安全扫描
OpenClaw
安全
high confidenceNULL
评估建议
This skill is coherent: it uses the Membrane CLI as a proxy to manage Discord connections and avoids asking for raw API keys. Before installing, verify you trust the @membranehq/cli npm package and the Membrane service (review its homepage, privacy, and permissions). Installing a global npm package modifies your system PATH and may require elevated privileges—avoid doing this on shared or sensitive hosts. Be aware that using this skill gives Membrane (and the connector you create) access to your...详细分析 ▾
✓ 用途与能力
The name/description (Discord integration) match the instructions: all actions are performed via the Membrane CLI and a Membrane account. No unrelated credentials, binaries, or config paths are requested.
✓ 指令范围
SKILL.md stays within scope: it instructs installing and using the Membrane CLI, logging in, creating a Discord connector, listing/running actions, and proxying Discord API requests. It does not ask to read unrelated files or access unrelated environment variables.
ℹ 安装机制
There is no formal install spec in the registry (instruction-only), but the doc tells users to run `npm install -g @membranehq/cli`. This is expected for a CLI-based integration but requires trusting the npm package and global install behavior.
✓ 凭证需求
The skill declares no required environment variables or credentials; it relies on Membrane to manage auth. This is proportionate to the stated purpose.
✓ 持久化与权限
The skill is not always-enabled and does not request persistent system privileges or modify other skills. Autonomous model invocation is allowed (platform default) but not combined with other concerning flags.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.22026/3/31
NULL
● Pending
安装命令
点击复制官方npx clawhub@latest install discord-integration
镜像加速npx clawhub@latest install discord-integration --registry https://cn.longxiaskill.com