google-drive
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill relies on the
@useclawlink/clipackage, which is executed vianpx. This downloads the tool from the official NPM registry to facilitate communication with the Google Drive API. - [CREDENTIALS_UNSAFE]: The skill documentation notes that user credentials for the service are stored at
~/.clawlink/credentials.json. This is a standard and transparent method for managing local session tokens for a CLI tool. - [COMMAND_EXECUTION]: Functionality is achieved through the execution of shell commands using the vendor's CLI. These commands perform specific Google Drive actions such as searching, uploading, and managing permissions.
- [DATA_EXFILTRATION]: The skill handles sensitive data from Google Drive and communicates with the
claw-link.devdomain. This behavior is consistent with the skill's primary purpose of providing cloud storage integration and utilizes the vendor's established infrastructure.
Audit Metadata