Back to skill

Security audit

Discord Community Hub Free

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a disclosed Discord read-only helper, but its broad activation wording and generic write-like instructions could steer an agent into a credentialed Discord integration outside the stated free read-only scope.

Install only if you intend to connect a Discord account through the named integration gateway for read-only account and server lookups. Review the OAuth scopes, avoid granting write scopes for this free skill, and do not rely on it for generic webhook, API integration, or Discord administration/write workflows.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill is presented as a low-risk, read-only Discord query tool, but these sections introduce generic create/modify/reset/import/save/export semantics that exceed the declared scope. This can cause an agent to over-trust the skill and invoke broader operations than the user intended, especially in systems that infer capability from documentation rather than enforce a strict tool allowlist.

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The documentation contains contradictory statements about whether command-permission editing is supported, which can mislead an agent or operator into attempting privileged write actions. In a credentialed integration context, ambiguity around write capability increases the risk of unauthorized or unintended state-changing operations.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger condition is overly broad, effectively telling agents to use this skill for generic API integration, interface connection, webhook, or system-connection tasks. That increases the chance of misrouting unrelated user requests into a Discord-connected skill, potentially exposing Discord account data or causing unnecessary OAuth/integration actions.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The capability coverage is defined with a long, broad keyword list instead of precise activation phrases and boundaries. In agent environments that select skills from descriptive text, this can cause prompt/skill hijacking by matching unrelated community-management or integration queries and steering them into a Discord credentialed context.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.