Back to skill

Security audit

discord-memory

Security checks across malware telemetry and agentic risk

Overview

This skill does what it claims, but it sends Discord-derived summaries to an external persistent memory service without clear consent, scoping, deletion, or sensitive-data limits.

Review this skill carefully before installing. It may be appropriate for a Discord bot where users and moderators have agreed that channel summaries can be stored in BlueColumn, but avoid using it for private messages, moderation discussions, credentials, personal data, or confidential project information unless you add explicit approval, redaction, retention, and deletion controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly directs agents to persist Discord conversation content to an external service but does not require any user notice, consent, or data-minimization step before storage. This creates a real privacy and compliance risk because agents may upload personal, sensitive, or server-confidential content to third-party persistent memory without the user's awareness.

Ssd 3

Medium
Confidence
91% confidence
Finding
The workflow tells the agent to recall prior community issues and then store a summary after each interaction, enabling ongoing retention and reuse of Discord-derived content across sessions without boundaries on sensitive data. In the Discord context, this is particularly risky because conversations often contain personal details, private moderation context, internal project information, or credentials that should not be propagated into long-lived external memory.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.