discord-clawd
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose matches a messaging relay, and the static command-injection hit is benign documentation text. The main concern is trust: the skill asks the agent to run a local relay helper from a personal `agent-scripts` path, with no verified same-org provenance, while that helper may consume gateway tokens and perform remote posting. That footprint is somewhat aligned with a relay skill but exceeds low-risk expectations because credentials and outbound actions are delegated to an unverified external helper.
Confidence: 87%Severity: 78%
Audit Metadata