discord
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
npxto execute the@useclawlink/clitool for authentication and performing Discord actions. This is the intended primary purpose of the skill. - [EXTERNAL_DOWNLOADS]: The skill downloads and executes the
@useclawlink/clipackage from the official npm registry. The package name aligns with the author's identity (clawlink-hq). - [CREDENTIALS_UNSAFE]: The documentation identifies that credentials are stored locally at
~/.clawlink/credentials.json. This is an informative note about how the tool manages session tokens and does not involve instructions to exfiltrate or hardcode secrets.
Audit Metadata