Back to skill

Security audit

Discord Chat 基础

Security checks across malware telemetry and agentic risk

Overview

This markdown-only skill gives an agent basic Discord message actions that match its stated purpose, with no hidden install code or persistence.

Install only if you intend the agent to read and post in approved Discord channels through your configured bot. Avoid using callback URLs unless they are trusted, and do not point the skill at private channels whose contents should not be shared with the agent or external services.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly supports reading Discord history, sending messages, and accepting a callback URL, but it does not clearly warn users that conversation content may be transmitted to external systems or persisted outside Discord. This can lead to unintended disclosure of private channel content, user messages, metadata, or sensitive operational information when an operator assumes the skill is only performing local formatting or benign chat actions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.