agent-discord

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The messaging capabilities fit the stated purpose, but the skill's main auth model—silent extraction of Discord user tokens from desktop/browser storage—is disproportionate and high-risk. It also enables autonomous posting and file uploads on behalf of the user. Install path looks more like ordinary npm distribution than malware, but the credential-harvesting-style auth flow and broad account access make this skill risky.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
May 8, 2026, 05:17 AM
Package URL
pkg:socket/skills-sh/devxoul%2Fagent-messenger%2Fagent-discord%2F@6d785efba49908a0424d6c4ea5b4b262326e32f3