ops-discord
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface (Category 8) because it ingests data from external Discord messages and processes it through other system components.
- Ingestion points: The
on_messageevent handler indiscord_ops/webhook_monitor.pyreads message content from any user in the monitored Discord guilds. - Boundary markers: Absent. Content is passed directly into JSON payloads or as command-line arguments to other skills without delimiters or instructions to ignore embedded commands.
- Capability inventory: The skill can execute local scripts via
subprocess.run(calling thememoryskill indiscord_ops/graph_persistence.py) and perform network POST requests to user-defined webhooks viahttpx. - Sanitization: Sanitization is limited to length truncation; the skill does not filter or escape potentially malicious instructions within the message body.
- [COMMAND_EXECUTION]: The skill interacts with a local
memoryskill by executing itsrun.shscript usingsubprocess.runindiscord_ops/graph_persistence.py. It follows security best practices by passing arguments as a list rather than a shell string, but the arguments themselves include raw data from external Discord messages. - [EXTERNAL_DOWNLOADS]: The skill's
run.shscript utilizes theuvpackage manager to install and run the Python environment defined inpyproject.toml. This involves downloading standard, well-known libraries such asdiscord.pyandhttpxfrom official package registries.
Audit Metadata