google-drive

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill relies on the @useclawlink/cli package, which is executed via npx. This downloads the tool from the official NPM registry to facilitate communication with the Google Drive API.
  • [CREDENTIALS_UNSAFE]: The skill documentation notes that user credentials for the service are stored at ~/.clawlink/credentials.json. This is a standard and transparent method for managing local session tokens for a CLI tool.
  • [COMMAND_EXECUTION]: Functionality is achieved through the execution of shell commands using the vendor's CLI. These commands perform specific Google Drive actions such as searching, uploading, and managing permissions.
  • [DATA_EXFILTRATION]: The skill handles sensitive data from Google Drive and communicates with the claw-link.dev domain. This behavior is consistent with the skill's primary purpose of providing cloud storage integration and utilizes the vendor's established infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 02:42 PM
Security Audit — agent-trust-hub — google-drive