agent-discordbot

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

BENIGN with notable operational risk. The skill's capabilities are largely aligned with its stated Discord bot purpose, and credential/data flows are proportionate, but it grants an agent the ability to publicly act on Discord, upload files, and process untrusted Discord content while using Bash and on-demand package execution. Main concerns are autonomy/public-action risk, exfiltration potential, and moderate npm supply-chain trust, not clear malicious behavior.

Confidence: 82%Severity: 68%
Audit Metadata
Analyzed At
May 8, 2026, 05:17 AM
Package URL
pkg:socket/skills-sh/devxoul%2Fagent-messenger%2Fagent-discordbot%2F@bf3ce66fef8f447a39296a44f76d624c41787cc9