discord

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the read-only Discord research purpose mostly matches the commands, but the skill relies on a third-party CLI with unclear provenance and instructs the agent to extract and use a raw Discord user token from local sessions. Data flow is plausibly to Discord for legitimate reads, yet the credential handling and local sync/export footprint are more invasive than expected for a simple research skill.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Mar 14, 2026, 07:43 AM
Package URL
pkg:socket/skills-sh/himself65%2Ffinance-skills%2Fdiscord%2F@0835438f983a83b532a206c71d124f23d3b321c5