Security audit
Discrawl
Security checks across malware telemetry and agentic risk
Overview
Discrawl asks for sensitive Discord archive access, but the access is disclosed, purpose-aligned, and bounded by clear safety guidance.
Install only if you intentionally want an agent to search local Discord archives and possibly DMs. Use least-privilege bot credentials, do not provide Discord user tokens, keep SQL read-only unless you deliberately approve a reviewed mutation, and treat exported snapshots as private because they may contain sensitive conversations.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
65/65 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
