discord
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the read-only Discord research purpose mostly matches the commands, but the skill relies on a third-party CLI with unclear provenance and instructs the agent to extract and use a raw Discord user token from local sessions. Data flow is plausibly to Discord for legitimate reads, yet the credential handling and local sync/export footprint are more invasive than expected for a simple research skill.
Confidence: 84%Severity: 68%
Audit Metadata