agent-discord

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The install source appears legitimate and proportionate, but the skill’s auth model relies on silent extraction of a Discord user token from the desktop app and grants an agent broad messaging/read/upload capabilities. Data flows appear to Discord rather than an unknown proxy, so this is not confirmed malware, but it is a high-sensitivity communication skill with notable credential and autonomy risk.

Confidence: 85%Severity: 68%
Audit Metadata
Analyzed At
Mar 18, 2026, 02:42 AM
Package URL
pkg:socket/skills-sh/devxoul%2Fagent-messenger%2Fagent-discord%2F@7ad4d35bca67f432ffaf0ae1779fdaf4ce426068