Back to skill

Security audit

Slack Crawler Free

Security checks for vulnerabilities and agentic risk

Overview

The skill is a Markdown-only Slack archive helper, but it requests write and exec authority while giving inconsistent and overbroad instructions for modifying, importing, saving, exporting, and general database use.

Review before installing. Use this only for the intended local Slack archive workflow, and avoid granting write access unless you specifically want it to create or update ~/.slack-crawler/archive.db from a desktop export. Do not use it for unrelated database administration, and require explicit confirmation before any sync, cleanup, reset, import, save, or export-style action.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document later states the archive cannot be modified and SQL is read-only, yet these earlier sections authorize modification, reset, and import operations. In an agent setting with write and exec tools enabled, this contradiction is dangerous because the agent may choose the broader instruction path and alter or overwrite local archive/configuration data without clear user intent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill markets itself as a local-first, read-only analytics tool with no export support in the free edition, but these instruction blocks explicitly say create/query/export, modify/reset/import, and export/save/convert are supported. This inconsistency can cause an agent to perform broader file or data operations than users would reasonably expect, weakening safety boundaries around local Slack archive data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The capability sections mention import, reset, export, and save style operations, and the rest of the document also describes sync and cleanup actions, but there is no strong warning or approval gate for operations that may change local data. In a skill with exec and write access, lack of explicit warning and confirmation requirements raises the risk of accidental destructive actions or unintended disclosure of Slack archive contents.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger condition says to use this skill whenever database operations, SQL queries, or data storage management are needed, which is far broader than Slack local archive analysis. That overbroad routing can cause the skill to activate for unrelated database tasks, increasing the chance that an agent runs local exec/write workflows against unintended data sources or contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

文件标题、描述、流程说明和示例均仅以中文提供,且未说明可根据用户偏好切换语言。按规则,若技能在自然语言层面默认强制特定语言且无用户选择,属于语言/地区策略风险。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.