Security Audit
discord-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
discord-automation received a trust score of 100/100, placing it in the Trusted category. This skill has passed all critical security checks and demonstrates strong security practices.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 0 medium, and 0 low severity. Key findings include Broad Discord Toolkit Access.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 17, 2026 (commit 99e2a295). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| INFO | Broad Discord Toolkit Access The skill explicitly requires access to the 'discord' and 'discordbot' toolkits via Rube MCP. These toolkits grant extensive permissions for managing Discord operations, including sending messages, managing roles, webhooks, and reactions across guilds and channels. While these permissions are necessary for a 'Discord Automation' skill to function as described, users should be aware of the broad scope of control this skill can exercise over their Discord environment. Ensure that the skill's functionality strictly adheres to its stated purpose and that the underlying Rube MCP and Composio toolkits enforce least privilege where possible. Users should be clearly informed about the full extent of permissions required before enabling the skill. | Static | SKILL.md:20 |
Scan History
Embed Code
[](https://skillshield.io/report/cc9dc9237e0a28bc)
Powered by SkillShield