notify-discord

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is coherent with its stated purpose: it sends messages to a Discord webhook via curl in Bash, using config-driven webhook_url and dynamic payloads from ARGUMENTS. Moderate security concerns involve storing the webhook URL in a plain config file and potential lack of input validation and error handling. Overall, the risk profile is low-to-moderate and proportionate to a webhook-sender utility, not an attacker-facing capability. Improvements could include secure storage of webhook URLs, input sanitization, and explicit error/retry handling.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 11:52 AM
Package URL
pkg:socket/skills-sh/tanabee%2Fskills%2Fnotify-discord%2F@a37edd22c87c43b283da1637d3396842ab622bbd