discord-clawd
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions in
SKILL.mdrequire the agent to execute a local Python script located at~/Projects/agent-scripts/skills/openclaw-relay/scripts/openclaw_relay.pyusingpython3. It utilizes various subcommands liketargets,resolve, andaskto facilitate the relay. - [DATA_EXFILTRATION]: The skill is designed to transmit messages to an external Discord session. While this is the intended functionality of the OpenClaw relay, it represents a network egress channel where agent context or user data is sent to a third-party service (Discord) that is not part of the standard whitelisted domains.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data returned from the Discord relay, creating a vulnerability to malicious instructions embedded in Discord messages.
- Ingestion points: Data enters the agent's context through the output of the
python3 ... askcommand, which retrieves replies from the Discord-backed agent. - Boundary markers: None are present. The instructions do not specify delimiters or warnings for the agent to ignore potentially malicious instructions within the relay's output.
- Capability inventory: The skill maintains shell execution capabilities (
python3) and network access (via the relay script). - Sanitization: No sanitization, filtering, or validation logic is defined for the content received from the Discord relay.
Audit Metadata