discord-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides educational material and code examples for Discord bot development using
discord.jsanddiscord.py. No malicious patterns such as credential exfiltration, obfuscation, or remote code execution were detected. - [CREDENTIALS_SAFE]: The implementation examples correctly demonstrate the use of
.envfiles and environment variables (process.env.DISCORD_TOKEN,os.getenv('DISCORD_TOKEN')) for managing sensitive API tokens rather than hardcoding them. - [EXTERNAL_DOWNLOADS]: The skill references official documentation and community resources from trusted or well-known services, including Discord's official developer portal, official library documentation (discord.js, discord.py), and reputable GitHub repositories.
- [INDIRECT_PROMPT_INJECTION]: The skill includes examples of bots that process untrusted user input (slash command options and channel messages). While this creates a standard attack surface for the resulting bot, the examples include basic validation and follow platform-standard interaction patterns. This is identified as a characteristic of the primary skill purpose (bot development) and does not indicate a malicious intent.
Audit Metadata