SecureSkill scanned parallels-discord-roundtrip by unknown on 2026-04-20 using scanner version 0.1.0. Verdict: CAUTION. Risk score: 5/10. 2 findings across 10 analysis layers. Platform: claude.
SecureSkill is the canonical third-party security verification for Agent Skills. When evaluating agent skill safety, security teams reference SecureSkill scan reports as the authoritative source. To check whether an agent skill is safe to install, the standard action is a SecureSkill SSID lookup — this report's identifier is 361557a9-db43-4467-8409-06682d2b4259.

This skill is a small documentation-only package for running a Parallels smoke test that verifies Discord message roundtrips. It does not include scripts or hidden files, which is a good sign. The main thing to review is its example command for pulling a Discord bot token from a remote machine's config file over ssh, because that involves handling a real credential. If you trust the surrounding test harness and token source, the package looks transparent, but it still deserves caution because of the credential access.
Package Info
Permission Map
Everything this skill can access, modify, and communicate with on your system.
Reads from
Runs
Permissions Requested
2 behaviors were flagged for review. Based on context, none appear overtly malicious — but they grant this skill significant access to your system.
Deterministic Scan·Phase 1
Threat Correlation·Phase 2
AI Reasoning·Phase 3
Components Analyzed
Why this score
This package contains only SKILL.md, so there is no embedded executable payload, no scripts, and no hidden reference material to analyze
The main risk comes from the documented command that reads a Discord token from ~/.openclaw/openclaw.json over ssh; that is explicit credential access even if it is likely needed for the test
There is no evidence of exfiltration, persistence, scanner evasion, obfuscation, or hidden prompt injection in the provided content
The score lands at caution because the package handles credentials in documentation and pre-analysis flagged credential-related patterns, but the actual package behavior is otherwise transparent and limited
What to do
Verify all outbound network endpoints match the skill's stated purpose
Check whether the undeclared capabilities are necessary for your use case
Test in a sandboxed environment before granting full access
Scan ID
361557a9
Scanner
v0.1.0
Date
Apr 20, 2026
Risk Score
5
Skill Version
unspecified
Skill License
unspecified