discord
Fail
Audited by Gen Agent Trust Hub on Mar 14, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill uses the
discord auth --savecommand to automatically extract Discord authentication tokens from the local filesystem or browser processes. This targets sensitive session data stored by the Discord desktop application and web browsers to facilitate access. - [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the
kabi-discord-clipackage from a public registry. This external dependency is responsible for performing sensitive operations, including the extraction of user credentials and interaction with the Discord API. - [COMMAND_EXECUTION]: The skill relies on executing the
discordCLI utility with various arguments to manage local data synchronization and query external APIs, which provides the agent with broad execution capabilities on the host system. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection by processing untrusted content from Discord messages.
- Ingestion points: Message history, search results, and recent activity retrieved via the
discordtool as described inSKILL.md. - Boundary markers: No delimiters or warnings are used to distinguish message content from agent instructions.
- Capability inventory: The agent can execute shell commands using the
discordCLI as outlined inreferences/commands.md. - Sanitization: No sanitization, escaping, or filtering of external message content is mentioned prior to processing or presentation.
Recommendations
- AI detected serious security threats
Audit Metadata