runpod
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes the
@useclawlink/clipackage, which is downloaded and executed vianpxfrom the official npm registry. - [COMMAND_EXECUTION]: Instructions provide commands for the agent to interact with the RunPod API via the vendor's CLI, including account inspection and resource management (clusters, pods, and secrets).
- [DATA_EXPOSURE]: The skill documents the storage of authentication credentials in the user's home directory at
~/.clawlink/credentials.json, which is standard behavior for CLI-based authentication tools.
Audit Metadata