moneybird
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads and executes the
@useclawlink/clipackage from the NPM registry vianpx. This is the official command-line interface provided by the vendor to facilitate the integration. - [COMMAND_EXECUTION]: The instructions direct the agent to run shell commands (e.g.,
npx @useclawlink/cli login,npx @useclawlink/cli run) to authenticate and interact with Moneybird data. - [PROMPT_INJECTION]: The skill processes data fetched from Moneybird, which constitutes an indirect prompt injection surface. The documentation includes a policy to confirm with the user before performing any write actions, which serves as a security best practice for managing this risk.
Audit Metadata