{"data":{"skill":{"slug":"sickn33-discord-automation","name":"discord-automation","icon":"📦","repo":"https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/discord-automation","status":"approved","author":"sickn33","authorVersion":null,"skillstoreRevision":2},"audit":{"id":"39df3397-6f8c-42ae-a113-4e9c1807d888","skill_id":"29d7a09c-ddff-4d0e-b9f5-deb7c61bdab1","version":5,"content_hash":"v3:f9e2c34b4f19c7f3e6b0a1e93227b5f77cc12526:661ba10d34357a838ed62f2f909bbd097cae168356d4cd7683fe8fb6411b36ac:4af5b29e672a558ec5be24d1fc75203debac33a1342bc950ffc412c6f5341dd5:736b696c6c732f7369636b6e33332f646973636f72642d6175746f6d6174696f6e:c8ed466b5d15d6b8db1bf68e1b3c29a3","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"The 50 command-execution alerts and 11 reconnaissance alerts are false positives caused by Markdown tool names and Discord reference rows. The external Rube MCP endpoint is a real low-severity network dependency, while authorized messaging and administration workflows create contextual medium-severity risks.","remediation":[{"issue":"External MCP authorization boundary","severity":"medium","suggestion":"Document what Discord data and actions Rube MCP can access before users approve an OAuth or bot connection."},{"issue":"Privileged Discord administration workflows","severity":"medium","suggestion":"Require explicit confirmation before role changes, member updates, webhook changes, reaction deletion, or other broad server actions."},{"issue":"Automated message and webhook sending","severity":"medium","suggestion":"Preview content and confirm recipients before sending direct messages, channel posts, or webhook messages."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":16,"line_start":16},{"file":"SKILL.md","line_end":17,"line_start":17},{"file":"SKILL.md","line_end":21,"line_start":21},{"file":"SKILL.md","line_end":23,"line_start":23},{"file":"SKILL.md","line_end":24,"line_start":24},{"file":"SKILL.md","line_end":35,"line_start":35},{"file":"SKILL.md","line_end":36,"line_start":36},{"file":"SKILL.md","line_end":37,"line_start":37},{"file":"SKILL.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":44,"line_start":44},{"file":"SKILL.md","line_end":56,"line_start":56},{"file":"SKILL.md","line_end":57,"line_start":57},{"file":"SKILL.md","line_end":60,"line_start":60},{"file":"SKILL.md","line_end":61,"line_start":61},{"file":"SKILL.md","line_end":72,"line_start":72},{"file":"SKILL.md","line_end":73,"line_start":73},{"file":"SKILL.md","line_end":74,"line_start":74},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":76,"line_start":76},{"file":"SKILL.md","line_end":79,"line_start":79},{"file":"SKILL.md","line_end":80,"line_start":80},{"file":"SKILL.md","line_end":81,"line_start":81},{"file":"SKILL.md","line_end":82,"line_start":82},{"file":"SKILL.md","line_end":83,"line_start":83},{"file":"SKILL.md","line_end":84,"line_start":84},{"file":"SKILL.md","line_end":96,"line_start":96},{"file":"SKILL.md","line_end":97,"line_start":97},{"file":"SKILL.md","line_end":98,"line_start":98},{"file":"SKILL.md","line_end":99,"line_start":99},{"file":"SKILL.md","line_end":102,"line_start":102},{"file":"SKILL.md","line_end":103,"line_start":103},{"file":"SKILL.md","line_end":104,"line_start":104},{"file":"SKILL.md","line_end":105,"line_start":105},{"file":"SKILL.md","line_end":106,"line_start":106},{"file":"SKILL.md","line_end":118,"line_start":118},{"file":"SKILL.md","line_end":119,"line_start":119},{"file":"SKILL.md","line_end":120,"line_start":120},{"file":"SKILL.md","line_end":121,"line_start":121},{"file":"SKILL.md","line_end":124,"line_start":124},{"file":"SKILL.md","line_end":125,"line_start":125},{"file":"SKILL.md","line_end":126,"line_start":126},{"file":"SKILL.md","line_end":127,"line_start":127},{"file":"SKILL.md","line_end":131,"line_start":131},{"file":"SKILL.md","line_end":151,"line_start":151},{"file":"SKILL.md","line_end":153,"line_start":153},{"file":"SKILL.md","line_end":158,"line_start":158},{"file":"SKILL.md","line_end":163,"line_start":163}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":21,"line_start":21}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Privileged Discord Administration Actions","locations":[{"file":"SKILL.md","line_end":89,"line_start":67},{"file":"SKILL.md","line_end":132,"line_start":91}],"confidence":0.95,"description":"The skill guides role creation, assignment, deletion, member updates, webhook management, and reaction deletion. These actions can alter server access or content.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The cited workflows explicitly include destructive and access-changing actions with Discord permission requirements. Their impact depends on the connected bot authority."},{"title":"Automated Messaging Abuse Potential","locations":[{"file":"SKILL.md","line_end":65,"line_start":30},{"file":"SKILL.md","line_end":110,"line_start":91}],"confidence":0.92,"description":"The skill supports channel messages, direct messages, and webhook messages with custom sender presentation. These features can send unwanted or misleading communications.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The cited sections explicitly document channel messages, direct messages, webhook execution, and custom webhook identity. Abuse remains constrained by Discord permissions."},{"title":"Third-Party MCP Authorization Boundary","locations":[{"file":"SKILL.md","line_end":26,"line_start":21},{"file":"SKILL.md","line_end":159,"line_start":157}],"confidence":0.9,"description":"Users must add the Rube MCP endpoint and authorize Discord through a returned link. The service receives delegated access for the connected account or bot.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The setup explicitly requires an external MCP endpoint and Discord authorization, while the token section identifies bot-token and user-OAuth modes."}],"low_findings":[{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":21,"line_start":21}],"confidence":0.9,"description":"**Get Rube MCP**: Add `https://rube.app/mcp` as an MCP server in your client configuration. No API k","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The skill instructs users to connect to https://rube.app/mcp, creating a real external network and service trust boundary. The endpoint is intentional and clearly disclosed."}],"dangerous_patterns":[],"files_scanned":1,"total_lines":196,"audit_model":"codex","audited_at":"2026-07-23T22:17:12.081+00:00","created_at":"2026-07-26T09:23:34.284926+00:00","static_findings":[{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Active Discord connection via `RUBE_MANAGE_CONNECTIONS` with toolkits `discord` and `discordbot`","category":"external_commands","line_end":16,"severity":"medium","line_start":16},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Always call `RUBE_SEARCH_TOOLS` first to get current tool schemas","category":"external_commands","line_end":17,"severity":"medium","line_start":17},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**Get Rube MCP**: Add `https://rube.app/mcp` as an MCP server in your client configuration. No API k","category":"external_commands","line_end":21,"severity":"medium","line_start":21},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Verify Rube MCP is available by confirming `RUBE_SEARCH_TOOLS` responds","category":"external_commands","line_end":23,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Call `RUBE_MANAGE_CONNECTIONS` with toolkit `discordbot` (bot operations) or `discord` (user oper","category":"external_commands","line_end":24,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `DISCORD_LIST_MY_GUILDS` - List guilds the bot belongs to [Prerequisite]","category":"external_commands","line_end":35,"severity":"medium","line_start":35},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. `DISCORDBOT_LIST_GUILD_CHANNELS` - List channels in a guild [Prerequisite]","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. `DISCORDBOT_CREATE_MESSAGE` - Send a message [Required]","category":"external_commands","line_end":37,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. `DISCORDBOT_UPDATE_MESSAGE` - Edit a sent message [Optional]","category":"external_commands","line_end":38,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `channel_id`: Channel snowflake ID","category":"external_commands","line_end":41,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `content`: Message text (max 2000 characters)","category":"external_commands","line_end":42,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `embeds`: Array of embed objects for rich content","category":"external_commands","line_end":43,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `guild_id`: Guild ID for channel listing","category":"external_commands","line_end":44,"severity":"medium","line_start":44},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `DISCORDBOT_CREATE_DM` - Create or get DM channel [Required]","category":"external_commands","line_end":56,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. `DISCORDBOT_CREATE_MESSAGE` - Send message to DM channel [Required]","category":"external_commands","line_end":57,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `recipient_id`: User snowflake ID for DM","category":"external_commands","line_end":60,"severity":"medium","line_start":60},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `channel_id`: DM channel ID from CREATE_DM","category":"external_commands","line_end":61,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `DISCORDBOT_CREATE_GUILD_ROLE` - Create a new role [Optional]","category":"external_commands","line_end":72,"severity":"medium","line_start":72},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. `DISCORDBOT_ADD_GUILD_MEMBER_ROLE` - Assign role to member [Optional]","category":"external_commands","line_end":73,"severity":"medium","line_start":73},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. `DISCORDBOT_DELETE_GUILD_ROLE` - Delete a role [Optional]","category":"external_commands","line_end":74,"severity":"medium","line_start":74},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. `DISCORDBOT_GET_GUILD_MEMBER` - Get member details [Optional]","category":"external_commands","line_end":75,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. `DISCORDBOT_UPDATE_GUILD_MEMBER` - Update member (roles, nick, etc.) [Optional]","category":"external_commands","line_end":76,"severity":"medium","line_start":76},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `guild_id`: Guild snowflake ID","category":"external_commands","line_end":79,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `user_id`: User snowflake ID","category":"external_commands","line_end":80,"severity":"medium","line_start":80},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `role_id`: Role snowflake ID","category":"external_commands","line_end":81,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `name`: Role name","category":"external_commands","line_end":82,"severity":"medium","line_start":82},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `permissions`: Bitwise permission value","category":"external_commands","line_end":83,"severity":"medium","line_start":83},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `color`: RGB color integer","category":"external_commands","line_end":84,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `DISCORDBOT_GET_GUILD_WEBHOOKS` / `DISCORDBOT_LIST_CHANNEL_WEBHOOKS` - List webhooks [Optional]","category":"external_commands","line_end":96,"severity":"medium","line_start":96},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. `DISCORDBOT_CREATE_WEBHOOK` - Create a new webhook [Optional]","category":"external_commands","line_end":97,"severity":"medium","line_start":97},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. `DISCORDBOT_EXECUTE_WEBHOOK` - Send message via webhook [Optional]","category":"external_commands","line_end":98,"severity":"medium","line_start":98},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. `DISCORDBOT_UPDATE_WEBHOOK` - Update webhook settings [Optional]","category":"external_commands","line_end":99,"severity":"medium","line_start":99},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `webhook_id`: Webhook ID","category":"external_commands","line_end":102,"severity":"medium","line_start":102},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `webhook_token`: Webhook secret token","category":"external_commands","line_end":103,"severity":"medium","line_start":103},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `channel_id`: Channel for webhook creation","category":"external_commands","line_end":104,"severity":"medium","line_start":104},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `name`: Webhook name","category":"external_commands","line_end":105,"severity":"medium","line_start":105},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `content`/`embeds`: Message content for execution","category":"external_commands","line_end":106,"severity":"medium","line_start":106},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `DISCORDBOT_LIST_MESSAGE_REACTIONS_BY_EMOJI` - List users who reacted [Optional]","category":"external_commands","line_end":118,"severity":"medium","line_start":118},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. `DISCORDBOT_DELETE_ALL_MESSAGE_REACTIONS` - Remove all reactions [Optional]","category":"external_commands","line_end":119,"severity":"medium","line_start":119},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. `DISCORDBOT_DELETE_ALL_MESSAGE_REACTIONS_BY_EMOJI` - Remove specific emoji reactions [Optional]","category":"external_commands","line_end":120,"severity":"medium","line_start":120},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. `DISCORDBOT_DELETE_USER_MESSAGE_REACTION` - Remove specific user's reaction [Optional]","category":"external_commands","line_end":121,"severity":"medium","line_start":121},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `channel_id`: Channel ID","category":"external_commands","line_end":124,"severity":"medium","line_start":124},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `message_id`: Message snowflake ID","category":"external_commands","line_end":125,"severity":"medium","line_start":125},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `emoji_name`: URL-encoded emoji or `name:id` for custom emojis","category":"external_commands","line_end":126,"severity":"medium","line_start":126},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `user_id`: User ID for specific reaction removal","category":"external_commands","line_end":127,"severity":"medium","line_start":127},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Custom emojis use `name:id` format","category":"external_commands","line_end":131,"severity":"medium","line_start":131},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Most list endpoints support `limit`, `before`, `after` parameters","category":"external_commands","line_end":151,"severity":"medium","line_start":151},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Reactions: max 100 per request, use `after` for pagination","category":"external_commands","line_end":153,"severity":"medium","line_start":153},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `discordbot` toolkit uses bot tokens; `discord` uses user OAuth","category":"external_commands","line_end":158,"severity":"medium","line_start":158},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Respect `Retry-After` headers on 429 responses","category":"external_commands","line_end":163,"severity":"medium","line_start":163},{"id":"network:SKILL.md:21:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"**Get Rube MCP**: Add `https://rube.app/mcp` as an MCP server in your client configuration. No API k","category":"network","line_end":21,"severity":"low","line_start":21},{"id":"blocker:SKILL.md:170:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| List channels | DISCORDBOT_LIST_GUILD_CHANNELS | guild_id |","category":"blocker","line_end":170,"severity":"low","line_start":170},{"id":"blocker:SKILL.md:172:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| Edit message | DISCORDBOT_UPDATE_MESSAGE | channel_id, message_id |","category":"blocker","line_end":172,"severity":"low","line_start":172},{"id":"blocker:SKILL.md:174:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| Create DM | DISCORDBOT_CREATE_DM | recipient_id |","category":"blocker","line_end":174,"severity":"low","line_start":174},{"id":"blocker:SKILL.md:176:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| Assign role | DISCORDBOT_ADD_GUILD_MEMBER_ROLE | guild_id, user_id, role_id |","category":"blocker","line_end":176,"severity":"low","line_start":176},{"id":"blocker:SKILL.md:177:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| Delete role | DISCORDBOT_DELETE_GUILD_ROLE | guild_id, role_id |","category":"blocker","line_end":177,"severity":"low","line_start":177},{"id":"blocker:SKILL.md:178:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| Get member | DISCORDBOT_GET_GUILD_MEMBER | guild_id, user_id |","category":"blocker","line_end":178,"severity":"low","line_start":178},{"id":"blocker:SKILL.md:179:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| Update member | DISCORDBOT_UPDATE_GUILD_MEMBER | guild_id, user_id |","category":"blocker","line_end":179,"severity":"low","line_start":179},{"id":"blocker:SKILL.md:180:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| Get guild | DISCORDBOT_GET_GUILD | guild_id |","category":"blocker","line_end":180,"severity":"low","line_start":180},{"id":"blocker:SKILL.md:183:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| List webhooks | DISCORDBOT_GET_GUILD_WEBHOOKS | guild_id |","category":"blocker","line_end":183,"severity":"low","line_start":183},{"id":"blocker:SKILL.md:185:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| Clear reactions | DISCORDBOT_DELETE_ALL_MESSAGE_REACTIONS | channel_id, message_id |","category":"blocker","line_end":185,"severity":"low","line_start":185},{"id":"blocker:SKILL.md:187:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| Get channel | DISCORDBOT_GET_CHANNEL | channel_id |","category":"blocker","line_end":187,"severity":"low","line_start":187}],"finding_verdicts":[{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","reason":"This line uses Markdown backticks around Rube MCP toolkit names. It contains no Ruby, shell, or executable command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","reason":"This line uses Markdown backticks around a Rube MCP tool name. It contains no Ruby, shell, or executable command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","reason":"The backticks format an HTTPS endpoint as inline Markdown. The line configures an MCP service but does not execute Ruby or shell code.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"This line formats a Rube MCP tool name as inline Markdown. It contains no command-execution syntax.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"The backticks identify MCP toolkits and a tool call in documentation. They are not Ruby or shell execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","reason":"The backticks mark a Discord MCP tool identifier in a documented sequence. No local command is executed.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"The backticks mark a Discord MCP tool identifier in a documented sequence. No local command is executed.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"The backticks mark a Discord MCP tool identifier in a documented sequence. No local command is executed.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"The backticks mark a Discord MCP tool identifier in a documented sequence. No local command is executed.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"The matched text is a Markdown-formatted Discord parameter name. It is documentation, not command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"The matched text is a Markdown-formatted Discord parameter name. It is documentation, not command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"The matched text is a Markdown-formatted Discord parameter name. It is documentation, not command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","reason":"The matched text is a Markdown-formatted Discord parameter name. It is documentation, not command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"The backticks mark a Discord MCP tool identifier in a documented sequence. No local command is executed.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"The backticks mark a Discord MCP tool identifier in a documented sequence. No local command is executed.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","reason":"The matched text is a Markdown-formatted Discord parameter name. It is documentation, not command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"The matched text is a Markdown-formatted Discord parameter name. It is documentation, not command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","reason":"The backticks mark a Discord MCP tool identifier in a documented sequence. No local command is executed.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","reason":"The backticks mark a Discord MCP tool identifier in a documented sequence. No local command is executed.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","reason":"The backticks mark a Discord MCP tool identifier in a documented sequence. No local command is executed.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"The backticks mark a Discord MCP tool identifier in a documented sequence. No local command is executed.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","reason":"The backticks mark a Discord MCP tool identifier in a documented sequence. No local command is executed.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"The matched text is a Markdown-formatted Discord parameter name. It is documentation, not command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","reason":"The matched text is a Markdown-formatted Discord parameter name. It is documentation, not command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"The matched text is a Markdown-formatted Discord parameter name. It is documentation, not command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","reason":"The matched text is a Markdown-formatted Discord parameter name. It is documentation, not command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"The matched text is a Markdown-formatted Discord parameter name. It is documentation, not command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","reason":"The matched text is a Markdown-formatted Discord parameter name. It is documentation, not command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","reason":"The backticks mark Discord MCP tool identifiers in a documented sequence. No local command is executed.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","reason":"The backticks mark a Discord MCP tool identifier in a documented sequence. No local command is executed.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","reason":"The backticks mark a Discord MCP tool identifier in a documented sequence. No local command is executed.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","reason":"The backticks mark a Discord MCP tool identifier in a documented sequence. No local command is executed.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","reason":"The matched text is a Markdown-formatted Discord parameter name. It is documentation, not command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:103:ruby-shell-backtick-execution","reason":"The matched text is a Markdown-formatted webhook parameter name. It does not expose a token or execute a command.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:104:ruby-shell-backtick-execution","reason":"The matched text is a Markdown-formatted Discord parameter name. It is documentation, not command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","reason":"The matched text is a Markdown-formatted Discord parameter name. It is documentation, not command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","reason":"The matched text consists of Markdown-formatted message parameter names. It is documentation, not command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","reason":"The backticks mark a Discord MCP tool identifier in a documented sequence. No local command is executed.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","reason":"The backticks mark a Discord MCP tool identifier in a documented sequence. No local command is executed.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","reason":"The backticks mark a Discord MCP tool identifier in a documented sequence. No local command is executed.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","reason":"The backticks mark a Discord MCP tool identifier in a documented sequence. No local command is executed.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","reason":"The matched text is a Markdown-formatted Discord parameter name. It is documentation, not command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","reason":"The matched text is a Markdown-formatted Discord parameter name. It is documentation, not command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","reason":"The matched text shows Markdown-formatted emoji parameters and syntax. It is documentation, not command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","reason":"The matched text is a Markdown-formatted Discord parameter name. It is documentation, not command execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","reason":"The backticks format a custom emoji syntax example in Markdown. They do not invoke Ruby or a shell.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","reason":"The backticks format pagination parameter names in Markdown. They do not invoke Ruby or a shell.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","reason":"The backticks format a pagination parameter name in Markdown. They do not invoke Ruby or a shell.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","reason":"The backticks format Rube MCP toolkit names in Markdown. They do not invoke Ruby or a shell.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","reason":"The backticks format an HTTP response-header name in Markdown. They do not invoke Ruby or a shell.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:21:hardcoded-url","reason":"The skill instructs users to connect to https://rube.app/mcp, creating a real external network and service trust boundary. The endpoint is intentional and clearly disclosed.","verdict":"confirmed","severity":"low","confidence":0.9},{"id":"blocker:SKILL.md:170:system-reconnaissance","reason":"This is a Discord tool reference for listing authorized guild channels. It does not inspect the host system or execution environment.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:172:system-reconnaissance","reason":"This is a Discord tool reference for editing a specified message. It does not inspect the host system or execution environment.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:174:system-reconnaissance","reason":"This is a Discord tool reference for creating a direct-message channel. It does not inspect the host system or execution environment.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:176:system-reconnaissance","reason":"This is a Discord tool reference for assigning an authorized server role. It does not inspect the host system or execution environment.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:177:system-reconnaissance","reason":"This is a Discord tool reference for deleting a specified role. It does not inspect the host system or execution environment.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:178:system-reconnaissance","reason":"This is a Discord tool reference for retrieving an authorized guild member. It does not inspect the host system or execution environment.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:179:system-reconnaissance","reason":"This is a Discord tool reference for updating a specified guild member. It does not inspect the host system or execution environment.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:180:system-reconnaissance","reason":"This is a Discord tool reference for retrieving an authorized guild. It does not inspect the host system or execution environment.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:183:system-reconnaissance","reason":"This is a Discord tool reference for listing authorized guild webhooks. It does not inspect the host system or execution environment.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:185:system-reconnaissance","reason":"This is a Discord tool reference for clearing message reactions. It does not inspect the host system or execution environment.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:187:system-reconnaissance","reason":"This is a Discord tool reference for retrieving an authorized channel. It does not inspect the host system or execution environment.","verdict":"false_positive","confidence":0.97}],"semantic_findings":[{"title":"Privileged Discord Administration Actions","severity":"medium","locations":[{"file":"SKILL.md","line_end":89,"line_start":67},{"file":"SKILL.md","line_end":132,"line_start":91}],"confidence":0.95,"description":"The skill guides role creation, assignment, deletion, member updates, webhook management, and reaction deletion. These actions can alter server access or content.","confidence_reasoning":"The cited workflows explicitly include destructive and access-changing actions with Discord permission requirements. Their impact depends on the connected bot authority."},{"title":"Automated Messaging Abuse Potential","severity":"medium","locations":[{"file":"SKILL.md","line_end":65,"line_start":30},{"file":"SKILL.md","line_end":110,"line_start":91}],"confidence":0.92,"description":"The skill supports channel messages, direct messages, and webhook messages with custom sender presentation. These features can send unwanted or misleading communications.","confidence_reasoning":"The cited sections explicitly document channel messages, direct messages, webhook execution, and custom webhook identity. Abuse remains constrained by Discord permissions."},{"title":"Third-Party MCP Authorization Boundary","severity":"medium","locations":[{"file":"SKILL.md","line_end":26,"line_start":21},{"file":"SKILL.md","line_end":159,"line_start":157}],"confidence":0.9,"description":"Users must add the Rube MCP endpoint and authorize Discord through a returned link. The service receives delegated access for the connected account or bot.","confidence_reasoning":"The setup explicitly requires an external MCP endpoint and Discord authorization, while the token section identifies bot-token and user-OAuth modes."}],"subject_marketplace_commit_sha":"f9e2c34b4f19c7f3e6b0a1e93227b5f77cc12526","subject_content_hash":"661ba10d34357a838ed62f2f909bbd097cae168356d4cd7683fe8fb6411b36ac","subject_tree_hash":"4af5b29e672a558ec5be24d1fc75203debac33a1342bc950ffc412c6f5341dd5","subject_plugin_path":"skills/sickn33/discord-automation","audit_payload_hash":"c8ed466b5d15d6b8db1bf68e1b3c29a3","confirmed_risk_level":"medium","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"f9e2c34b4f19c7f3e6b0a1e93227b5f77cc12526","contentHash":"661ba10d34357a838ed62f2f909bbd097cae168356d4cd7683fe8fb6411b36ac","treeHash":"4af5b29e672a558ec5be24d1fc75203debac33a1342bc950ffc412c6f5341dd5","pluginPath":"skills/sickn33/discord-automation","auditPayloadHash":"c8ed466b5d15d6b8db1bf68e1b3c29a3"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/sickn33-discord-automation/audits/5/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":3,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}