T09 · Insecure Skill Coding Practices
- Location
SKILL.md:362- Finding
Discord Webhook Credentials and Message Data Are Forwarded Through a Third-Party Service
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is meant to post to Discord, but it routes webhook credentials and message or file data through AgentPMT and trusts mutable remote instructions, so it needs review before installation.
Install only if you are comfortable sending Discord webhook URLs, message contents, embeds, mentions, and attachments through AgentPMT as well as Discord. Treat webhook URLs as secrets, avoid sensitive or regulated data, restrict mentions, prefer pinned installation paths, and do not let remote live instructions override your local safety rules without review.
SKILL.md:362Discord Webhook Credentials and Message Data Are Forwarded Through a Third-Party Service
SKILL.md:216Unaudited Remote Instructions Can Override the Locally Reviewed Skill
SKILL.md:280Unpinned Third-Party Installation Commands Create a Supply-Chain Risk
The skill's core capability is to send arbitrary content, embeds, and files to Discord channels through a webhook URL, which is an exfiltration-capable channel. In context this is intentional product functionality, not necessarily malicious, but from a security perspective it is a real data egress mechanism that could be abused to leak sensitive information, especially because webhook destinations can be attacker-controlled and attachments are supported.
---
name: post-on-discord-channel
description: "Post On Discord Channel: Send messages to Discord channels via webhooks with markdown, embeds, file attachments, and mention controls. Use when an agent needs post on discord channel, update community when new products features drop, notify channel followers of upcoming events, notify users of support ticket requests, integrate with content publishing pipeline, send, webhook url, content through AgentPMT-hosted remote tool calls. Discovery terms: post on discord channel."
version: 1.0.0
homepage: https://www.agentpmt.com/marketplace/post-on-discord-channel
compatibility: "Agent instructions for AgentPMT-hosted remote tool calls. Follow this skill body for supported account, wallet, and setup routes. No local command runtime is declared."
The skill clearly enables sending content and attachments to Discord via webhooks, but its description and introductory text do not prominently warn that all provided message content, embeds, attachment data, and mention targets are transmitted to a third-party service. This omission increases the risk that an agent or user will route sensitive data externally without informed consent, especially because the tool is designed for outbound messaging.
The skill advertises broad discovery and activation keywords such as generic terms like send, content, and notification phrases, which can cause accidental invocation on unrelated user requests. In a skill that transmits data to an external Discord webhook, overbroad matching increases the chance of unintended disclosure or posting to the wrong destination.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/post-on-discord-channel
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/post-on-discord-channel
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
The schema describes sending messages, embeds, and base64-encoded file attachments to a Discord webhook but does not warn users that all provided content is transmitted to an external third-party service. In agent workflows, this omission can cause users or upstream systems to pass sensitive text, files, or identifiers into the tool without realizing they are leaving the original trust boundary.
No suspicious patterns detected.