Back to skill

Security audit

Discord Thread Naming Backstop Workflow

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrowly scoped Discord thread-renaming backstop with disclosed write actions and no hidden code or persistence.

Install this only if you want an agent with Discord permissions to read the specified dispatch channel, rename a small number of recent thread titles, and post limited failure or recovery notices. For informal requests, require confirmation of the guild/channel and scope before allowing renames.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description explicitly says it should trigger even when the user does not mention 'backstop' as long as the intent seems like low-disturbance correction of new thread titles. That broad activation rule can cause the agent to invoke a renaming workflow on ambiguous requests, increasing the chance of unintended modifications to Discord resources.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instructions require treating current time as Asia/Shanghai and repeatedly use that timezone for operational decisions. This is a locale constraint expressed in natural language, but the file does not offer user opt-in or explain that the skill is region-specific in a way that would justify the fixed locale under the policy.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This eval explicitly rewards triggering the workflow from loosely phrased intent such as '处理下 dispatch 里刚创建的几个 thread 标题' and says the agent should infer backstop behavior even when the user does not say 'backstop'. That broad activation contract can cause unintended execution of thread-list and channel-edit operations from casual cleanup requests, increasing the risk of unauthorized or over-broad modifications in Discord.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This prompt allows activation from casual wording like '顺手把 Discord 里 dispatch 的线程标题收一收' and expects the model to interpret that as a backstop rename workflow. In a skill that can rename channels/threads, ambiguous trigger language is dangerous because it normalizes action on vague user intent and can lead to accidental renames or misuse when the requested scope is not explicitly confirmed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.