Back to skill

Security audit

Discord Chat Manager Free

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a Discord chat manager, but its trigger instructions point to unrelated SEO tasks while it can read, post, edit, and delete Discord messages.

Review this before installing. Use it only for Discord chat workflows, correct the SEO trigger text, configure the bot with the minimum Discord permissions needed, keep the bot token in a secret manager or environment variable, and require explicit confirmation before editing or deleting messages or searching private history.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The trigger condition says to use this skill for SEO optimization, keyword analysis, and search traffic improvement, which is unrelated to Discord chat management. This mismatch can cause the agent to invoke the skill in inappropriate contexts, increasing the chance of unintended Discord reads/writes or confused tool routing.

Vague Triggers

High
Confidence
97% confidence
Finding
An unrelated and overly broad trigger condition can cause the agent to activate a Discord-capable skill for requests about SEO or keyword analysis. Because the skill can read history, send, edit, and delete messages, incorrect activation materially raises the risk of unauthorized actions or data exposure in Discord environments.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill advertises edit and delete capabilities without warning that these actions are destructive and may alter records, erase context, or affect other users' content if the bot has elevated permissions. In agent-driven workflows, omission of such warnings increases the chance of accidental irreversible changes.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill supports reading and searching Discord message history but provides no privacy warning about accessing potentially sensitive conversations, personal data, or internal team information. This can normalize broad history access and increase the risk of unnecessary data exposure through summaries, search results, or accidental disclosure.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The documentation tells users to configure a Discord Bot Token but does not warn that the token is a sensitive secret that must never be exposed in prompts, logs, screenshots, or committed files. If leaked, an attacker could use the bot's permissions to read channels, send messages, react, edit, delete, or otherwise abuse the connected Discord server.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.