Back to skill

Security audit

Discord社区管理

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a disclosed Discord management helper, but its invocation metadata is inconsistent and asks for broader local tool authority than its Discord OAuth workflow appears to need.

Review this skill before installing. It should only be used for Discord OAuth and community-management workflows, and any agent using it should ignore the database/SQL invocation text. Confirm that local read/write/exec authority is acceptable in your environment, and require explicit confirmation for guild-leave, entitlement deletion/consumption, profile changes, and role-connection updates.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill metadata describes a Discord community management assistant, but the description also instructs use for unrelated database, SQL, and data storage tasks. This scope confusion can cause an agent to invoke the skill in inappropriate contexts and grant it access or trust beyond its actual capability boundaries, increasing the chance of unsafe tool use or data mishandling.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The document claims the skill is focused on identity and permission management, yet it also supports entitlement consumption/deletion and guild-leave operations, which are destructive or account-affecting actions outside that narrow stated focus. This mismatch can mislead users or orchestrators into underestimating the risk profile of the skill and approving higher-impact actions without appropriate scrutiny.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation guidance is overly broad and ambiguous, including generic language about when to use the skill that does not map cleanly to its Discord-only functionality. Ambiguous routing criteria can cause accidental invocation in unrelated tasks, leading to unnecessary exposure of OAuth-linked data or execution of inappropriate actions.

Natural-Language Policy Violations

Medium
Confidence
75% confidence
Finding
The text states support for Chinese interaction in a way that can be interpreted as a default or required interaction mode without explicit user opt-in. While not directly a security flaw by itself, forced language behavior can confuse users, reduce transparency, and increase the chance that consent prompts or high-impact confirmations are misunderstood.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.