spoonos-platform-integration

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
scripts/discord_bot.py

The code is not overtly malicious (no obfuscation, backdoor, or arbitrary code execution). The critical security concern is privacy/exfiltration: user-supplied content (including secrets) is forwarded verbatim to an external LLM provider via agent.run, and responses are posted back to Discord. The 'analyze' command explicitly solicits a 'token', which is a high-risk pattern that can result in credential leakage. Treat this module as risky for environments where secrets or PII may be present; apply input redaction, access controls, and limit the bot's permissions and exposure before deploying.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 07:35 PM
Package URL
pkg:socket/skills-sh/XSpoonAi%2Fspoon-awesome-skill%2Fspoonos-platform-integration%2F@62058730a2a6353e7e98e83747c911735349cf20