Back to skill

Security audit

Slack消息中枢LITE

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Slack helper that can send messages and list public channels using a user-provided bot token; that external access is expected for its purpose but should be used deliberately.

Install only if you are comfortable giving the agent a Slack Bot Token with chat:write and channels:read. Review the exact destination channel and message text before any send, avoid including secrets or sensitive workspace content, and do not use callback_url unless the destination is trusted and intentionally chosen.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description is overly broad and advertises general-purpose Slack integration without strong trigger boundaries or user-consent constraints. In an agent environment with read/exec/write tools, vague activation language can cause the skill to be invoked in unintended contexts and may lead to unreviewed outbound messaging or workspace enumeration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill accepts a callback_url and performs Slack message sending, but the description does not prominently warn that user-provided data may be transmitted to third-party services. This creates a risk of silent exfiltration of prompts, message content, metadata, or results to Slack or arbitrary callback endpoints.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
### 缺失时引导配置
> 需要先配置 Slack Bot Token:
> 1. 访问 https://api.slack.com/apps 创建新App
> 2. 配置 Bot Token Scopes:`chat:write`、`channels:read`
> 3. 安装App到工作区,获取 `xoxb-` 开头的Bot Token
> 4. 终端环境变量:`export SLACK_BOT_TOKEN="${SLACK_BOT_TOKEN:?请设置环境变量}"`

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

md
### 缺失时引导配置
> 需要先配置 Slack Bot Token:
> 1. 访问 https://api.slack.com/apps 创建新App
> 2. 配置 Bot Token Scopes:`chat:write`、`channels:read`
> 3. 安装App到工作区,获取 `xoxb-` 开头的Bot Token
> 4. 终端环境变量:`export SLACK_BOT_TOKEN="${SLACK_BOT_TOKEN:?请设置环境变量}"`

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This example issues a real outbound POST to Slack using a bearer token, which means any message content included by the agent will be transmitted to an external service. In agent contexts, this is dangerous because prompts or sensitive workspace/user data could be sent out without a sufficiently explicit confirmation step, even though the skill warns not to print the token.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

执行:

bash
# 发送会议提醒
curl -s -X POST "https://slack.com/api/chat.postMessage" \
  -H "Authorization: Bearer ${SLACK_BOT_TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{

Static analysis

No suspicious patterns detected.