discord-bot
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the 'clawlink-plugin' from the vendor's centralized repository.
- [COMMAND_EXECUTION]: Provides setup instructions that include shell commands for installing and configuring the required plugin environment.
- [DATA_EXFILTRATION]: Performs network requests to the Discord API and the vendor's authentication service (claw-link.dev). These are legitimate operations required for bot functionality.
- [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection through data ingestion. 1. Ingestion points: Data is pulled from external Discord channels and user profiles via tools like 'discordbot_list_messages'. 2. Boundary markers: The instructions do not define specific delimiters for processed external data. 3. Capability inventory: The skill has the ability to perform high-impact actions like banning users and deleting content. 4. Sanitization: There is no evidence of content sanitization within the skill's instructions.
Audit Metadata