Back to skill

Security audit

Slack Hub Tool Free

Security checks for vulnerabilities and agentic risk

Overview

This Slack skill does what it says, but it needs review because it can post messages, search workspace content, and uses broad or inconsistent scope language.

Review this before installing. Use a minimally scoped Slack bot token, avoid granting private-channel scopes unless needed, confirm every message send/search target explicitly, and prefer a pinned or otherwise verified installer instead of running a mutable `@latest` package.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:148
Finding

Unpinned Third-Party Package Execution via Mutable npm Tag

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 148
Vulnerability Type: Supply-chain risk caused by executing an unpinned third-party package
Risk Level: Medium

Vulnerable Code:

bash
npx skillhub@latest install slack-hub-tool-free

Technical Analysis

The installation instructions invoke skillhub through npx using the mutable @latest tag. If the package is not already available locally, npx can download package content from the configured npm registry and execute its CLI code. npm lifecycle scripts may also execute during package installation.

Because @latest does not identify an immutable, audited release, the code executed by users can differ from the version considered during this audit. The project does not specify an exact package version, integrity hash, trusted registry, signature-verification process, or lifecycle-script restriction.

This creates an insecure dependency boundary: compromise of the package publisher, npm account, registry resolution, or a future release could replace the effective installation payload without requiring any change to this reviewed file.

Attack Path

  1. An attacker compromises the skillhub package publisher account, its release pipeline, or another relevant dependency in its supply chain.
  2. The attacker publishes a malicious version and assigns or causes npm to assign the latest distribution tag to it.
  3. A user follows the documented command in SKILL.md.
  4. npx resolves skillhub@latest, downloads the attacker-controlled version, and executes its CLI or associated installation scripts.
  5. The malicious process runs with the permissions of the user who invoked the command.
  6. It may access files and environment variables available to that user, including a configured SLACK_BOT_TOKEN, and perform unauthorized local or network operations.

Impact Assessment

Successful exploitation could provide arbitrary code executi ...[truncated 738 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with an exact, reviewed version, for example:

    bash
    npx --yes skillhub@X.Y.Z install slack-hub-tool-free
    
  2. Verify the selected package version and its transitive dependencies before recommending it.

  3. Publish and validate package integrity hashes or cryptographic signatures through a documented verification procedure.

  4. Explicitly specify the trusted npm registry and use a lockfile where the installation workflow permits it.

  5. Disable npm lifecycle scripts with --ignore-scripts if the package can operate without them.

  6. Prefer a locally installed, locked, and reviewed CLI rather than downloading executable code at invocation time.

  7. Run installation with a minimally privileged account in an isolated environment that does not expose Slack credentials or unrelated files.

  8. Document package ownership, provenance, and the process used to review upgrades before changing the pinned version.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

在项目根目录创建 .env 文件:

bash
# .env
SLACK_BOT_TOKEN=xoxb-your-bot-token-here

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documents outbound Slack operations and workspace search but does not clearly warn that using it will transmit data to Slack and may post messages, query workspace history, or expose organizational information through the connected account. In an agent setting, missing side-effect warnings can lead to silent external actions with privacy and integrity consequences.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The core capability section states the channel-list feature is limited to "所有公开频道" (all public channels), and the summary also frames browsing as public channels only. Later, the file documents groups:read for listing private channels if needed and says search covers joined private channels, which contradicts the earlier stated free-version scope rather than merely omitting detail.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger conditions are broad enough to match generic communication tasks, which increases the chance an agent will invoke this skill in situations the user did not explicitly intend. Because the skill can send messages and search workspace content, overbroad activation can cause unintended data transmission or Slack-side actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The install command uses npx skillhub@latest, which pulls and executes the latest published package without version pinning. This creates a supply-chain risk: a compromised or malicious upstream release could run arbitrary code on the user's machine at install time.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.