discord-chat

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This document is a behavioral specification for a Discord messaging skill and, by itself, contains no executable code, downloads, or obfuscated payloads. The capabilities align with the stated purpose (sending, searching, and managing Discord messages). The primary risks are operational: (1) the gateway/plugin is a sensitive trust boundary that must protect bot tokens and should be audited, (2) the skill enables high-impact actions (edit/delete/post) that require strict authorization and explicit user confirmation to avoid abuse, and (3) read/search can expose sensitive message history and needs access controls and redaction. No clear signs of malware or supply-chain download-execute patterns are present in the provided text. Recommend ensuring least-privilege bot scopes, logging/auditing of agent-initiated actions, and strict controls on the gateway storage/use of credentials.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:14 AM
Package URL
pkg:socket/skills-sh/ThinkfleetAI%2Fthinkfleet-engine%2Fdiscord-chat%2F@c52652a222a8f3c470a10d001f959d65fd36d718