ClawAudit verdict
bulk message delete
discord-bulk-message-delete
Discord bulk message deletion tool that defaults to dry-run mode and requires explicit user confirmation before deleting; a legitimate admin utility with appropriate safeguards.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
Possible hardcoded credential
SKILL.md ยท code ยท TOKEN = "YOUR_BOT_TOKEN_HERE
Python urllib.request โ network access
backup/discord-purge-tool_no_dry-run.py ยท prose ยท downgraded ยท urllib.request
Permissions & capabilities
No declared permissions โ minimal attack surface.
Is this flag fair?
Thanks โ recorded.