discord
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides Python scripts and shell recipes to interact with the Discord API. These scripts use environment variables for authentication and perform network operations to send messages.
- [EXTERNAL_DOWNLOADS]: The bundled Python scripts depend on the
requestslibrary for HTTP communication. All network requests target official Discord API endpoints (discord.com), which is a well-known and expected service for this skill's functionality. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied data to generate message content for Discord.
- Ingestion points: Message content is ingested from the
--contentCLI argument orsys.stdininpost_webhook.pyandsend_message.py. - Boundary markers: The content is interpolated directly into a JSON payload without specific delimiters.
- Capability inventory: The skill can perform network POST requests to Discord servers.
- Sanitization: The skill uses standard JSON encoding for payloads and defaults to a strict
allowed_mentionspolicy ({"parse": []}) to prevent accidental or malicious mass pings (e.g., @everyone).
Audit Metadata