Back to skill

Security audit

Discord工具箱专业版

Security checks across malware telemetry and agentic risk

Overview

This Discord administration skill discloses powerful moderation features, but its scope and local tool permissions are broad and internally inconsistent enough to require user review before installation.

Install only if you intend to give an agent Discord bot authority for server administration. Confirm the bot has the minimum necessary Discord permissions, keep moderation and role actions disabled until needed, require confirmation for bans, deletions, and role changes, and review the local audit log path and retention before use. Avoid using this skill for general file processing or shell automation despite its generic wording.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The documented request/response schema describes a generic scoring or audit workflow rather than Discord administration actions, creating a capability mismatch between what the skill claims to do and how it is invoked. This can cause an agent or user to supply unintended inputs, mis-handle outputs, or route sensitive moderation tasks through the wrong execution path, increasing the chance of unsafe or unauthorized actions.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The '主要功能' section expands the skill from Discord management into generic file processing and command execution, which is a risky overclaim when the skill also advertises read/write/exec tool access. Broad capability claims can prompt an agent to use local filesystem or shell operations unrelated to Discord, materially increasing the attack surface for destructive commands, data exposure, or abuse of host resources.

Vague Triggers

High
Confidence
93% confidence
Finding
The activation language is so broad that it may trigger on generic productivity or automation requests far outside Discord administration. In a skill with write and exec permissions plus high-impact moderation features, overbroad matching increases the risk of accidental invocation, confused-deputy behavior, and unauthorized side effects on local systems or external services.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill documents writing audit logs to local files but does not clearly warn users about persistent local storage, retention, possible inclusion of user identifiers, or disk impact. Because this skill handles moderation and role operations, those logs may contain sensitive operational metadata whose silent retention can create privacy, compliance, or forensic exposure risks.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.