discord-skill

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This Discord skill's documented behavior is coherent with its purpose: it needs bot tokens or OAuth to send/read/manage messages on Discord. The main security concerns are storage of long-lived credentials in plaintext under ~/.claude/skills/discord-skill/ (tokens and credentials.json) and the optional support for user-account OAuth (which can violate Discord ToS). There are no signs of remote download-execute chains, third-party intermediary endpoints, obfuscated code, or explicit exfiltration instructions. The confirmation requirement before sending messages is a strong mitigation. Overall this appears functionally legitimate but carries moderate supply-chain/credential risk due to plaintext token storage and unpinned dependency guidance.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 27, 2026, 03:22 PM
Package URL
pkg:socket/skills-sh/idanbeck%2Fclaude-skills%2Fdiscord-skill%2F@7ccc85bb45961f6179d0d266978870f6165884c0