skills/clawlink-hq/skills/moneybird/Gen Agent Trust Hub

moneybird

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads and executes the @useclawlink/cli package from the NPM registry via npx. This is the official command-line interface provided by the vendor to facilitate the integration.
  • [COMMAND_EXECUTION]: The instructions direct the agent to run shell commands (e.g., npx @useclawlink/cli login, npx @useclawlink/cli run) to authenticate and interact with Moneybird data.
  • [PROMPT_INJECTION]: The skill processes data fetched from Moneybird, which constitutes an indirect prompt injection surface. The documentation includes a policy to confirm with the user before performing any write actions, which serves as a security best practice for managing this risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 02:42 PM
Security Audit — agent-trust-hub — moneybird