discord-harvest

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose matches its scraping and download behavior, but its footprint is still high-risk for an agent skill. Main concerns are transitive skill installation, processing untrusted Discord/browser content with write/exec capability, and bulk harvesting of private conversation artifacts. Controls like CDN allowlisting and filename sanitization help, but they do not remove the broader trust and prompt-injection risks.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Apr 20, 2026, 03:45 AM
Package URL
pkg:socket/skills-sh/t4sh%2Fskills4sh%2Fdiscord-harvest%2F@a2669db47e4794c5ac5f65eea1c6db987eebeb5a