discord-reader

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and commands are mostly coherent and read-only, and the npm install appears to be the publisher's official path. However, it requires trusting a third-party CLI to access private Discord data through a local CDP session, instructs enabling remote debugging on the Discord desktop app, and includes load-time pre-execution. These are notable security risks, but there is no clear evidence of credential theft, remote-code execution, or malicious exfiltration.

Confidence: 90%Severity: 56%
Audit Metadata
Analyzed At
Sep 15, 2026, 08:05 AM
Package URL
pkg:socket/skills-sh/himself65%2Ffinance-skills%2Fdiscord-reader%2F@611c031694e2068584e50137185b5e7fff7c3118b7a38d2ebd94bbab68de82bf
Security Audit — socket — discord-reader