Back to skill

Security audit

Discord

Security checks for vulnerabilities and agentic risk

Overview

This Discord skill is a transparent command guide for an existing Discord bot tool, but users should be careful because it can read, post, delete, and upload content in Discord.

Install only where the Clawdbot Discord permissions match your intended use. Consider disabling unneeded action groups, especially messages, search, uploads, roles, and moderation, and require explicit operator review before deleting messages, moderating users, sending DMs, or uploading local files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly supports reading/searching Discord content and sending, editing, or deleting messages, but it does not warn users that these actions may access private conversations or modify live community content. That omission can lead operators to invoke sensitive actions without informed consent, increasing the chance of privacy violations or unintended destructive changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents uploading local files via file:// paths and remote media URLs without warning that the referenced content will be transmitted to Discord. This creates a real risk of accidental exfiltration of sensitive local files or unreviewed remote content, particularly because operators may treat file paths as harmless references rather than outbound data transfer.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.