{"skill":{"id":"mn-gen-00003","name":"discord-mcp","slug":"real-discord-mcp","category":"Communication","price":0,"author":"SaseQ"},"audit":{"timestamp":"2026-09-25T06:26:47.176Z","auditor":"Sentinel v3.0 (Real-time Security Audit; layers: metadata → static → L2-trigger)","overall_score":9,"max_score":10,"summary":"metadata: 5 passed, 1 warnings, 0 failed | static (L3): 0 semgrep, 0 secrets, 0 OSV vulns | L2: completed","risk_level":"medium","risk_breakdown":{"l15_l16":"medium","l2":"low","final":"medium"},"layers":{"l15":{"checks_run":6,"findings":1},"l16":{"semgrep_rules_run":18,"secret_patterns_run":18,"osv_checked":true,"semgrep_findings":0,"secret_findings":0,"osv_findings":0},"l2":{"status":"completed","has_results":true,"score":10}}},"checks":[{"name":"AUTH","status":"warning","detail":"No authentication required. If this runs as a server, anyone with network access can call it.","risk":"medium","recommendation":"Add API key or token auth. Localhost is not a security boundary on shared/dev machines."},{"name":"TOOL_DESCRIPTIONS","status":"pass","detail":"No prompt injection patterns detected in descriptions or system prompt","risk":"low","recommendation":""},{"name":"INPUT_VALIDATION","status":"pass","detail":"No direct fs/db/http access detected from metadata","risk":"low","recommendation":""},{"name":"CORS_ORIGIN","status":"pass","detail":"Skill runs locally (stdio/local_runtime). CORS not applicable.","risk":"low","recommendation":""},{"name":"OAUTH_SCOPES","status":"pass","detail":"No OAuth/token-based access detected","risk":"unknown","recommendation":""},{"name":"RATE_LIMITING_ERROR_LEAKAGE","status":"pass","detail":"No rate limiting concerns detected from metadata","risk":"low","recommendation":""},{"name":"LAYER 3 SEMGREP RULES","status":"pass","detail":"18 rules checked, 0 findings","risk":"low","recommendation":""},{"name":"LAYER 3 SECRET DETECTION","status":"pass","detail":"18 patterns checked, 0 secrets found","risk":"low","recommendation":""},{"name":"LAYER 3 OSV DEPENDENCIES","status":"pass","detail":"OSV API checked — no known vulnerabilities","risk":"low","recommendation":""}],"recommendations":["[AUTH] Add API key or token auth. Localhost is not a security boundary on shared/dev machines."],"testing_guide":{"step1":"Send raw JSON-RPC requests manually (not via polished client that hides errors)","step2":"Test with malformed inputs — check if stack traces or secrets leak in error responses","step3":"Test path traversal (../../etc/passwd) if fs access detected","step4":"Test SQL injection (1' OR 1=1) if db access detected","step5":"Test SSRF (http://169.254.169.254) if http access detected","step6":"Verify rate limiting by sending 100 rapid requests"},"l2_docker_sandbox":{"status":"completed","results":{"skill_id":"mn-gen-00003","timestamp":"2026-09-25T04:42:25Z","l2_version":"2.5","sandbox_config":{"network":"none","filesystem":"read-only","capabilities":"dropped ALL","memory":"256m","cpu":"0.5","pids":"64","timeout":"60s","gvisor":"gvisor-active","seccomp_profile":"n/a (gVisor userspace kernel active)"},"execution_status":"ran","failure_reason":null,"analysis_layers":{"stdout_passive":{"network_attempts":0,"fs_write_attempts":0,"process_spawns":1,"credential_leakage":0,"crash_detected":0,"dynamic_imports":0},"strace_syscalls":{"file_access_sensitive":0,"file_write_outside_tmp":0,"network_connect":0,"process_exec":0,"process_fork":0,"permission_escalation":0,"sensitive_paths_accessed":[]},"mcp_probe_active":{"tools_discovered":0,"tools_tested":0,"adversarial_findings":0,"critical_findings":0,"high_findings":0,"details":[],"leaked_data":[]},"filesystem_diff":{"files_created":0,"files_modified":0,"files_deleted":0,"suspicious_changes":[]},"l25_seccomp_violations":{"total_violations":0,"ptrace_attempted":false,"bpf_attempted":false,"mount_attempted":false,"kexec_attempted":false,"clone3_attempted":false,"unshare_attempted":false,"blocked_syscalls":[]},"l25_suspicious_files":{"ssh_files":false,"env_files":false,"cron_files":false,"key_files":false,"details":[]},"l26_egress_proxy":{"total_requests":0,"allowed_requests":0,"blocked_requests":0,"blocked_domains":[],"allowed_domains":[],"metadata_endpoint_access":false,"localhost_access":false,"private_range_access":false}},"stdout_size_bytes":421,"stdout_sample":"docker: Error response from daemon: failed to create task for container: failed to create shim task: OCI runtime create failed: unable to retrieve OCI runtime error (open /run/containerd/io.containerd.runtime.v2.task/moby/9da01ee14d8af0538ff4a27b3608752fc332d395db411f51bec1b3b5c8d12483/log.json: no such file or directory): fork/exec /usr/local/bin/runsc: exec format error  Run 'docker run --help' for more information ","l2_score":10,"l2_risk_level":"low","findings_summary":{"total_critical":0,"total_high":0,"sensitive_paths_accessed":[],"leaked_data":[],"suspicious_fs_changes":[],"egress_blocked_domains":[],"egress_metadata_access":false}},"trigger":null}}