discord-expert

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides educational material and code examples for Discord bot development using discord.js and discord.py. No malicious patterns such as credential exfiltration, obfuscation, or remote code execution were detected.
  • [CREDENTIALS_SAFE]: The implementation examples correctly demonstrate the use of .env files and environment variables (process.env.DISCORD_TOKEN, os.getenv('DISCORD_TOKEN')) for managing sensitive API tokens rather than hardcoding them.
  • [EXTERNAL_DOWNLOADS]: The skill references official documentation and community resources from trusted or well-known services, including Discord's official developer portal, official library documentation (discord.js, discord.py), and reputable GitHub repositories.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes examples of bots that process untrusted user input (slash command options and channel messages). While this creates a standard attack surface for the resulting bot, the examples include basic validation and follow platform-standard interaction patterns. This is identified as a characteristic of the primary skill purpose (bot development) and does not indicate a malicious intent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:12 AM
Security Audit — agent-trust-hub — discord-expert