discord-clawd

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses python3 to execute the local script openclaw_relay.py located at ~/Projects/agent-scripts/skills/openclaw-relay/scripts/openclaw_relay.py for resolving targets and sending messages.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its interaction with an external Discord-backed agent.
  • Ingestion points: Data and responses retrieved through the openclaw_relay.py ask command (SKILL.md).
  • Boundary markers: No specific boundary markers or delimiters are used to wrap or isolate the external agent's output from the local instructions.
  • Capability inventory: Subprocess execution of Python scripts and directory navigation (SKILL.md).
  • Sanitization: The skill relies on high-level instructions ('Do not expose gateway tokens or session secrets') rather than technical validation or programmatic sanitization of the external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 02:11 PM
Security Audit — agent-trust-hub — discord-clawd