discord-bot-architect
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill implements dynamic module loading in both JavaScript and Python environments. In the JavaScript foundation,
require(filePath)is used within a loop to load command and event handlers from constructed file paths. Similarly, the Python implementation usesbot.load_extension()to dynamically load cog files based on directory contents. While standard for plugin-based architectures, this involves executing code from paths computed at runtime. - [INDIRECT_PROMPT_INJECTION]: The skill architecture is designed to ingest and process untrusted data from the Discord platform.
- Ingestion points: User-supplied content enters the context via slash command options (e.g., the
messageargument in thegreetcommand) and interactive component interactions. - Boundary markers: The provided code templates do not implement boundary markers or instructions to delimit user-provided strings from system instructions.
- Capability inventory: The skill possesses the ability to read from the local file system (
fs.readdirSync,os.listdir), execute dynamic code (viarequireandload_extension), and perform network operations through the Discord API. - Sanitization: The examples do not include logic for sanitizing or validating user-provided input before it is processed or used in responses.
Audit Metadata