Back to skill

Security audit

Discord

Security checks across malware telemetry and agentic risk

Overview

This Discord skill is transparent about broad bot controls, but it lacks clear safeguards for message deletion, searches, public posting, local file uploads, and admin-style actions.

Install only for a Discord bot and servers where you are comfortable letting an agent post, read/search accessible messages, upload files, and manage content. Keep role and moderation action groups disabled unless needed, limit enabled action groups, and require clear confirmation before deleting messages, changing roles, moderating users, searching sensitive channels, or uploading any local file path.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill exposes destructive actions such as deleteMessage plus user-impacting moderation actions like timeout and roleAdd, but does not pair them with explicit safety guidance, confirmation requirements, or user-visible warnings about consequences. In an agent setting, this increases the chance of accidental message deletion, improper moderation, or unauthorized changes when a prompt is ambiguous or manipulated.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.