parallels-discord-roundtrip
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides a bash snippet that executes
sshto a development host (peters-mac-studio-1) andjqto parse a local JSON file (~/.openclaw/openclaw.json) to retrieve a Discord token. This is a standard practice for managing credentials in a development environment. - [COMMAND_EXECUTION]: The skill uses the Parallels Desktop command-line tool (
prlctl) andpnpmto perform test execution and virtual machine state management. - [PROMPT_INJECTION]: The skill reads Discord message history as part of its verification logic, which creates a potential surface for indirect prompt injection. This risk is assessed as safe due to the restricted context of a local smoke test and the specific nature of the data being processed.
Audit Metadata