Agent skill

Discord Php Bot Security

by discord-php in discord-php/DiscordPHP

Audit checklist for DiscordPHP bots and API libraries — stop the bot token leaking to third-party APIs or logs, keep secrets out of customids and exception messages, use constant-time comparison and…

MITAuto-check: notesBackend & APIs

Install Discord Php Bot Security

skills CLI
$ npx skills add discord-php/DiscordPHP --skill discord-php-bot-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install discord-php/DiscordPHP discord-php-bot-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/discord-php/DiscordPHP.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/discord-php-bot-security .claude/skills/discord-php-bot-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
discord-php-bot-security
GitHub stars
1.1k
Token cost
~1.2k tokens
SKILL.md length
450 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

Audit checklist for DiscordPHP bots and API libraries — stop the bot token leaking to third-party APIs or logs, keep secrets out of customids and exception messages, use constant-time comparison and…

  • Works in 5 steps: Never send the Discord bot token to a… → Keep tokens out of logs and exception… → Keep secrets out of custom_id → …
  • Reviewing an HTTP client
  • SKILL.md covers 1. Never send the Discord bot…, 2. Keep tokens out of logs and…, 3. Keep secrets out of custom_id and 4. OAuth2 / CSRF / webhooks, plus 2 more sections
  • Calls rg and git

What it does

Discord Php Bot Security is an agent skill from discord-php/DiscordPHP. Audit checklist for DiscordPHP bots and API libraries — stop the bot token leaking to third-party APIs or logs, keep secrets out of customids and exception messages, use constant-time comparison and crypto-random for auth/CSRF/webhook flows, and don't log OAuth codes / full headers / PII. Use when reviewing an HTTP client, an error handler, an OAuth or webhook endpoint, or before publishing a repo.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Webhooks, Third-party API integration and Web application vulnerabilities. It works with Discord and PHP. The repository describes itself as: An API to interact with the popular messaging app Discord. The licence is MIT.

When your agent uses it

  • Reviewing an HTTP client
  • An error handler
  • Webhook endpoint
  • Before publishing a repo

Example prompts

  • “/discord-php-bot-security”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Never send the Discord bot token to a third party
  2. Keep tokens out of logs and exception messages
  3. Keep secrets out of custom_id
  4. OAuth2 / CSRF / webhooks
  5. Repo hygiene

What it can do on your machine

Read from SKILL.md and the folder at commit 580c66a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Discord Php Bot Security loads about 1.2k tokens when it runs. Until then it costs about 107 tokens; SKILL.md has 450 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:74
    - `.gitignore` must cover `.env`, `.env.*`, `composer.lock` (in these repos),

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from discord-php/DiscordPHP at commit 580c66a, republished under its MIT licence (© discord-php). 450 words, ~1,160 tokens.

Download SKILL.mdSave it as .claude/skills/discord-php-bot-security/SKILL.md (or your agent's skills folder).
name
discord-php-bot-security
description
Audit checklist for DiscordPHP bots and API libraries — stop the bot token leaking to third-party APIs or logs, keep secrets out of custom_ids and exception messages, use constant-time comparison and crypto-random for auth/CSRF/webhook flows, and don't log OAuth codes / full headers / PII. Use when reviewing an HTTP client, an error handler, an OAuth or webhook endpoint, or before publishing a repo.

DiscordPHP Bot Security Skill

A concrete checklist built from real findings across DiscordPHP-MTG, DiscordPHP-NHA, DiscordPHP-Voice and Civilizationbot.

1. Never send the Discord bot token to a third party

The classic bug: an extension's Http client for api.example.com is constructed with 'Bot '.$this->token and adds Authorization: <token> to every request — so the Discord bot token is sent to an unrelated host on every call.

  • Extension HTTP clients for a third-party API should take an empty token and only set Authorization when a real value is present:
    php
    $h = ['User-Agent' => $this->getUserAgent()];
    if ($this->token !== '')  $h['Authorization'] = $this->token;
    if ($this->apiKey !== null) $h['X-Api-Key'] = $this->apiKey;   // that API's own key
  • Drop Discord-only headers (X-Ratelimit-Precision) from non-Discord clients.
  • Override getUserAgent() to identify your library, not DiscordPHP-HTTP.

2. Keep tokens out of logs and exception messages

  • Do not log full request/response bodies on error. A FastAPI-style 422 body echoes the request back under input — for an auth'd POST that includes the token. Redact before logging and before putting it in an exception message:
    php
    $body = preg_replace('/("(?:nha_)?token"\s*:\s*)"[^"]*"/i', '$1"***"', $body) ?? $body;
  • Manager/gateway code: log ['token' => '*****'], and give payload parts a __debugInfo() that redacts the token (see VoicePayload::__debugInfo()). Log identify with ['op' => $payload->op], not the whole payload.
  • Global error handlers that DM a technician: send file:line:function from debug_backtrace() (no ['args']). getTraceAsString() still inlines scalar args truncated to 15 chars — a token prefix can leak. Prefer the arg-free form.

3. Keep secrets out of custom_id

Component custom_ids are sent to Discord and visible in the client. Capture the agent/session token in the server-side listener closure, never in the id or a button label. (NHA's AgentObservation::toContainer($nha, $token) does this right — $token lives only in the $submit closure.)

Show full SKILL.md (201 more words)Show less

4. OAuth2 / CSRF / webhooks

  • State / session ids: bin2hex(random_bytes(16)), never uniqid() (predictable microtime).
  • Compare with hash_equals(), not === / !== — HMAC signatures and CSRF state tokens. Reject empty/absent values up front; make the state single-use (delete it after a successful exchange).
  • Webhook signature: verify with hash_equals(), prefer X-Hub-Signature-256, and fail closed when the shared secret env var is unset (an unset secret makes hash_hmac key '' and every request "valid").
  • Redirect URIs: always validate the effective redirect_uri against an allow-list — a caller-supplied value must not bypass the check (open redirect / auth-code interception).
  • Don't log the OAuth authorization code (an exchangeable credential), the full request header set on a rejected request (a mistyped Authorization lands in the log), or contact-form email/message bodies (PII — send them to the private channel, not the log).
  • Raw curl in an OAuth path: set CURLOPT_SSL_VERIFYPEER => true, CURLOPT_SSL_VERIFYHOST => 2, CURLOPT_CONNECTTIMEOUT, CURLOPT_TIMEOUT, curl_close(), and null-check the result.

5. Repo hygiene

  • .gitignore must cover .env, .env.*, composer.lock (in these repos), /var/* (state files with tokens), and any bespoke secret file (token.php, /json, botlog.txt).
  • Verify nothing sensitive is tracked: git ls-files | grep -iE '\.env|token|secret|\.pem|\.key|credential'.
  • Never place personal data or tokens in URL query strings (they get logged by proxies and land in Referer).

Quick grep sweep

rg -n "addQuery\(\s*['\"](token|key|secret|password)" src/          # token in URL
rg -n "(debug|info|warn|error).*(token|Authorization|getBody|payload|->data\b)" src/
rg -n "!==|===" src/ | rg -i "hash_hmac|signature|hash_equals"      # non-constant-time
rg -n "uniqid\(" src/                                               # weak randomness

© discord-php, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/discord-php-bot-security of discord-php/DiscordPHP.

Open the folder on GitHubat commit 580c66a

Compare with similar skills

Discord Php Bot Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Discord Php Bot Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Discord Php Bot Security this skilldiscord-php/DiscordPHP1.1k—~1.2kAutomated safety check: NotesMIT
Passport Developmenttrypostit/trypost676—~1.9kAutomated safety check: PassMIT
Frappe Core APIImpertio-Studio/Frappe_Claude_Skill_Package1871 repos~3.2kAutomated safety check: PassMIT
Frappe Errors APIImpertio-Studio/Frappe_Claude_Skill_Package1871 repos~4kAutomated safety check: PassMIT
Shopify ExpertJeffallan/claude-skills12k—~1.8kAutomated safety check: PassMIT
Web Ssrfs0ld13rr/pentestcode817—~660Automated safety check: WarnMIT

Similar skills

  • Passport Development

    trypostit/trypost

    Develops OAuth2 API authentication with Laravel Passport. An agent skill from trypostit/trypost.

    676 GitHub stars~1.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Frappe Core API

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when building ERPNext/Frappe API integrations (v14/v15/v16) including REST API, RPC API, authentication, webhooks, and rate limiting.

    187 GitHub starsUsed in 1 repo~3.2k tokens
    Backend & APIsAuto-check passed
  • Frappe Errors API

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when debugging or handling API errors in Frappe/ERPNext v14/v15/v16.

    187 GitHub starsUsed in 1 repo~4k tokens
    Backend & APIsAuto-check passed
  • Shopify Expert

    Jeffallan/claude-skills

    Builds Shopify themes in Liquid, custom apps, Storefront API storefronts and checkout extensions, using the Shopify CLI to lint, run locally and deploy.

    12k GitHub stars~1.8k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Web Ssrf

    s0ld13rr/pentestcode

    Server-Side Request Forgery detection→internal-access→proof for web apps.

    817 GitHub stars~660 tokensUpdated 5 days ago
    Backend & APIsAuto-check: warnings
  • Shopify API

    Microck/ordinary-claude-skills

    Complete API integration guide for Shopify including GraphQL Admin API, REST Admin API, Storefront API, Ajax API, OAuth authentication, rate limiting, and webhooks.

    401 GitHub starsUsed in 1 repo~4.3k tokens
    Backend & APIsAuto-check passed

More from discord-php/DiscordPHP

All 14 skills in this repo
  • Async Test And Doc Sync

    discord-php/DiscordPHP

    Maintain test and documentation alignment — PHPUnit tests, async testing patterns, PHPDoc contracts, guide pages, and documentation workflow.

    1.1k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check: notes
  • Discord Php Extension

    discord-php/DiscordPHP

    Scaffold and maintain a DiscordPHP-based bot or an API-library-on-DiscordPHP (the DiscordPHP-MTG / DiscordPHP-NHA / DiscordPHP-Sabacc pattern) — client subclass, third-party HTTP layer, Parts…

    1.1k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Discord Php Interactions

    discord-php/DiscordPHP

    Build DiscordPHP slash commands and message components — global command trees with subcommands, user- AND guild-installable commands usable in DMs / group DMs / guild channels, Components V2…

    1.1k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Helpers And Infra Keeper

    discord-php/DiscordPHP

    Work with DiscordPHP's infrastructure utilities — CacheWrapper, CacheConfig, BigInt, Multipart, Endpoint::bind URL templates, Collection base class, and domain Exceptions.

    1.1k GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Part Model Maintainer

    discord-php/DiscordPHP

    Maintain Part domain models — fillable attributes, mutators, typed nested data, save/fetch behavior, permission checks, PHPDoc, and repository bindings.

    1.1k GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Runtime Bootstrap Keeper

    discord-php/DiscordPHP

    Maintain Discord.php runtime bootstrapping, startup options, event loop, gateway connection, reconnection, member chunking, cache configuration, and process lifecycle.

    1.1k GitHub stars~4k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Discord Php Bot Security

What does Discord Php Bot Security do?

Audit checklist for DiscordPHP bots and API libraries — stop the bot token leaking to third-party APIs or logs, keep secrets out of customids and exception messages, use constant-time comparison and…. Discord Php Bot Security is an agent skill from discord-php/DiscordPHP. Audit checklist for DiscordPHP bots and API libraries — stop the bot token leaking to third-party APIs or logs, keep secrets out of customids and exception messages, use constant-time comparison and crypto-random for auth/CSRF/webhook flows, and don't log OAuth codes / full headers / PII.

When should I use Discord Php Bot Security?

Discord Php Bot Security fits situations like: reviewing an HTTP client; an error handler; webhook endpoint; before publishing a repo.

How do I install Discord Php Bot Security in Claude Code?

Run `npx skills add discord-php/DiscordPHP --skill discord-php-bot-security -a claude-code`. Or copy the skill folder (.github/skills/discord-php-bot-security in discord-php/DiscordPHP) into .claude/skills/discord-php-bot-security in your project. Claude Code loads it when a task matches its description.

How do I install Discord Php Bot Security in Codex?

Run `npx skills add discord-php/DiscordPHP --skill discord-php-bot-security -a codex`. Or copy the skill folder (.github/skills/discord-php-bot-security in discord-php/DiscordPHP) into .agents/skills/discord-php-bot-security in your project. Codex loads it when a task matches its description.

Can I use Discord Php Bot Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add discord-php/DiscordPHP --skill discord-php-bot-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/discord-php-bot-security, .gemini/skills/discord-php-bot-security, .github/skills/discord-php-bot-security and .opencode/skills/discord-php-bot-security in your project.

What does Discord Php Bot Security need to run?

Going by SKILL.md and its folder, Discord Php Bot Security needs the command-line tools its instructions call (rg and git).

Does Discord Php Bot Security access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Discord Php Bot Security safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Discord Php Bot Security use?

Discord Php Bot Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Discord Php Bot Security use?

About 1.2k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Discord Php Bot Security?

Skills that share tags, products or a category with Discord Php Bot Security: Passport Development (trypostit/trypost, 676 stars), Frappe Core API (Impertio-Studio/Frappe_Claude_Skill_Package, 187 stars), Frappe Errors API (Impertio-Studio/Frappe_Claude_Skill_Package, 187 stars) and Shopify Expert (Jeffallan/claude-skills, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Discord Php Bot Security?

discord-php (a GitHub organization) maintains it in discord-php/DiscordPHP, which has 1,080 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 6, 2026.

Source: discord-php/DiscordPHP on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.