discord-bot

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the 'clawlink-plugin' from the vendor's centralized repository.
  • [COMMAND_EXECUTION]: Provides setup instructions that include shell commands for installing and configuring the required plugin environment.
  • [DATA_EXFILTRATION]: Performs network requests to the Discord API and the vendor's authentication service (claw-link.dev). These are legitimate operations required for bot functionality.
  • [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection through data ingestion. 1. Ingestion points: Data is pulled from external Discord channels and user profiles via tools like 'discordbot_list_messages'. 2. Boundary markers: The instructions do not define specific delimiters for processed external data. 3. Capability inventory: The skill has the ability to perform high-impact actions like banning users and deleting content. 4. Sanitization: There is no evidence of content sanitization within the skill's instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 11:11 AM
Security Audit — agent-trust-hub — discord-bot