discord

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This artifact implements a functional data exfiltration channel: arbitrary text and filesystem files readable by the agent can be posted to an external Discord webhook via a local helper script. By design it exposes sensitive capability (embedded webhook secret + unrestricted file upload). If this behavior is intended and tightly controlled (trusted operator, audited helper, explicit consent, path whitelists), risks can be mitigated. Otherwise treat as high-risk for data leakage and audit or remove the helper, restrict allowed payloads/paths, require explicit confirmations, and avoid embedding webhook secrets in local scripts.

Confidence: 75%Severity: 70%
Audit Metadata
Analyzed At
Feb 16, 2026, 01:03 AM
Package URL
pkg:socket/skills-sh/dtinth%2Fagent-skills%2Fdiscord%2F@3c43ade3c0cc98c3fe740bde02c6c0d0728c29c0