skills/clawlink-hq/skills/gumroad/Gen Agent Trust Hub

gumroad

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute the @useclawlink/cli tool via npx to perform various Gumroad actions such as listing products and verifying licenses. This is the intended functionality for the integration.
  • [EXTERNAL_DOWNLOADS]: Uses npx to download and run the @useclawlink/cli package from the official NPM registry. This package is maintained by the skill's author and is required for the integration to function.
  • [CREDENTIALS_UNSAFE]: Identifies that credentials obtained during the login process are stored locally at ~/.clawlink/credentials.json. This path is disclosed to the user as part of the setup instructions and represents standard local credential management for CLI tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 02:42 PM
Security Audit — agent-trust-hub — gumroad