Back to skill

Security audit

Slack

Security checks for vulnerabilities and agentic risk

Overview

This Slack skill is a markdown-only package, but its instructions describe broad Slack write actions like sending, editing, deleting, pinning messages and retrieving member data without clear permissions, authentication, or safety controls.

Review this skill before installing. Use it only with a least-privilege Slack token, confirm every send/edit/delete/pin action explicitly, and avoid member lookups unless there is a clear business need. The package does not show malicious code, but its permissions and authentication model are too unclear for automatic trust.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Scope Creep

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest exposes only the read tool, while the documentation instructs the agent to perform state-changing Slack operations such as sending, editing, deleting, pinning, and unpinning messages. This mismatch can bypass user and platform expectations about the skill's actual privileges, increasing the risk of unauthorized actions, confused-deputy behavior, or hidden dependency on out-of-band execution paths.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill advertises message send, edit, and delete capabilities without warning that these are destructive or potentially irreversible actions. In a Slack automation context, omission of such warnings increases the chance of accidental tampering with business communications, audit confusion, and social or operational harm.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation gives contradictory guidance about authentication, first saying no additional API key is required and later stating an API key must be configured. In a Slack-control skill, this ambiguity can lead users or agents to misuse existing ambient credentials, misunderstand trust boundaries, or attempt actions without proper security review.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The summary and description combine Chinese and English, and later sections also include mixed-language text, but the file does not explain the language policy or offer the user a language preference. This can violate language/locale expectations because the skill implicitly imposes multilingual output without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill includes member information retrieval without any privacy or data-handling warning. In Slack, user profile and membership data may be sensitive, so failing to disclose privacy considerations can encourage unnecessary collection or exposure of personal or organizational information.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.