposebot safe to install?
No — not without reading the findings first. The audit graded it D (69/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What can Purposebot access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Purposebot work with?
Its documentation mentions cursor and openclaw. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f3b4a2a472e), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.