ops-discord

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface (Category 8) because it ingests data from external Discord messages and processes it through other system components.
  • Ingestion points: The on_message event handler in discord_ops/webhook_monitor.py reads message content from any user in the monitored Discord guilds.
  • Boundary markers: Absent. Content is passed directly into JSON payloads or as command-line arguments to other skills without delimiters or instructions to ignore embedded commands.
  • Capability inventory: The skill can execute local scripts via subprocess.run (calling the memory skill in discord_ops/graph_persistence.py) and perform network POST requests to user-defined webhooks via httpx.
  • Sanitization: Sanitization is limited to length truncation; the skill does not filter or escape potentially malicious instructions within the message body.
  • [COMMAND_EXECUTION]: The skill interacts with a local memory skill by executing its run.sh script using subprocess.run in discord_ops/graph_persistence.py. It follows security best practices by passing arguments as a list rather than a shell string, but the arguments themselves include raw data from external Discord messages.
  • [EXTERNAL_DOWNLOADS]: The skill's run.sh script utilizes the uv package manager to install and run the Python environment defined in pyproject.toml. This involves downloading standard, well-known libraries such as discord.py and httpx from official package registries.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — ops-discord