Back to plugin

Security audit

Discord

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Discord channel plugin that uses Discord credentials and messaging/moderation capabilities for its stated purpose.

Install this only for Discord servers and channels where you want OpenClaw agents to participate. Use a least-privilege Discord bot token, keep credentials in the secret/env mechanisms, and review action gates for moderation, roles, channel management, voice auto-join, thread-bound session spawning, and allowlists before enabling broad access.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/.setup/receive-recovery-CHPOsnLc.mjs:119
Evidence
const ffmpeg = spawn(resolveFfmpegBin(), [

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/.setup/provider-B_G5hASF.mjs:6113
Evidence
const gatewayInfoTimeoutMs = resolveDiscordGatewayInfoTimeoutMs({ env: process.env });