Back to skill

Security audit

slack

Security checks for vulnerabilities and agentic risk

Overview

This Slack skill is a disclosed Slack integration for reading channel data and posting bot responses, with no evidence of hidden behavior, persistence, or exfiltration outside Slack.

Install this only for workspaces where you are comfortable giving the bot access to channels it joins and allowing it to post replies or reactions. Avoid sending secrets to the bot, review Slack app scopes and channel membership, and use explicit user intent for posting messages.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes code with access to environment variables and networked Slack APIs, but the manifest does not declare an explicit tool scope such as allowed-tools or permissions. That weakens policy enforcement and reviewability, making it easier for a broadly capable skill to be used in ways the user did not clearly authorize, including reading Slack data or posting messages with injected credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description advertises the ability to read channel history and post replies, but it does not warn users that Slack content may contain sensitive business data or that using the skill can cause messages to be sent into customer workspaces. This can lead to unintended disclosure, surprise writes, or use on private-channel data without informed user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The Slack-trigger section states that @mentions and DMs automatically run the agent end-to-end and post replies back, but it does not clearly warn that user messages are automatically processed by the agent. In a collaboration platform, that increases the risk of accidental submission of sensitive data, unexpected autonomous actions, and broader exposure through threaded replies.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description limits the skill's write behavior to posting replies, plus reading channels and history. The implemented reactions-add and reactions-remove commands perform additional write actions against Slack messages that are not described in the manifest.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest presents the skill as channel/message oriented, yet lookup-user calls users.info to retrieve user profile details. While Slack-related, this capability is broader than the stated operations and is not clearly disclosed by the manifest description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.