skills/clawlink-hq/skills/discord-bot/Gen Agent Trust Hub

discord-bot

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads and executes the '@useclawlink/cli' package from the npm registry using 'npx'. This is the vendor's official tool for interacting with their service.
  • [COMMAND_EXECUTION]: The skill uses shell commands to manage the Discord connection and execute actions. These commands are limited to the functionality of the '@useclawlink/cli' tool.
  • [PROMPT_INJECTION]: As a communication tool that reads messages from Discord, the skill has an inherent surface for indirect prompt injection (Category 8). Malicious instructions embedded in Discord messages could potentially influence the agent's behavior. The skill currently relies on the underlying agent's safety guardrails for this data ingestion.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 02:42 PM
Security Audit — agent-trust-hub — discord-bot