access

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [Local State Management]: The skill modifies access control configurations within a local directory (~/.claude/channels/discord/) and does not perform network operations or external API calls, reducing data exfiltration risks.
  • [Proactive Prompt Injection Defense]: The instructions explicitly direct the agent to reject requests originating from external channel notifications, recognizing them as potential vectors for indirect prompt injection and requiring direct user invocation via the terminal instead.
  • [Input Validation and Verification]: The workflow mandates verification codes for pairing operations and defines specific type validations for configuration properties, which helps ensure structural integrity and prevents arbitrary data injection into the state file.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:01 PM
Security Audit — agent-trust-hub — access