discord-integration

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The stated Discord purpose matches the capabilities, and network traffic goes to official Discord endpoints, which is a positive sign. However, the skill exposes exact secret file locations, instructs direct credential-file access, and routes those credentials through local unverifiable scripts/MCP code. That makes the footprint disproportionately risky for an agent skill even without evidence of confirmed exfiltration.

Confidence: 88%Severity: 84%
Audit Metadata
Analyzed At
Apr 19, 2026, 05:25 PM
Package URL
pkg:socket/skills-sh/nice-wolf-studio%2Fwolf-skills-marketplace%2Fdiscord-integration%2F@d14e7ae1c9433aff3adb4681a6cd31290d03b53c