Back to skill

Security audit

Discord语音工具免费版

Security checks across malware telemetry and agentic risk

Overview

This Discord voice skill is mostly coherent, but it requests command execution for live voice-channel listening while its trigger guidance is too broad and its privacy controls are under-disclosed.

Review before installing. Use this only for explicitly requested Discord voice-channel interactions, configure allowedUsers for any shared server, confirm participants know the bot listens and transcribes speech, and verify the repository source before running the npm/system install steps.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
78% confidence
Finding
The trigger condition is excessively broad and could cause the agent to invoke this skill for generic AI/LLM tasks unrelated to Discord voice. In context, this skill has exec/read/write capability and handles live voice-channel interactions, so over-triggering increases the chance of unnecessary command execution, unintended channel joins, and speech capture in situations where the user did not specifically request Discord voice actions.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill description does not prominently warn that it captures and processes speech from voice channels, potentially including bystanders or other participants who did not directly invoke the tool. Because the skill is designed for real-time channel participation, insufficient disclosure can lead to covert or unintended collection of sensitive voice content and privacy violations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.