discord-bot-architect
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill implements dynamic loading of code components from local directories to initialize bot commands and events. While this is a standard pattern for the discord.js and py-cord frameworks, it involves executing code from computed file paths at runtime.
- Evidence: In
src/index.js, the script iterates over thecommandsandeventsdirectories usingfs.readdirSyncand imports each file usingrequire(filePath). - Evidence: In
main.py, the script iterates over the./cogsdirectory and usesbot.load_extension(f"cogs.{filename[:-3]}")to dynamically load Python modules. - [INDIRECT_PROMPT_INJECTION]: The skill provides templates for handling user interactions, which introduces a surface where untrusted data from Discord users is ingested into the bot's execution context.
- Ingestion points: The
interactionobject in the JavaScriptpingcommand and thectx/messageoptions in the Pythonmain.pyslash command definitions. - Boundary markers: The templates do not implement explicit delimiters or instructional boundaries to isolate user-supplied strings from the bot's logic.
- Capability inventory: The provided examples are limited to responding within the Discord channel (
interaction.reply,ctx.respond) and do not demonstrate high-risk capabilities such as file system writing or subprocess execution. - Sanitization: No input sanitization or validation logic is present in the boilerplate code for user-supplied strings.
Audit Metadata